.llmwiki/profile.json.
They are not runtime plugins, and they do not contain executable code.
If a project has no .llmwiki/profile.json, llmwiki uses the built-in default
profile exactly as before.
List templates
The public template surface supports built-in templates, local template files,
and signed releases from explicitly trusted remote taps.
Inspect a template
Install a built-in template
.llmwiki/profile.json, is refused so
existing wiki/concepts and wiki/queries pages are not orphaned under a new
profile.
On success this writes:
.llmwiki/profile.json- attempts to write
.llmwiki/template-lock.json
.llmwiki/profile.json, which is validated on load.
Install a local template file
Replacing a profile
llmwiki template init refuses to overwrite an existing profile by default.
--force only works when the current typed corpus is empty:
- no typed entity pages under the active or incoming profile’s entity directories;
- no relation records;
- no event records;
- no artifact files;
- no workflow runs;
- no pending or archived review candidates;
- no unresolved, unsafe, or unreadable typed stores.
--force.
What templates cannot do
Templates cannot include executable code, scripts, postinstall hooks, connector implementations, MCP servers, or out-of-band local or environment trust grants. They may declare workflow gates and permission requests that the normal workflow authority model evaluates at run time. Connector bindings can only name connectors that are both compiled into llmwiki and marked template-installable.Configure a signed remote tap
A tap is an HTTPS signed index. Adding one requires its Ed25519 public key explicitly; llmwiki does not trust a key merely because a server presents it.--key-base64 instead of --key-file for automation, but never pass both.
Adding a tap does not perform network I/O.
Inspect and verify a remote release
Remote releases use a fully qualified coordinate:tap refresh can restore missing or malformed
index evidence only from the exact signed snapshot already recorded in state.
Install a remote release
Install by exact coordinate, never by a floating version or search result:template-lock.json records the coordinate, package digest,
tap, accepted index sequence, and publisher key id. This remains advisory
provenance. Profile loading and runtime authority come only from the validated
.llmwiki/profile.json; editing the lock cannot bless profile drift.
Check provenance and drift
Update an installed remote template
Preview compatibility before writing:llmwiki template status reports
interrupted-write. The next update, compile, or explicit llmwiki recover
restores the recorded pre-update state before continuing, so a partial update
cannot masquerade as a local profile modification or a clean install.
Signatures and untrusted content
Ed25519 signatures establish who signed exact bytes and whether tap continuity accepts them. They do not establish that publisher-authored display names, workflow labels, or descriptions are safe instructions. llmwiki nonce-fences presentation strings from every non-shipped profile before exposing them to an agent. This decision is derived from active profile bytes, not the mutable lock. Remote packages contain profile configuration only. Remote docs, examples, scripts, executable plugins, and automatic content seeding are not downloaded or run. Publishing a tap is a separate operator workflow. See Publish a signed template tap for the package envelope, index, signing, hosting, rotation, and client-verification procedure.Disable a tap
tap list and tap refresh
warn when a tap approaches its persistence limit so operators can plan a new
identity or an explicit reset before refresh is refused.
If a tap’s root key is lost or its retained history must be discarded, use the
explicit destructive operation: