skill-installer
Install Codex Skills from GitHub
Installing skills manually requires choosing sources, authentication, and destination settings. This skill guides curated and GitHub installations through standard helper commands.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "skill-installer" from https://skillstore.io/skills/davila7-skill-installer.md and its manifest at https://skillstore.io/api/skills/davila7-skill-installer/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "skill-installer". List curated skills and show which ones are installed.
Expected outcome:
Skills from openai/skills: skill-a; skill-b, already installed. Which skill should be installed?
Using "skill-installer". Install the reviewed skill named skill-a.
Expected outcome:
Installed skill-a in the configured Codex skills directory. Restart Codex to load the new skill.
Security Audit
High RiskAll 20 static findings are false positives caused by Markdown code spans, expected GitHub URLs, documented installation paths, or token-name references. Two semantic risks remain: unverified installation from mutable remote sources and permission to overwrite preinstalled system skills. The package contains only SKILL.md, so referenced helper scripts were not available for review.
Confirmed security concerns (2)
Risk Factors
โ๏ธ External commands (10)
๐ Network access (4)
๐ Filesystem access (5)
๐ Env variables (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/davila7-skill-installer/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/davila7-skill-installer?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/davila7-skill-installer?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/davila7-skill-installer/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/davila7-skill-installer.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
davila7. (2026). skill-installer security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/davila7-skill-installer/audits/10BibTeX citation
@techreport{davila7-davila7-skill-installer-2026,
author = {davila7},
title = {skill-installer security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/davila7-skill-installer/audits/10},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "skill-installer security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "davila7"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/davila7-skill-installer/audits/10"
identifiers:
- type: other
value: "skillstore:davila7-skill-installer:audit:10"
description: "Skillstore immutable audit report identifier"
Compare variants
2 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
skill-installer
2026-09-09
davila7-skill-installer
2026-09-09
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Browse curated skills
An individual developer lists available skills and identifies which are already installed.
Install a team skill
An engineering lead installs a reviewed skill from a private GitHub repository using existing credentials.
Control managed setup
A platform engineer selects a pinned ref, custom destination, and transfer method for a managed workstation.
Try These Prompts
List the curated skills available from the default repository. Mark which skills are already installed.
Install the curated skill named [skill-name]. Confirm the source and destination before running the helper.
Install the skill at [GitHub URL] using ref [commit SHA]. Review the source and show the destination before installation.
Install [path one] and [path two] from [owner/repository] at [commit SHA]. Use existing credentials, destination [path], and the git method.
Best Practices
- Review each repository and use an immutable commit before installation.
- Use least-privilege credentials and keep tokens outside prompts and logs.
- Confirm the destination, then restart Codex after a successful installation.
Avoid
- Do not install skills from unknown repositories or mutable refs without review.
- Do not expose GitHub tokens in prompts, command output, or shared logs.
- Do not overwrite preinstalled system skills through routine installation workflows.