跳过主要内容

By agent · Codex

Codex skills: 1008 worth installing

Skills in the open SKILL.md format that Codex reads. Each one has a plain-language summary and the command to install it.

Installing a skill in Codex

$ npx skills add <author>/<skill> --agent codex

Replace the placeholder with the author and skill name from the skill's page. Start a new Codex session afterwards so the skill is picked up.

Skills for Codex

All skills

Semgrep Rule Creator

Trail of BitsAudit warning

Creates custom Semgrep rules that detect security vulnerabilities and bug patterns.

DevelopmentGitHub stars: 7.3kInstalls: 5.2k

Sharp Edges

Trail of Bits

Identifies error-prone APIs, dangerous configurations and designs that invite security mistakes.

DevelopmentGitHub stars: 7.3kInstalls: 6k

Checks code against its specification: which requirements hold, which are contradicted and which are missing.

DevelopmentGitHub stars: 7.3kInstalls: 5.3k

CodeQL

Trail of BitsAudit warning

Scans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.

DevelopmentGitHub stars: 7.3kInstalls: 7.7k

SARIF Parsing

Trail of Bits

Parses, aggregates and deduplicates SARIF files from static analysis tools such as CodeQL and Semgrep.

DevelopmentGitHub stars: 7.3kInstalls: 5.4k

Semgrep

Trail of BitsAudit warning

Runs a Semgrep security scan: detects languages, selects rulesets, asks for approval, then runs the scans.

DevelopmentGitHub stars: 7.3kInstalls: 8.6k

Audits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.

DevelopmentGitHub stars: 7.3kInstalls: 7.2k

Fuzzing Harness Writing

Trail of BitsAudit warning

Designs and improves fuzzing harnesses for C, C++ and Rust targets.

DevelopmentGitHub stars: 7.3kInstalls: 5k

Variant Analysis

Trail of Bits

Hunts for other instances of a bug that has already been found, across the whole codebase.

DevelopmentGitHub stars: 7.3kInstalls: 5.7k

YARA Rule Authoring

Trail of Bits

Guides the authoring of YARA-X detection rules for malware identification.

DevelopmentGitHub stars: 7.3kInstalls: 4.7k

Zeroize Audit

Trail of BitsAudit warning

Detects missing zeroisation of sensitive data in C, C++ and Rust code, including cases removed by the compiler.

DevelopmentGitHub stars: 7.3kInstalls: 4.3k

n8n Agents

Romuald Członkowski

Guides the design of n8n AI agents and LLM chains built from the LangChain AI nodes.

AutomationGitHub stars: 6.4kInstalls: 1.6k

n8n Code JavaScript

Romuald Członkowski

Writes JavaScript for n8n Code nodes, covering $input, $json and $node syntax, HTTP helpers and date handling.

AutomationGitHub stars: 6.4kInstalls: 6.7k

n8n Code Python

Romuald Członkowski

Writes native Python for n8n Code nodes and migrates older Pyodide-based code.

AutomationGitHub stars: 6.4kInstalls: 4.5k

n8n Error Handling

Romuald Członkowski

Wires error handling into n8n workflows so that failures are visible, structured and recoverable.

AutomationGitHub stars: 6.4kInstalls: 1.6k

n8n Expression Syntax

Romuald Członkowski

Validates n8n expression syntax and fixes common errors when mapping data between nodes.

AutomationGitHub stars: 6.4kInstalls: 6.2k

n8n MCP Tools Expert

Romuald Członkowski

Guides use of the n8n-mcp tools: searching nodes, validating configurations, using templates and managing workflows and credentials.

AutomationGitHub stars: 6.4kInstalls: 7.8k

n8n Node Configuration

Romuald Członkowski

Guides node configuration in n8n: property dependencies, required fields and common patterns by node type.

AutomationGitHub stars: 6.4kInstalls: 7.2k

n8n Validation Expert

Romuald Członkowski

Interprets n8n validation errors and warnings, and guides the fix.

AutomationGitHub stars: 6.4kInstalls: 6.4k

n8n Workflow Patterns

Romuald CzłonkowskiAudit warning

Supplies workflow architecture patterns drawn from real n8n workflows, such as webhook processing and HTTP API integration.

AutomationGitHub stars: 6.4kInstalls: 11.1k

Antfu

Anthony Fu

Applies Anthony Fu's tooling and conventions to JavaScript and TypeScript projects: linting, monorepos and library publishing.

DevelopmentGitHub stars: 5.9kInstalls: 16.4k

Nitro

Anthony Fu

Reference for Nitro, the server toolkit behind Nuxt: server routes, route rules, caching, storage, tasks and websockets.

DevelopmentGitHub stars: 5.9kInstalls: 2.2k

Nuxt

Anthony Fu

Reference for Nuxt: SSR, auto-imports, file-based routing, server routes, useFetch, middleware and hybrid rendering.

DevelopmentGitHub stars: 5.9kInstalls: 23.4k

Pinia

Anthony Fu

Reference for Pinia, Vue's state management library: defining stores, state, getters, actions and store patterns.

DevelopmentGitHub stars: 5.9kInstalls: 18.9k

Questions

Codex and skills.

Do Claude skills work in Codex?

Often. A skill is a folder of instructions and scripts in the open SKILL.md format, which Codex reads. A skill that depends on tools only one agent provides will not carry over, so read the skill's source before you rely on it.

How do I install a skill in Codex?

Each skill page has an install command. Run it in a terminal, then start a new Codex session so the skill is picked up.

What is the difference between a skill and an instructions file such as AGENTS.md?

An instructions file is loaded in every session and describes the project. A skill is loaded only when a task calls for it, so it can be long and specific without costing context on every turn.

Other agents