CatalogOpenAI Codex Skills · OpenAI

skill-installer

Install Codex skills into $CODEX_HOME/skills from a curated list or a GitHub repo path. Use when a user asks to list installable skills, install a curated skill, or install a skill from another repo (including private repos).

Review advisedOfficial28k starsalso listed on skills.sh

Savant verdict: Review advised

SkillSpector or the source hub flagged patterns to review before use.

Live evaluation

52overall
54quality
25compliance
68grounding
51actionability
76efficiency
Why this score may understate the skillThe live evaluation is a chat-only run: the model follows the skill's instructions but can't execute its scripts, call tools or reach the network.
  • Ships 3 scripts the live run can't execute; outputs describe those steps rather than perform them.
Live telemetry from real runs (via the Savant skill router) replaces this estimate as it accumulates.

1 pass · 2 investigate · 7 fail across 10 cases. Jev accepted 10 of 19 LLM-drafted cases. Drafted and run by nvidia/nemotron-3-super-120b-a12b, validated and scored by jev-latest.

  • List the available curated skills for me to install.positive case · fail
  • Install the skill named 'python-linter' from the curated list.positive case · investigate
  • Install the skill 'data-validator' from the experimental skills in the openai/skills repository.positive case · fail
  • List the skills from the .experimental directory.positive case · pass
  • Teach me how to write a new skill from scratch.negative case · fail
  • Remove the 'old-skill' skill from my installed skills.negative case · fail
  • Install the skill named 'data-analysis' from the curated list.positive case · fail
  • List the skills available for installation from the experimental directory.positive case · fail

Safety (NVIDIA SkillSpector)

Risk score
32/100
Recommendation
CAUTION
Severity
MEDIUM
Savant decision
Review advised
SkillSpector rated it CAUTION with a risk score of 20/100 or more; review the findings before use. SkillSpector 2.12.0, static analysis.

4 patterns found

  • MCP Least Privilege: Skill declares no tool scope ('permissions' or 'allowed-tools') but code capabilities were detected: env, file_read, file_write, network, shell.medium · SKILL.md:1 · Without declared permissions the skill's intent is opaque and cannot be validated.
  • Agent Snooping: ls into `$CODEX_HOME/skills/<skill-name>` (defaults to `~/.codex/skillsmedium · SKILL.md:48 · Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
  • Data Exfiltration: https://api.github.com/medium · scripts/github_utils.py:21 · Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
  • Dangerous Code Execution: subprocess.run(args, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True)medium · scripts/install-skill-from-github.py:100 · subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Structure

  • Ships 3 executable scriptsscripts/github_utils.py, scripts/install-skill-from-github.py, scripts/list-skills.py. Review what they do before enabling the skill for agents with tool access.

SKILL.md

---
name: skill-installer
description: Install Codex skills into $CODEX_HOME/skills from a curated list or a GitHub repo path. Use when a user asks to list installable skills, install a curated skill, or install a skill from another repo (including private repos).
metadata:
  short-description: Install curated skills from openai/skills or other repos
---

# Skill Installer

Helps install skills. By default these are from https://github.com/openai/skills/tree/main/skills/.curated, but users can also provide other locations.

Use the helper scripts based on the task:
- List skills when the user asks what is available, or if the user uses this skill without specifying what to do. Default listing is `.curated`, but you can pass `--path skills/.experimental` when they ask about experimental skills.
- Install from the curated list when the user provides a skill name.
- Install from another repo when the user provides a GitHub repo/path (including private repos).

Install skills with the helper scripts.

## Communication

When listing skills, output approximately as follows, depending on the context of the user's request. If they ask about experimental skills, list from `.experimental` instead of `.curated` and label the source accordingly:
"""
Skills from {repo}:
1. skill-1
2. skill-2 (already installed)
3. ...
Which ones would you like installed?
"""

After installing a skill, tell the user it will be available on their next turn.

## Scripts

All of these scripts use network, so when running in the sandbox, request escalation when running them.

- `scripts/list-skills.py` (prints skills list with installed annotations)
- `scripts/list-skills.py --format json`
- Example (experimental list): `scripts/list-skills.py --path skills/.experimental`
- `scripts/install-skill-from-github.py --repo <owner>/<repo> --path <path/to/skill> [<path/to/skill> ...]`
- `scripts/install-skill-from-github.py --url https://github.com/<owner>/<repo>/tree/<ref>/<path>`
- Example (experimental skill): `scripts/install-skill-from-github.py --repo openai/skills --path skills/.experimental/<skill-name>`

## Behavior and Options

- Defaults to direct download for public GitHub repos.
- If download fails with auth/permission errors, falls back to git sparse checkout.
- Aborts if the destination skill directory already exists.
- Installs into `$CODEX_HOME/skills/<skill-name>` (defaults to `~/.codex/skills`).
- Multiple `--path` values install multiple skills in one run, each named from the path basename unless `--name` is supplied.
- Options: `--ref <ref>` (default `main`), `--dest <path>`, `--method auto|download|git`.

## Notes

- Curated listing is fetched from `https://github.com/openai/skills/tree/main/skills/.curated` via the GitHub API. If it is unavailable, explain the error and exit.
- Private GitHub repos can be accessed via existing git credentials or optional `GITHUB_TOKEN`/`GH_TOKEN` for download.
- Git fallback tries HTTPS first, then SSH.
- The skills at https://github.com/openai/skills/tree/main/skills/.system are preinstalled, so no need to help users install those. If they ask, just explain this. If they insist, you can download and overwrite.
- Installed annotations come from `$CODEX_HOME/skills`.