Set up OpenAI Skill Installer

The Skill Installer adds OpenAI Codex skills from curated lists or GitHub repositories into local agent workflows and projects.

Published on 09.09.2026

What the Skill Installer is and why it matters

The Skill Installer is a system skill from OpenAI that is built directly into the openai/skills repository at skills/.system/skill-installer and ships by default with OpenAI's Codex CLI tool. Codex is OpenAI's command-line assistant for coding tasks, conceptually comparable to Claude Code, and likewise uses a skill system in which individual markdown files with instructions provide additional knowledge or capabilities. The Skill Installer's job is to install further skills, either from OpenAI's curated list under skills/.curated in the same repository or from any other GitHub repository, including private repositories, when the appropriate credentials are available. The skill is relevant for anyone who wants to extend Codex with additional community or internal company capabilities without manually copying files into the right directory.

Prerequisites

Since the Skill Installer already ships as a preinstalled system skill with every Codex installation, all that is initially needed is a working Codex CLI installation. Installing skills themselves requires network access, so the underlying helper scripts, per the documentation, need explicit permission for network access when running inside a sandboxed environment. Anyone wanting to install skills from private GitHub repositories needs either existing git credentials already present on the system or an environment variable holding a GitHub token, named either GITHUB_TOKEN or GH_TOKEN.

Setting it up step by step

Because the skill is already preinstalled, there is no separate setup step for the skill itself; it is used directly by asking Codex for it. To first see which skills are available, you can request the curated list, where the underlying script by default reads the .curated folder and can be switched to the .experimental folder via the --path option to view experimental skills. Installing a specific skill from the curated list only requires naming it, after which the install-skill-from-github.py script creates the skill under the CODEX_HOME/skills directory named after the skill, defaulting to the .codex/skills path inside the user's home directory. For skills from other repositories, you instead provide either the repository path together with the path to the skill inside that repository, or the full GitHub URL to the corresponding directory directly, optionally combined with a different branch name via the --ref option.

Security and best practices

Because installing a skill from an arbitrary GitHub repository means adopting instructions, and sometimes executable helper scripts, written by a third party, the content of a SKILL.md file and any referenced scripts should be reviewed before installation, especially when the source is not OpenAI's curated list. The curated list is at least subject to editorial selection by OpenAI, while arbitrary GitHub repositories are not, and should be treated with the same caution as any other external code dependency. Per the documentation, the installer aborts if the destination directory already exists, which prevents accidental overwrites; the preinstalled system skills under .system can be overwritten if a user explicitly insists, but this is generally not recommended.

Practical example and limitations

A typical call is asking the Skill Installer to install a specific experimental skill, such as a planning skill from the .experimental folder, or alternatively providing a GitHub directory URL of a third-party repository directly to install a skill from it. The limitations are that the installer itself performs no content or security review of the skill being installed, only handling the transfer process, and that it is built exclusively for Codex's directory structure. It therefore cannot be used directly for Claude Code, since both systems follow a similar underlying concept but use different storage locations and configuration formats for skills.

Published on 09.09.2026

Categories

Frequently asked questions

Does the skill automatically trust arbitrary GitHub content?

No. It supports repository paths, but the source, revision, files, and permissions must be reviewed before use.

What happens when an installation already exists?

The intended workflow aborts so an existing destination is not silently overwritten.