Skill Installer

Official Codex skill for listing and installing skills from curated OpenAI sources or GitHub repositories.

Skill Installer is an official sample skill from the OpenAI Codex repository. The verified primary source is https://github.com/openai/codex/tree/main/codex-rs/skills/src/assets/samples/skill-installer. It helps Codex discover skills for a local working environment and install them into the skills directory. The candidate source reported by Smithery originally pointed to codex-rs/core/src/skills/assets/samples/skill-installer. That path is no longer reachable on the current main branch. The verified, semantically matching primary source is codex-rs/skills/src/assets/samples/skill-installer, which contains SKILL.md and the supporting helper scripts. According to the provider, the skill covers three common situations: listing available skills, installing a named skill from the curated collection, and installing a skill from a GitHub repository and a supplied path.

Purpose and workflow

The skill packages a repeatable installation workflow without becoming a general package manager. For a listing it uses list-skills.py. The default collection is the curated area of the official openai/skills repository; experimental skills can be requested explicitly through the experimental path. For GitHub installation, the instructions point to install-skill-from-github.py. A repository owner and name, a path inside the repository, or a complete GitHub URL can be supplied. The default method downloads directly. If permission or authentication failures occur, the intended Git fallback can be used.

The destination is the skills directory below CODEX_HOME/skills, while an environment can provide its own CODEX_HOME value. Without that variable, Codex uses the user-directory default described by the provider. Several paths can be installed in one operation. A name option can set the destination name; otherwise the name is derived from the final path component. The workflow aborts when the destination already exists, preventing an existing installation from being overwritten silently. After a successful installation, the user should be told that the skill will be available on the next turn. The official documentation also explains that a restart may be needed if a newly installed capability does not appear immediately.

Practical value and boundaries

Skill Installer is useful when a team wants to extend Codex deliberately without rewriting installation instructions for every individual skill directory. It makes the source and destination of an installation more explicit and separates curated, experimental, and repository-based sources. It does not guarantee the quality of the installed skill. An accessible GitHub repository proves neither that its scripts are safe nor that every instruction it contains is trustworthy. Before team-wide use, review the repository, revision, license, change history, and required tools.

The skill is not an OpenAI API client, an MCP server, or a central permission manager. It installs files into a local Codex environment. Network access occurs during the intended listing and download operations; private repositories may depend on existing Git credentials or already configured authentication. Credentials, tokens, private source code, and confidential project data do not belong in the skill description or installation examples. Installed material can contain instructions and scripts that are later used in an agent context. Teams should therefore require a controlled working copy, least-privilege access, and human review before productive changes.

Classification and security

The official Codex documentation describes skills as directories with a required SKILL.md and optional scripts, references, or resources. Skill Installer follows that model by installing complete skill directories rather than isolated text fragments. According to the provider, system skills are already preinstalled and normally do not need to be installed again. Anyone who nevertheless wants to overwrite a system skill should review the consequences and local configuration explicitly. A local skill can be disabled through the relevant skills entry in Codex configuration without immediately deleting its files.

The canonical source for this catalog entry is the current Codex path at codex-rs/skills/src/assets/samples/skill-installer; the original candidate URL is preserved as an outdated registry mapping. The Codex repository publishes its source under Apache-2.0. GitHub stars are not stored because the Skill model has no github_stars field. This classification was reviewed on September 9, 2026. Skill Installer makes local distribution easier, but it does not replace dependency review, permission review, or approval by the responsible person.

Free
Provider
OpenAI
License
Apache-2.0
Last reviewed
09.09.2026

Repository and documentation

Categories

Compatible with

Codex