Codex reads skills from repository, user, admin, and system locations. The repository scope is the one that surprises people coming from another agent: Codex scans a directory named .agents/skills in every directory from your current working directory up to the repository root.
Names are not merged across locations. OpenAI documents that if two skills share the same name, Codex does not merge them and both can appear in skill selectors. That is a real difference from the precedence rules other agents apply, and it means a personal skill and a repository skill with the same name coexist rather than one silently winning.
Symlinked skill folders work. Codex follows the symlink target when it scans these locations, which is how one checked-out copy of a skill can serve several repositories without being duplicated in each of them.
The initial list is budgeted. In Codex the startup list includes each skill's name, description, and file path, and it is capped at 2% of the model's context window, or 8,000 characters when the context window is unknown. If many skills are installed, Codex shortens descriptions first, and for large skill sets it may leave some skills out of the initial list and show a warning. The budget applies only to that list: once Codex selects a skill, it still reads the full SKILL.md.
You can turn a skill off without deleting it. A [[skills.config]] entry in ~/.codex/config.toml takes the path to the skill folder containing SKILL.md and an enabled flag, and the config reference documents both keys. Restart Codex after changing the file.
Codex detects skill changes automatically, and OpenAI's instruction when an update does not show up is to restart Codex. The same applies to skills you have just installed.
Skills are not the only file Codex reads. It also builds an AGENTS.md chain before doing any work, and the two formats answer different questions, which is the subject of AGENTS.md vs SKILL.md: two formats, two different jobs.