Claude Skills explained: a library of instructions, tools and plugins
Claude Skills source-code walkthrough: how the Codex installer changes files
Read the three operations that matter before running the script
What you will learn
- Inspect discovery
- Inspect the copy boundary
- Inspect conversion separately
Before you start
- A disposable project
- A pinned repository revision
- One supported agent client
Turn a catalogue entry into a measured, reversible team decision
Key takeaways
- The script has a destructive same-name replacement.
- `cp -rL` follows mirror symlinks.
- Index data and filesystem contents can diverge.
Inspect discovery
The pinned `codex-install.sh` first checks the `.codex/skills` source mirror and optionally loads `skills-index.json`. `--list` can enumerate candidates, while `--skill` narrows to one package.
A missing index limits category selection, but the fallback can still traverse mirror entries for an all-skills installation. That distinction matters if the index and filesystem are out of sync.
Inspect the copy boundary
`install_skill` rejects empty names and path separators, checks that the source has SKILL.md, then computes a destination below the configured Codex skills directory. With `--dry-run`, it prints the planned copy and returns.
Without dry run it creates the destination root, removes an existing same-name destination and invokes `cp -rL`. Following symlinks can copy real content, but the script does not perform a content-hash verification after copying.
Inspect conversion separately
`convert.sh` and `install.sh` are separate paths for client-specific output. They should be reviewed as code, not inferred from the Codex installer. A marketplace entry similarly describes where a plugin lives but is not itself a permissions policy.
We read these pinned files; we did not execute a dry run or install. If you change the destination environment variable, verify the resolved absolute path before invoking a script with a removal step.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Read prerequisite and index branches in the script.
- 2
Trace one `--skill` through dry run and real copy.
- 3
Verify the resolved destination and resulting hashes.
Copy-ready example
--skill name -> source/SKILL.md check -> destination
--dry-run -> print only
real run -> remove same-name target -> cp -rL source targetFrequently asked questions
Does `--dry-run` remove an existing skill?
No. The pinned function returns before directory creation, removal and copy.
Does the installer check the copied hash?
Not in the inspected path; add a release-level verification if reproducibility matters.
Sources
- Claude Skills / scripts/codex-install.shSource checked 2026-10-04
- Claude Skills / INSTALLATION.mdSource checked 2026-10-04
- Claude Skills / scripts/convert.shSource checked 2026-10-04
- Claude Skills / scripts/install.shSource checked 2026-10-04
- Claude Skills / .claude-plugin/marketplace.jsonSource checked 2026-10-04