Skip to content
Back to skills

Skill Installer

ASecurity

Install Codex skills into the canonical git source tree from a curated list or a GitHub repo path. Use when a user asks to list installable skills, install a curated skill, or install a skill from another repo (including private repos).

  • 9 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added June 1, 2026
ai-agentsrustgit

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned June 1, 2026

npx -y skills add jscraik/Agent-Skills --skill skill-installer --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skill Installer?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Skill Installer
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jscraik-skill-installer/badge)](https://www.skillsdirectory.com/skills/jscraik-skill-installer)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: skill-installer
description: Install Codex skills into the canonical git source tree from a curated list or a GitHub repo path. Use when a user asks to list installable skills, install a curated skill, or install a skill from another repo (including private repos).
metadata:
  short-description: Install curated skills from openai/skills or other repos
  skill-type: infrastructure_ops
---

# Skill Installer

Use this skill for listing and installing skills from trusted sources.

## When to use
- List available installable skills.
- Install from curated catalog or explicit GitHub repo/path.
- Verify install destination and runtime visibility.

## Do not use
- Skill creation or refactor design work: route to `[[skill-creator]]`.
- Release-hardening/eval work: route to `[[skill-builder]]`.

## Core Philosophy
- Verify source and destination before writing anything.
- Prefer explicit user intent over inferred replacement behavior.
- Preserve required operational context in `references/` with clear signposts.

## Core workflow
1. Classify request: `list` or `install`.
2. Resolve source and destination with explicit user intent.
3. Run minimal installer helper command.
4. Verify resulting filesystem state.
5. Report exact paths and restart requirement.

## Required output contract
Provide:
- `schema_version`
- `mode`
- `source`
- `destination`
- `validation_evidence`
- `restart_required`

## Progressive disclosure policy
Apply the context-disposition policy: move important still-valid context to references, and intentionally discard stale, duplicated, unsafe, superseded, or low-signal text.

Read when:
- handling source and install safety caveats: [install flows](./references/install-flows.md)
- handling failures: [troubleshooting](./references/troubleshooting.md)
- verifying policy boundaries: [contract](./references/contract.yaml)

## Anti-Patterns to Avoid
- Overwriting existing installs without explicit confirmation.
- Treating untrusted URLs or paths as safe inputs.
- Reporting success without filesystem verification evidence.

## Constraints
- Do not overwrite existing installs without explicit confirmation.
- Treat URLs and paths as untrusted input.
- Redact tokens, credentials, and secret values.

Files in this skill

  • LICENSE.txt141 B
  • SKILL.md2.2 KB
  • agents/openai.yaml217 B
  • assets/skill-installer-small.svg201 B
  • assets/skill-installer.png12.7 KB
  • references/contract.yaml750 B
  • references/evals.yaml2 KB
  • references/install-flows.md3 KB
  • references/task-profile.json1.4 KB
  • references/troubleshooting.md1.4 KB
  • scripts/github_utils.py379 B
  • scripts/install-skill-from-github.py155 B
  • scripts/install-skill-from-github.pyw33.3 KB
  • scripts/list-skills.py155 B
  • scripts/list-skills.pyw4.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…