Copy the complete install command
For a Skill published in a GitHub repository, the universal installer accepts the repository URL, Skill name, and Codex target. Run it from the repository where you want the project-scoped Skill. Add -g only for a personal installation.
Replace the placeholders with the source shown on the Skill profile. If the source cannot produce a reliable command, open the linked source and copy the complete Skill folder instead of guessing a repository path.
npx skills add <github-repository-url> --skill <skill-name> --agent codexnpx skills add <github-repository-url> --skill <skill-name> --agent codex -gProject scope or personal scope?
Project installation places a Skill under .agents/skills/<skill>/ in the current repository. It is the recommended default because the source, instructions, and changes can be reviewed alongside the project. A teammate receives the same Skill folder when it is committed.
Personal installation places it under ~/.agents/skills/<skill>/ and makes it available across repositories. That convenience also widens the discovery boundary: use it only when the workflow, permissions, and maintenance owner are genuinely the same across projects.
- Choose project scope for repository-specific conventions or team sharing.
- Choose personal scope only for a deliberately cross-project workflow.
- Do not install both copies unless you can explain which one Codex should use.
Inspect the source before installation
Read SKILL.md and every referenced script, template, or configuration file. Record the repository and revision you reviewed. A short instruction file can still delegate powerful behavior to a bundled script or external service.
Compare the requested access with the first task. A formatting or review Skill should not need publishing credentials, destructive commands, or broad network access merely because those capabilities are available in the Agent environment.
- The source repository and reviewed revision are recorded.
- Referenced files and scripts are present and understandable.
- Network, command, write, credential, and publishing access match the first task.
- The source offers a clear update or removal path.
Five useful starter roles—not five automatic installs
A balanced developer stack can cover discovery, planning, reusable workflow design, change review, and behavioral evidence. The corresponding SkillSignal shortlist is find-skills, create-implementation-plan, skill-creator, differential-review, and webapp-testing.
Treat those names as role examples, not a universal ranking. Install the one that solves the current bottleneck first. Add another only when it produces a distinct artifact that someone will inspect; replace the evidence role when the product is not a web application.
Verify discovery with one controlled task
After installation, confirm that the expected Skill name and description are discoverable in Codex. Then choose a small, reversible task with a clear input, output, stop condition, and rollback. Record which files, commands, network calls, and outputs the run actually used.
A successful first run is local evidence for that source revision, repository, environment, and task. It is not a permanent compatibility or safety certificate. Recheck after source updates, Agent changes, new scripts, or permission expansion.
- Codex discovers the intended copy and scope.
- The trigger matches the intended task and stays inactive for an unrelated task.
- The run remains inside the agreed files, commands, and services.
- The output passes a human-reviewable acceptance check.
- Rollback returns the repository to its starting state.
Keep the installation smaller than the collection
Review installed Skills monthly by role, source revision, last use, permissions, output owner, and last successful controlled test. Remove a duplicate or unclear Skill before adding a new one.
The goal is not to accumulate every useful package. It is to keep the smallest set whose behavior, sources, and outputs you can still explain. Project scope makes that maintenance easier; personal scope should remain the exception you can justify.