codex-skills
Research Date: 2026-02-20
Source URL: https://github.com/jMerta/codex-skills
GitHub Repository: https://github.com/jMerta/codex-skills
Version at Research: v2.0.0
License: MIT
Overview
codex-skills is a curated skill catalog for the OpenAI Codex CLI, providing drop-in skill folders that extend the agent with specialized workflows. Skills are installed into ~/.agents/skills/ and auto-discovered by Codex via SKILL.md frontmatter. A companion npm CLI (npx codex-skills) enables listing, searching, installing individual skills, and installing entire categories without cloning the repository.
Problem Addressed
| Problem |
Solution |
| Codex CLI ships with no built-in specialized workflows |
Pre-built skills for git, CI, planning, docs, and operations give Codex immediate domain expertise |
| Reusing agent instructions across projects requires manual file copying |
npx codex-skills install <name> copies a versioned skill folder into the standard catalog location |
No standard convention for agent-context files (AGENTS.md) |
agents-md skill + init-ledger command establish the ledger pattern for cross-session state |
| Prompt injection via invisible Unicode characters in agent inputs |
CI pipeline runs check_invisible_chars.py on file contents, PR metadata, and commit messages |
| Hard-coded skill locations break when switching between user and repo scope |
--dir <dir> flag selects between ~/.agents/skills/ (user) and .agents/skills/ (repo-local) |
Key Statistics
| Metric |
Value |
Date Gathered |
| GitHub Stars |
116 |
2026-02-20 |
| Forks |
11 |
2026-02-20 |
| Contributors |
1 (jMerta) |
2026-02-20 |
| Latest Release |
v2.0.0 |
2026-02-06 |
| Total Skills in Catalog |
19 |
2026-02-20 |
| npm package |
codex-skills |
2026-02-20 |
Key Features
Skill Catalog (19 skills at v2.0.0)
plan-work -- repo-grounded research, risk analysis, Q&A-gated implementation planning
bug-triage -- reproduce, isolate, and fix bugs with root-cause summary
ci-fix -- diagnose and fix GitHub Actions failures via gh CLI
commit-work -- staged splitting + Conventional Commit message generation
create-pr -- branch, lint/build, commit, and PR description with validation steps
coding-guidelines-gen -- generate nested AGENTS.md per module, configure formatters/linters
coding-guidelines-verify -- scoped compliance checks, auto-format, lint/test run
dependency-upgrader -- safe incremental bump for Java/Kotlin (Gradle/Maven) and Node/TS
docs-sync -- keep README, API docs, runbooks in sync with code changes
release-notes -- draft changelogs and GitHub Release bodies from git ranges
agents-md -- create/update root and nested AGENTS.md with module maps and feature maps
branch-cleaner -- audit and prune stale git branches locally and on remotes
rebase-assistant -- safe rebase onto target branch with conflict triage steps
regex-builder -- build, test, explain regexes using rg and Python against sample files
vps-checkup -- read-only Ubuntu VPS health/security report over SSH; applies changes only on confirmation
sessions-to-blog -- convert session logs to MDX blog posts with project style rules
- Third-party:
create-cli (steipete), video-transcript-downloader (steipete), ui-ux-pro-max (Next Level Builder)
Skill Structure Convention
- Each skill is a directory containing
SKILL.md (YAML frontmatter + Markdown body)
- Frontmatter fields:
name (<=100 chars, single line), description (<=500 chars, single line)
- Optional subdirectories:
references/, scripts/, assets/
- Only
name, description, and SKILL.md path are injected into Codex context; bodies are loaded on demand
CLI Tool (npx codex-skills)
list / ls -- all skills grouped by category, supports --json
search <query> -- search by name/description/category
install <name> -- copy skill to skills directory from GitHub release tarball
install-category <category> -- install all skills in a category
install-all -- install every skill in the catalog
install-agent-scripts -- install shared shell scripts alongside skills
init-ledger -- create ~/.codex/AGENTS.MD global context ledger
verify <name> -- validate local skill install (SKILL.md + frontmatter)
--dir <dir> flag for user (~/.agents/skills/) vs. repo-local (.agents/skills/) scope
Global Ledger Pattern
init-ledger creates ~/.codex/AGENTS.MD as a cross-project agent context file
- Ledger headings: Goal, Constraints/Assumptions, Key decisions, State, Done/Now/Next, Open questions, Working set
- Not a skill -- applies globally to all Codex sessions across projects
Security: Prompt-Injection Hardening
scripts/check_invisible_chars.py scans file contents, filenames, PR metadata (title/body), and commit messages for invisible/suspicious Unicode characters (zero-width, directional overrides, etc.)
- GitHub Actions CI runs check on every push and PR
- Run locally:
python3 scripts/check_invisible_chars.py --all
Registry Maintenance Pipeline
skills-meta.json -- category/author/license overrides per skill
skills.json -- full machine-readable catalog generated by scripts/build_skills_json.py
scripts/validate_skills.py -- validates SKILL.md frontmatter (no PyYAML dependency since v2.0.0)
- GitHub Pages at
https://jmerta.github.io/codex-skills/ publishes the catalog on each release
Technical Architecture
codex-skills/
<skill-name>/
SKILL.md # YAML frontmatter (name, description) + Markdown workflow body
references/ # Extended templates, checklists (loaded on demand)
scripts/ # Optional helper scripts for the skill
assets/ # Optional assets
agent-scripts/ # Shared shell scripts installable via install-agent-scripts
agents-md/ # agents-md skill
cli/
bin/codex-skills.js # npm CLI entry point (Node.js, single dependency: tar)
package.json # npm package definition (name: codex-skills, v2.0.0)
test/ # Node.js built-in test runner
scripts/
build_skills_json.py # Regenerates skills.json from skill folders + skills-meta.json
validate_skills.py # Validates SKILL.md frontmatter (stdlib only)
check_invisible_chars.py # Scans for Unicode prompt-injection vectors
skills.json # Machine-readable catalog (version, total, skills array, categories)
skills-meta.json # Overrides for category/author/license per skill
AGENTS.md # Repo-scoped agent instructions
LEDGER-PATTERN.md # Documentation of the cross-session ledger pattern
Codex discovery mechanism:
- User scope:
~/.agents/skills/**/SKILL.md (legacy: ~/.codex/skills/**/SKILL.md)
- Repo scope:
.agents/skills/**/SKILL.md
- Only
name, description, and path from frontmatter enter Codex context; full SKILL.md body is read on demand
CLI install mechanism:
- Fetches
skills.json from the selected GitHub ref (latest release by default, --ref to override)
- Downloads repo tarball for the ref via GitHub API
- Extracts only the requested skill folder into the target directory
Installation & Usage
# Clone entire catalog as user skills
git clone https://github.com/jMerta/codex-skills.git ~/.agents/skills
# Or use npx CLI (no clone required)
npx codex-skills list
npx codex-skills search git
npx codex-skills install commit-work
npx codex-skills install-category development
npx codex-skills install-all
npx codex-skills install-all --dir .agents/skills # repo-local
# Initialize global ledger
npx codex-skills init-ledger
# Verify a skill install
npx codex-skills verify commit-work
# Install shared agent scripts and add to PATH
npx codex-skills install-agent-scripts
export PATH="$PATH:$HOME/.agents/skills/agent-scripts"
# Enable skills permanently in ~/.codex/config.toml
[features]
skills = true
# Validate the catalog (no external dependencies)
python3 scripts/validate_skills.py
# Rebuild skills.json after adding/renaming skills
python3 scripts/build_skills_json.py
# Scan for invisible Unicode characters
python3 scripts/check_invisible_chars.py --all
Relevance to Claude Code Development
Applications
- Directly analogous to this repository's plugin/skill system: both use SKILL.md (or equivalent) with YAML frontmatter to define name and description, store workflow bodies in Markdown, and keep extended content in
references/ subdirectories
- The ledger pattern (
AGENTS.MD with Goal/Constraints/State/Done/Now/Next headings) maps to cross-session state management for Claude Code agent workflows
- The
coding-guidelines-gen and coding-guidelines-verify skills demonstrate how to generate and enforce nested AGENTS.md per module -- applicable to monorepo plugin structures
- The
ci-fix skill's approach (inspect gh run logs, identify root cause, patch workflow, rerun) mirrors the CI Workflow Modification Protocol in CLAUDE.md
Patterns Worth Adopting
- Minimal frontmatter constraint: name <=100 chars single-line, description <=500 chars single-line -- a stricter bound than currently enforced here; reduces context injection noise
- Stdlib-only validation:
validate_skills.py requires no external dependencies (no PyYAML) -- important for zero-setup CI
- Prompt-injection CI check:
check_invisible_chars.py scanning PR metadata and commit messages is a security pattern applicable to any AI-assisted workflow repository
--dir scope flag: user vs. repo-local install target with a single flag -- cleaner UX than two separate install paths
- Registry as generated artifact:
skills.json is regenerated from source of truth (skills-meta.json + skill folders) rather than hand-maintained -- reduces drift
Integration Opportunities
- codex-skills skill definitions (SKILL.md) could be cross-referenced or ported as Claude Code plugin skills, since both formats share the same YAML frontmatter + Markdown body convention
- The
check_invisible_chars.py script could be added as a pre-commit hook or CI check in this repository's .pre-commit-config.yaml
- The
plan-work skill's Q&A-gate pattern (research -> analysis -> ask before implementing) is a behavioral protocol worth encoding in agent delegation prompts here
References
Freshness Tracking
| Field |
Value |
| Last Verified |
2026-02-20 |
| Version at Verification |
v2.0.0 |
| Next Review Recommended |
2026-05-20 |
1---2name: problem-addressed-263description: codex-skills is a curated skill catalog for the OpenAI Codex CLI, providing drop-in skill folders that extend the agent with specialized workflows.4---5# codex-skills67**Research Date**: 2026-02-208**Source URL**: <https://github.com/jMerta/codex-skills>9**GitHub Repository**: <https://github.com/jMerta/codex-skills>10**Version at Research**: v2.0.011**License**: MIT1213---1415## Overview1617codex-skills is a curated skill catalog for the OpenAI Codex CLI, providing drop-in skill folders that extend the agent with specialized workflows. Skills are installed into `~/.agents/skills/` and auto-discovered by Codex via `SKILL.md` frontmatter. A companion npm CLI (`npx codex-skills`) enables listing, searching, installing individual skills, and installing entire categories without cloning the repository.1819---2021## Problem Addressed2223| Problem | Solution |24|---------|----------|25| Codex CLI ships with no built-in specialized workflows | Pre-built skills for git, CI, planning, docs, and operations give Codex immediate domain expertise |26| Reusing agent instructions across projects requires manual file copying | `npx codex-skills install <name>` copies a versioned skill folder into the standard catalog location |27| No standard convention for agent-context files (`AGENTS.md`) | `agents-md` skill + `init-ledger` command establish the ledger pattern for cross-session state |28| Prompt injection via invisible Unicode characters in agent inputs | CI pipeline runs `check_invisible_chars.py` on file contents, PR metadata, and commit messages |29| Hard-coded skill locations break when switching between user and repo scope | `--dir <dir>` flag selects between `~/.agents/skills/` (user) and `.agents/skills/` (repo-local) |3031---3233## Key Statistics3435| Metric | Value | Date Gathered |36|--------|-------|---------------|37| GitHub Stars | 116 | 2026-02-20 |38| Forks | 11 | 2026-02-20 |39| Contributors | 1 (jMerta) | 2026-02-20 |40| Latest Release | v2.0.0 | 2026-02-06 |41| Total Skills in Catalog | 19 | 2026-02-20 |42| npm package | codex-skills | 2026-02-20 |4344---4546## Key Features4748### Skill Catalog (19 skills at v2.0.0)4950- `plan-work` -- repo-grounded research, risk analysis, Q&A-gated implementation planning51- `bug-triage` -- reproduce, isolate, and fix bugs with root-cause summary52- `ci-fix` -- diagnose and fix GitHub Actions failures via `gh` CLI53- `commit-work` -- staged splitting + Conventional Commit message generation54- `create-pr` -- branch, lint/build, commit, and PR description with validation steps55- `coding-guidelines-gen` -- generate nested `AGENTS.md` per module, configure formatters/linters56- `coding-guidelines-verify` -- scoped compliance checks, auto-format, lint/test run57- `dependency-upgrader` -- safe incremental bump for Java/Kotlin (Gradle/Maven) and Node/TS58- `docs-sync` -- keep README, API docs, runbooks in sync with code changes59- `release-notes` -- draft changelogs and GitHub Release bodies from git ranges60- `agents-md` -- create/update root and nested `AGENTS.md` with module maps and feature maps61- `branch-cleaner` -- audit and prune stale git branches locally and on remotes62- `rebase-assistant` -- safe rebase onto target branch with conflict triage steps63- `regex-builder` -- build, test, explain regexes using `rg` and Python against sample files64- `vps-checkup` -- read-only Ubuntu VPS health/security report over SSH; applies changes only on confirmation65- `sessions-to-blog` -- convert session logs to MDX blog posts with project style rules66- Third-party: `create-cli` (steipete), `video-transcript-downloader` (steipete), `ui-ux-pro-max` (Next Level Builder)6768### Skill Structure Convention6970- Each skill is a directory containing `SKILL.md` (YAML frontmatter + Markdown body)71- Frontmatter fields: `name` (<=100 chars, single line), `description` (<=500 chars, single line)72- Optional subdirectories: `references/`, `scripts/`, `assets/`73- Only `name`, `description`, and SKILL.md path are injected into Codex context; bodies are loaded on demand7475### CLI Tool (`npx codex-skills`)7677- `list` / `ls` -- all skills grouped by category, supports `--json`78- `search <query>` -- search by name/description/category79- `install <name>` -- copy skill to skills directory from GitHub release tarball80- `install-category <category>` -- install all skills in a category81- `install-all` -- install every skill in the catalog82- `install-agent-scripts` -- install shared shell scripts alongside skills83- `init-ledger` -- create `~/.codex/AGENTS.MD` global context ledger84- `verify <name>` -- validate local skill install (SKILL.md + frontmatter)85- `--dir <dir>` flag for user (`~/.agents/skills/`) vs. repo-local (`.agents/skills/`) scope8687### Global Ledger Pattern8889- `init-ledger` creates `~/.codex/AGENTS.MD` as a cross-project agent context file90- Ledger headings: Goal, Constraints/Assumptions, Key decisions, State, Done/Now/Next, Open questions, Working set91- Not a skill -- applies globally to all Codex sessions across projects9293### Security: Prompt-Injection Hardening9495- `scripts/check_invisible_chars.py` scans file contents, filenames, PR metadata (title/body), and commit messages for invisible/suspicious Unicode characters (zero-width, directional overrides, etc.)96- GitHub Actions CI runs check on every push and PR97- Run locally: `python3 scripts/check_invisible_chars.py --all`9899### Registry Maintenance Pipeline100101- `skills-meta.json` -- category/author/license overrides per skill102- `skills.json` -- full machine-readable catalog generated by `scripts/build_skills_json.py`103- `scripts/validate_skills.py` -- validates SKILL.md frontmatter (no PyYAML dependency since v2.0.0)104- GitHub Pages at `https://jmerta.github.io/codex-skills/` publishes the catalog on each release105106---107108## Technical Architecture109110```text111codex-skills/112 <skill-name>/113 SKILL.md # YAML frontmatter (name, description) + Markdown workflow body114 references/ # Extended templates, checklists (loaded on demand)115 scripts/ # Optional helper scripts for the skill116 assets/ # Optional assets117 agent-scripts/ # Shared shell scripts installable via install-agent-scripts118 agents-md/ # agents-md skill119 cli/120 bin/codex-skills.js # npm CLI entry point (Node.js, single dependency: tar)121 package.json # npm package definition (name: codex-skills, v2.0.0)122 test/ # Node.js built-in test runner123 scripts/124 build_skills_json.py # Regenerates skills.json from skill folders + skills-meta.json125 validate_skills.py # Validates SKILL.md frontmatter (stdlib only)126 check_invisible_chars.py # Scans for Unicode prompt-injection vectors127 skills.json # Machine-readable catalog (version, total, skills array, categories)128 skills-meta.json # Overrides for category/author/license per skill129 AGENTS.md # Repo-scoped agent instructions130 LEDGER-PATTERN.md # Documentation of the cross-session ledger pattern131```132133Codex discovery mechanism:134135- User scope: `~/.agents/skills/**/SKILL.md` (legacy: `~/.codex/skills/**/SKILL.md`)136- Repo scope: `.agents/skills/**/SKILL.md`137- Only `name`, `description`, and path from frontmatter enter Codex context; full SKILL.md body is read on demand138139CLI install mechanism:140141- Fetches `skills.json` from the selected GitHub ref (latest release by default, `--ref` to override)142- Downloads repo tarball for the ref via GitHub API143- Extracts only the requested skill folder into the target directory144145---146147## Installation & Usage148149```bash150# Clone entire catalog as user skills151git clone https://github.com/jMerta/codex-skills.git ~/.agents/skills152153# Or use npx CLI (no clone required)154npx codex-skills list155npx codex-skills search git156npx codex-skills install commit-work157npx codex-skills install-category development158npx codex-skills install-all159npx codex-skills install-all --dir .agents/skills # repo-local160161# Initialize global ledger162npx codex-skills init-ledger163164# Verify a skill install165npx codex-skills verify commit-work166167# Install shared agent scripts and add to PATH168npx codex-skills install-agent-scripts169export PATH="$PATH:$HOME/.agents/skills/agent-scripts"170```171172```toml173# Enable skills permanently in ~/.codex/config.toml174[features]175skills = true176```177178```bash179# Validate the catalog (no external dependencies)180python3 scripts/validate_skills.py181182# Rebuild skills.json after adding/renaming skills183python3 scripts/build_skills_json.py184185# Scan for invisible Unicode characters186python3 scripts/check_invisible_chars.py --all187```188189---190191## Relevance to Claude Code Development192193### Applications194195- Directly analogous to this repository's plugin/skill system: both use SKILL.md (or equivalent) with YAML frontmatter to define name and description, store workflow bodies in Markdown, and keep extended content in `references/` subdirectories196- The ledger pattern (`AGENTS.MD` with Goal/Constraints/State/Done/Now/Next headings) maps to cross-session state management for Claude Code agent workflows197- The `coding-guidelines-gen` and `coding-guidelines-verify` skills demonstrate how to generate and enforce nested `AGENTS.md` per module -- applicable to monorepo plugin structures198- The `ci-fix` skill's approach (inspect `gh` run logs, identify root cause, patch workflow, rerun) mirrors the CI Workflow Modification Protocol in CLAUDE.md199200### Patterns Worth Adopting201202- **Minimal frontmatter constraint**: name <=100 chars single-line, description <=500 chars single-line -- a stricter bound than currently enforced here; reduces context injection noise203- **Stdlib-only validation**: `validate_skills.py` requires no external dependencies (no PyYAML) -- important for zero-setup CI204- **Prompt-injection CI check**: `check_invisible_chars.py` scanning PR metadata and commit messages is a security pattern applicable to any AI-assisted workflow repository205- **`--dir` scope flag**: user vs. repo-local install target with a single flag -- cleaner UX than two separate install paths206- **Registry as generated artifact**: `skills.json` is regenerated from source of truth (`skills-meta.json` + skill folders) rather than hand-maintained -- reduces drift207208### Integration Opportunities209210- codex-skills skill definitions (SKILL.md) could be cross-referenced or ported as Claude Code plugin skills, since both formats share the same YAML frontmatter + Markdown body convention211- The `check_invisible_chars.py` script could be added as a pre-commit hook or CI check in this repository's `.pre-commit-config.yaml`212- The `plan-work` skill's Q&A-gate pattern (research -> analysis -> ask before implementing) is a behavioral protocol worth encoding in agent delegation prompts here213214---215216## References217218- [jMerta/codex-skills GitHub repository](https://github.com/jMerta/codex-skills) (accessed 2026-02-20)219- [codex-skills v2.0.0 release notes](https://github.com/jMerta/codex-skills/releases/tag/2.0.0) (accessed 2026-02-20)220- [skills.json catalog (v2.0.0)](https://raw.githubusercontent.com/jMerta/codex-skills/main/skills.json) (accessed 2026-02-20)221- [GitHub Pages catalog](https://jmerta.github.io/codex-skills/) (accessed 2026-02-20)222- [npm: codex-skills](https://www.npmjs.com/package/codex-skills) (accessed 2026-02-20)223224---225226## Freshness Tracking227228| Field | Value |229|-------|-------|230| Last Verified | 2026-02-20 |231| Version at Verification | v2.0.0 |232| Next Review Recommended | 2026-05-20 |