Find and Install Codex Skills from GitHub

31 August 2026 · updated 06 September 2026 · 2,790 words

Professional header image for educational tutorial: How to Find and Install Codex Skills from GitHub

If you have been working with AI-powered development tools, you already know that extensibility is what separates a useful assistant from a truly powerful one. Codex, OpenAI's coding-focused AI system, becomes significantly more capable when you expand its functionality through custom skills. And one of the best places to source those skills is directly from the community-driven repositories on GitHub.

In this tutorial, you will learn exactly how to find a codex github skill that fits your workflow, evaluate its quality and compatibility, and install it correctly within your environment. Whether you are looking to automate repetitive tasks, add new language support, or integrate specialized tooling, the process follows a consistent pattern once you understand the underlying structure.

By the end of this guide, you will be comfortable navigating GitHub repositories for Codex-compatible skills, understanding the basic configuration files involved, and troubleshooting common installation issues. No advanced system administration experience is required, but familiarity with the command line and basic Git operations will help you follow along smoothly. Let's get started.

What a SKILL.md File Does
What a SKILL.md File Does

What a SKILL.md File Does

A SKILL.md file is a trigger-driven instruction package. It activates only when the task an agent receives matches its declared trigger conditions, and stays completely dormant otherwise. Nothing loads into the context window until the match fires. That single design decision is what makes skills practical at scale: a developer can install dozens of them without bloating every prompt.

The format is plain markdown. There is no binary, no compiled artifact, no runtime dependency to install. A minimal file has two parts: a frontmatter block declaring name, version, and trigger conditions, followed by a fenced instructions block containing the procedural steps the agent follows. A representative skeleton looks like this:

---
name: write-commit-message
version: 1.0.0
triggers:
 - "commit"
 - "write a commit message"
---

## Instructions

Generate a conventional commit message from the staged diff.

The triggers field is the most consequential part of the file. A vague or missing trigger means the skill never fires, regardless of how precise the instructions inside are. Write the trigger to match exactly how a developer would phrase the task.

OpenAI launched Codex Skills experimentally in December 2025. By early 2026 the SKILL.md format had been adopted as a cross-platform open standard across Claude Code, Gemini CLI, Cursor, GitHub Copilot, and more than 20 other AI coding tools. OpenAI's own skills repository has drawn tens of thousands of stars, which reflects how fast practitioners picked the format up.

Progressive loading is what keeps multi-skill setups lean. At session start, the agent reads only each skill's name and description. It pulls the full instructions only when a trigger fires. Supporting files bundled inside the skill folder load only if the instructions explicitly reference them. Per current analysis of the most-used skills in production, a developer can have fifty skills installed and the context window stays clean because the agent pulls in the two it needs and ignores the rest.

Skills and MCP servers are complementary layers, not competing ones. MCP gives the agent access to tools and APIs. A SKILL.md file gives it the instructions for using those tools correctly. Moltline Studio publishes 138 free SKILL.md files at GarphenGate/moltline-oss, covering tasks that pair directly with the 160 tools exposed across its 22 hosted MCP servers.

Where to Find Skills on GitHub

The two GitHub topic pages are the fastest cold-start points. github.com/topics/codex-skills lists every repository that has self-tagged with that topic, sortable by stars or most recently pushed. The broader github.com/topics/ai-skills topic catches cross-platform collections that cover Codex alongside other runtimes. Both pages update in real time as maintainers push new tags, so checking them periodically surfaces repos that predate the curated lists.

Curated Awesome Lists

For a filtered starting point, composio-community/awesome-codex-skills is the most-starred curated collection in this space, with north of fifteen thousand stars. Its README makes an architectural point worth internalising: skills tell an agent how to work, while an MCP gateway gives it secure access to the tools it needs. The two layers are complementary. That framing directly mirrors how Moltline's 138 free SKILL.md files at GarphenGate/moltline-oss pair with its hosted MCP servers; neither replaces the other.

heilcheng/awesome-agent-skills takes a wider cross-platform view, covering skills compatible with Codex, Claude Code, Gemini CLI, and Cursor from a single collection. It publishes its README in six languages: English, Spanish, Japanese, Korean, simplified Chinese, and traditional Chinese. That multilingual reach signals genuine international adoption, not just English-language hype.

Vendor-Published Skills Directory

When you want officially maintained skills rather than community submissions, mcpservers.org/agent-skills organises its library by vendor. Current counts: Microsoft at 1,577 skills, Anthropic at 927, OpenAI at 746, GitHub at 567, and Vercel at 396. Vendor-published skills tend to have clearer maintenance commitments and version histories, making them lower-risk for production use.

Supply-Chain Caveat

Community repositories are unreviewed by default. Before dropping any community SKILL.md into ~/.codex/skills/, read it line by line. Look for outbound network calls, unexpected dependency declarations, and anything that writes outside a sandboxed path. Plain-text, auditable files are the only format where that inspection is even possible, which is why the Moltline OSS repo publishes plain SKILL.md files rather than compiled or obfuscated packages.

How to Install a Skill in Codex

Codex CLI scans ~/.codex/skills/ on startup and loads any valid skill folders it finds there. No config file edit is required. If you have set the $CODEX_HOME environment variable to a custom path, the directory becomes $CODEX_HOME/skills/ instead. Create the directory first if it does not exist:

mkdir -p ~/.codex/skills/

Installing from GarphenGate/moltline-oss

Moltline Studio publishes 138 free SKILL.md files at GarphenGate/moltline-oss. The repository is public, requires no account, no API key, and no signup to clone. The files are covered by the Moltline Free Skills License: free to use with any agent for personal or commercial work, with redistribution as a skill pack or marketplace listing reserved to Moltline. The install sequence is:

git clone https://github.com/GarphenGate/moltline-oss
cp -r moltline-oss/skills/<skill-name> ~/.codex/skills/

Then restart Codex. The skill triggers automatically when a task matches its declared conditions. You do not wire anything up manually; Codex reads the skill folder on startup and activates it when the trigger fires.

Installing from Any Other Public Repository

The same pattern applies to any public skill source. Clone or download the repository, copy the skill folder into ~/.codex/skills/, and restart. A real-world example of the folder structure is visible in the codex-review-workflow-skill repository, which places SKILL.md at the root of the skill folder. That root placement is required; if the file is nested further down, Codex will not recognize the skill.

One important constraint: Codex does not validate the source of installed skills. It will load whatever is in the skills directory. Auditing is your responsibility. Read the SKILL.md content before installing from an unfamiliar repository. Check any referenced scripts or external calls. The Agensi skills directory runs security scans on listed skills, but those scans are not a guarantee of safety.

Verifying the Install

Run a task that matches the skill's declared trigger. If the skill fires, Codex will reference it in its reasoning output. If it does not fire, two things to check: confirm the folder exists inside ~/.codex/skills/ and confirm it contains a valid SKILL.md at its root, not in a subdirectory. Skill names are case-sensitive on Linux; match the folder name exactly to what was in the source repository. To remove a skill, delete its folder from the skills directory and restart Codex.

The 138 Free SKILL.md Files at GarphenGate/moltline-oss

The 138 Free SKILL.md Files at GarphenGate/moltline-oss
The 138 Free SKILL.md Files at GarphenGate/moltline-oss

GarphenGate/moltline-oss holds 138 open SKILL.md files, each built alongside one of the 22 hosted MCP servers at moltlinestudio.com. The pairing is intentional. Rather than writing generic agent instructions, each skill is structured to complement a specific server or tooling pattern, so the trigger conditions, context blocks, and instructions align with what the corresponding MCP tools actually expose. If you are already using a Moltline server endpoint, the matching skill gives your agent the behavioral layer that makes those tools useful without you having to author it from scratch.

Auditability Before Installation

Every file in the repo is plain text and readable line by line before you copy anything into ~/.codex/skills/. That matters because a SKILL.md file has direct write access to an agent's instruction context. An unreviewed file from an unknown community repo could inject arbitrary instructions, override trigger conditions you did not set, or silently expand the agent's permitted action scope. With GarphenGate/moltline-oss, you open the file, read the frontmatter, check the trigger declaration, and inspect the instructions block before the skill ever touches your environment. There is no black-box install step.

The SKILL.md Linter

The linter is not a CLI you install — it is one of the 22 hosted MCP servers, at https://mcp.moltlinestudio.com/skillmd-lint, with six free tools and no account or API key. Wire it into Codex the same way as any other Streamable HTTP server, then hand it the text of a SKILL.md file and ask it to lint. It catches malformed frontmatter, missing trigger declarations, and instructions blocks that run past a sensible length.

Running it as an MCP server rather than a local binary has one practical advantage for this particular job: you can lint a skill you are considering installing, from inside the agent session, before the file ever lands in ~/.codex/skills/. It works on files from any source, not only the Moltline collection.

The Agent-Readiness Checker

The agent-readiness checker is a separate free tool, and it answers a different question than the linter does. It lives at moltlinestudio.com/agent-check.html, takes a public domain rather than a local path, and scores that domain against 21 checks covering discovery and identity, machine-readable content, commerce and payment, trust and security, and agent access hygiene — returning the fix for each failure. No signup, no API key.

So it tells you what an autonomous agent sees when it arrives at a site you operate. It does not inspect a local codebase; if you want to know whether your own repo is legible to a coding agent, that is a manual review, not this tool.

Why Skills and MCP Servers Pair Together

A SKILL.md file encodes workflow logic. An MCP server exposes executable tools. These are different layers of the same stack, and conflating them is the most common mistake developers make when first wiring up an agent environment. The skill tells Codex how to approach a class of tasks: which steps to follow, which guardrails to apply, when to pause for confirmation. The MCP server provides the actual function calls the skill can invoke. Neither layer substitutes for the other.

The setup reflects this separation. Clone the relevant skill from GarphenGate/moltline-oss and copy the skill folder to ~/.codex/skills/. Separately, open your Codex MCP config and paste the server endpoint, for example https://mcp.moltlinestudio.com/codereview, as a Streamable HTTP entry. Codex loads both layers independently on startup. The skill activates when a task matches its trigger conditions. The MCP tools appear in Codex's tool registry as soon as the endpoint is registered. You can run either without the other, but the combination is where the pattern pays off: the skill provides the decision logic, and the MCP server provides the execution surface that logic calls into.

On the MCP side, 110 of the 160 tools across all 22 hosted servers are free. No account. No API key. No signup form. Paste the endpoint URL and the tools are available immediately. This matters because the usual friction point with MCP adoption is authentication overhead, not the protocol itself. Removing that barrier entirely for the majority of tools means a developer can validate the pairing pattern in under five minutes.

The remaining 50 tools sit behind the $19/month All-Access licence, billed monthly through NOWPayments and payable in cryptocurrency. One key covers the premium tools on all 22 servers rather than being metered per server or per call, so the cost does not move with how many projects you point it at. Teams that need seats on one invoice can ask about the $99/month Team plan listed on moltlinestudio.com (five seats on one invoice, arranged by email rather than self-serve checkout); the $19 tier is the individual one.

Every server is built and operated by Moltline directly; there are no proxied third-party integrations in the stack. This has a practical consequence for anyone writing skills against these servers: the tool schemas are stable and the provenance is auditable. A skill written today against mcp.moltlinestudio.com/codereview will not break because an upstream vendor changed an API wrapper. The MCP server code and the SKILL.md files in moltline-oss share the same origin, which means the skill's assumptions about tool behaviour are grounded in the actual implementation. That auditability is increasingly relevant as community skill libraries grow and the provenance of a skill becomes a supply-chain question.

The x402 Machine Payment Flow

Hit moltlinestudio.com/api directly and the server does not return a resource. It returns an HTTP 402 status with a JSON body containing the price and the on-chain settlement address. No session, no login prompt, no redirect. The payload is plain JSON, readable in a browser or with curl without any client library installed.

The agent flow from that point is fully programmatic. The agent reads the 402 payload, signs a stablecoin payment authorization using its wallet, and re-submits the original request with an X-PAYMENT header containing the signed payload. The server verifies the signature and returns 200 OK with the resource. No OAuth redirect, no webhook callback, no human clicking approve. The tool unlocks within the same request cycle.

This is an implementation of x402, an open payment protocol launched in May 2025. The HTTP 402 status code has existed since 1997 but sat dormant for lack of a viable micropayment rail. Stablecoins on Base, with sub-$0.001 transaction costs and second-level confirmation, provided that rail.

The practical value for agent pipelines is concrete. Traditional API access requires hardcoded keys, pre-purchased plans, and a human completing a payment flow before the agent can run. x402 eliminates that entirely. The agent discovers the price at runtime, settles on-chain, and acquires the tool, all without a human in the loop. This matches documented x402 use cases including premium API access without pre-approval and pay-per-use compute.

Your agent will need a funded wallet capable of signing USDC transactions on Base before this flow works. That is a prerequisite the protocol itself does not handle.

Next Steps

Clone the repo and drop any skill folder into place:

git clone https://github.com/GarphenGate/moltline-oss
cp -r moltline-oss/skills/your-chosen-skill ~/.codex/skills/

Restart Codex and the skill is live. No config edits required.

Browse the 22 MCP servers at mcp.moltlinestudio.com. Each server has a direct Streamable HTTP endpoint at mcp.moltlinestudio.com/<server-slug>. Paste that URL into Codex CLI, Claude Code, Cursor, or any other MCP client. The 110 free tools activate immediately, no account and no API key needed.

Run the agent-readiness checker against any domain you operate before you point agents at it. It scores the site on 21 checks and names the fix for each failure, so you find out where an autonomous agent would fail on your surface before one does in production. The Codex Prompting Guide covers related grounding practices worth reading alongside it.

Run the SKILL.md linter on any community skill before installing it. Poorly scoped skills with duplicate front matter or overlapping triggers consume context budget fast and produce inconsistent output. Catch structural errors at install time rather than during a live agent run.

If you need the 50 premium tools, the All-Access licence is $19/month, paid in cryptocurrency through NOWPayments at moltlinestudio.com. The x402 endpoint at /api settles the same month machine-to-machine — an agent reads the price out of the HTTP 402 and pays in USDC on Base without a human present. Same product, two counters.

Conclusion

Expanding Codex through GitHub skills is one of the most practical ways to make your AI development environment work harder for you. To recap the essentials: you now know how to search GitHub for compatible Codex skills, evaluate repository quality before committing to an install, follow the correct configuration steps, and troubleshoot the most common issues that arise along the way.

The real power here is momentum. Every skill you add compounds your productivity, reducing the manual work that slows down your development cycle.

Your next step is simple. Head to GitHub right now, search for a Codex skill that addresses a pain point in your current workflow, and walk through the installation process using what you have learned today. The community is actively building, sharing, and improving these tools. All you have to do is show up and start exploring.

Try it rather than read about it

22 hosted MCP servers, 160 tools, 110 of them free. No account, no API key, no signup — paste a URL into your client and the tools are there.

Browse the servers
← All posts