Agent Skill Installation Has a Portability Problem: A Directory Audit
A skill can be written as plain Markdown and still be awkward to install. The instructions might travel between agents; the command that puts them in the right place often does not. That distinction gets lost when a directory presents one tidy install line next to a list of compatible agents.
We audited the install metadata in the AgentNDX skills directory on September 25, 2026. The finding is less about which skill is best and more about what developers should check before copying a command into a terminal.
What the directory actually records
The current src/data/skills.ts snapshot contains 93 skill records. Each has an install_cmd field. Ninety use a command beginning gh skill install; the other three start with git clone, pip install, and npm install, respectively. That is a count of the commands stored in the directory, not a measured success rate for installations.
| Recorded command prefix | Skill records |
|---|---|
gh skill install | 90 |
git clone | 1 |
pip install | 1 |
npm install | 1 |
The outliers make the distinction concrete. Humanizer lists a Git clone into a Claude-specific skills directory. OpenForgeAI lists a Python package install. Supermemory lists an npm install. Those commands do different jobs: copying instruction files, installing a Python distribution, and installing a JavaScript package are not interchangeable operations. A package install may provide software without registering a skill with your agent at all. Check the upstream project for the actual activation step.
Most records, though, use the same gh skill install prefix. It is useful as a directory convention, but don’t infer that the GitHub CLI on your machine necessarily supports that subcommand. Check the tool and extension that provide it, then check the source repository’s own installation instructions. We did not run these install commands for this audit.
A portable skill is not a portable installer
The universal compatibility label describes the skill’s intended runtime reach. It does not promise a universal setup path. A Markdown workflow might work in Claude Code and Codex after it is loaded, while the listed install command places it only under ~/.claude/skills/. Another may require an agent-specific directory, plugin, or project configuration that the one-line command does not mention.
Treat compatibility and installation as separate questions:
- Can this agent interpret the skill’s instructions and call the tools they assume?
- Where does this agent discover skill files, and at what scope: user, project, or session?
- Does the command install a skill, install a dependency, or merely clone its source?
- How will you verify that the agent loaded the intended version?
The fourth question is easy to skip. A command can exit successfully while the agent continues using an older copy from another directory. Conversely, a skill can be present on disk but invisible because the agent only scans a different path. An installation test should ask the agent to list or invoke the skill, then inspect which file it read.
Why the count matters, and why it has limits
Ninety of 93 records sharing one prefix is a strong signal about the directory’s representation of installation. It is not evidence that 90 projects share one packaging standard, nor that the commands work unmodified across agents. These records are curated metadata, not telemetry from successful installs. The audit did not test repository availability, command behavior, operating systems, or whether an upstream project changed its instructions after the record was added.
The same caution applies to verified and health fields. In this snapshot all 93 entries are marked verified and active. Those fields do not substitute for a reproducible installation test on your machine with your chosen agent. A directory can help you find candidates; it cannot promise that your local runtime has the right loader, permissions, or dependencies.
If you maintain a skill directory, this suggests a better data model. Store the source repository separately from the setup instructions. Label the command’s target agent and prerequisites. Distinguish “download source” from “register with agent” and “install runtime dependency.” Record when an install path was last tested and against which agent version. A single string field cannot answer all of those questions.
A safer install check
Start on the skill’s detail page and open its source repository. Read the README and the skill file before executing anything. Look for shell commands inside the instructions, network access, filesystem write scope, and credentials the skill expects. This is especially important for security and compliance skills, which may ask for broad access to code or cloud resources.
Next, match the source instructions to your agent’s documented skill discovery path. If the directory’s command targets a different agent, install manually only after confirming the file layout. Avoid running an unfamiliar command just because it appears in a listing. Test in a throwaway project or limited-permission environment first. Then have the agent identify the installed skill by name and path, and exercise a harmless task before granting access to a production repository.
For teams, pin the repository revision and record the installation procedure in the project. A working skill today can silently change upstream tomorrow. A README URL alone is not a deployment record.
The directory gets you to the right candidate. The installer still has to meet your actual runtime.
FAQ
Does gh skill install work in every GitHub CLI installation?
No universal support should be assumed. Check the installed CLI and any extension or separate skill tool that provides the command. If it is unavailable, consult the skill’s upstream installation instructions rather than substituting an unverified command.
Does a universal skill need only one installation method? No. The instructions can be portable while each agent uses a different discovery directory or registration mechanism. Test both loading and a small task in each target agent.
Are the 93 directory records proof that the skills install successfully?
No. The audit counts install_cmd values in a source snapshot. It does not execute them or verify successful loading. Use the commands as starting points, then confirm the upstream source and your local agent behavior.