How-to

GitHub Copilot Agent Skills: Where They Live and How to Install Them

GitHub Copilot agent skills are SKILL.md folders in .github/skills. See which Copilot surfaces use them, how gh skill installs one, and project vs user scope.

By Updated 6 min read

GitHub Copilot agent skills are folders with a SKILL.md file that Copilot loads when a task matches the skill. In a repository they go in .github/skills, and for personal use in ~/.copilot/skills. The quickest installer is gh skill install, which GitHub ships in its own command-line tool, and the same folders are read by Copilot in the cloud agent, code review, the CLI and VS Code.

This guide gives the locations first, then the surfaces that read skills, each install method, how scope and pinning work, and how skills differ from the instruction files Copilot already reads.

Where do GitHub Copilot agent skills live?

ScopeFolders
Project (in the repository).github/skills, .claude/skills, .agents/skills
Personal (your home directory)~/.copilot/skills, ~/.agents/skills

VS Code's documentation also lists ~/.claude/skills as a personal location. Each skill gets its own subdirectory, such as .github/skills/webapp-testing, with SKILL.md inside it.

The project folders matter more than they look. The cloud agent works from a checkout of your repository, so a skill in your home directory on your own machine is not part of what it sees. If you want the cloud agent or code review to use a skill, commit it to the repository. The GitHub Copilot page in this directory keeps the paths and commands in one place.

Which Copilot features use skills?

GitHub describes agent skills as folders of instructions, scripts and resources that Copilot can load when relevant to a specialized task. According to its documentation, they work with:

  • the Copilot cloud agent
  • Copilot code review
  • the GitHub Copilot CLI
  • the GitHub Copilot app
  • agent mode in Visual Studio Code and JetBrains IDEs

Copilot picks a skill from your prompt and the skill's description. When it does, it injects the SKILL.md into the agent's context and can use the scripts and examples in the same folder. VS Code describes a three-step load: discovery reads the frontmatter, the instructions load when the skill is relevant or invoked by hand, and referenced files load only when the skill touches them.

GitHub's documented frontmatter is name (lowercase letters and hyphens), description, an optional license, and an optional allowed-tools that pre-approves tools. VS Code documents more: argument-hint, user-invocable, disable-model-invocation, and an experimental context: fork that runs the skill in its own subagent. The description is limited to 1,024 characters there. The SKILL.md format reference explains the shared fields in the open specification.

How do you install a skill with gh skill?

gh skill is GitHub's own installer. It is in public preview and needs GitHub CLI 2.90.0 or later. By default it installs for Copilot at project scope, so the skill lands in the current repository.

gh skill search design
gh skill preview anthropics/skills frontend-design
gh skill install anthropics/skills frontend-design

The examples use frontend-design from anthropics/skills, which sits at skills/frontend-design. Here is what each command does.

  • gh skill search looks for skills by keyword.
  • gh skill preview renders the SKILL.md and the file tree without installing anything, which is worth doing for any repository you have not used before.
  • gh skill install copies the skill into place and writes provenance metadata into its frontmatter: the source repository, the ref and the tree SHA.

The command takes the form install <repository> [<skill[@version]>]. It discovers skills using the skills/*/SKILL.md convention, accepts plain names or exact repository paths, and resolves versions from the latest tagged release or the default branch. Run it with no arguments for an interactive picker. The flags that matter most:

FlagEffect
--agentTarget agent. Defaults to github-copilot
--scopeproject (default) or user for a personal install
--pin or @TAGLock a tag or commit SHA, but not both together
--dirInstall into a custom folder, overriding agent and scope
--forceOverwrite an existing skill without asking
--allInstall every skill in the repository without prompting
--from-localTreat the argument as a local directory

The full list is in the gh skill install manual. The same command can target other agents, including Claude Code, Cursor, Codex and Gemini CLI, by changing --agent, which is useful if your team does not use only one tool.

What are the other ways to add a skill?

The skills CLI

npx skills add anthropics/skills --skill frontend-design -a github-copilot

This installs into .agents/skills/ in the project. Add -g for ~/.copilot/skills/. It comes from the vercel-labs/skills project.

Copy the folder

git clone --depth 1 https://github.com/anthropics/skills.git skills-src
mkdir -p .github/skills
cp -r skills-src/skills/frontend-design .github/skills/frontend-design
rm -rf skills-src

Use ~/.copilot/skills/ for a personal skill, and commit .github/skills so the cloud agent and code review can find it. A manual copy is the easiest way to read every file before the skill enters your project.

How do you check and use a skill?

  • VS Code: type /skills in the chat input to open the Configure Skills menu, or open the gear icon and the Skills tab. Skills also appear in the / menu, and you can add context after the name, for example /webapp-testing for the login page.
  • Copilot CLI: run /skills list, then /skills info frontend-design to see its location. To use one, name it in your prompt: "Use the /frontend-design skill to ...".
  • Cloud agent and code review: the documentation describes no list to open. Copilot picks the skill from the task. For code review, a review-focused folder name such as code-review makes use more likely.

Skills vs custom instructions vs custom agents

GitHub has several customization files, and mixing them up leads to instructions that never load.

File or folderPurposeLoaded
.github/copilot-instructions.mdRepository-wide instructionsFor requests in the repository
.github/instructions/*.instructions.mdPath-specific instructions with glob patternsWhen files match
AGENTS.md, CLAUDE.md, GEMINI.mdAgent instructions, the nearest AGENTS.md taking precedenceBy agents such as the cloud agent
.github/agents/NAME.mdCustom agent profileWhen that agent is chosen
SKILL.md foldersTask-specific procedures with optional scriptsOn demand, when relevant

VS Code's documentation draws the line between skills and custom instructions this way: skills carry scripts and resources with a task-specific scope, while custom instructions define coding standards with an always-applied scope. GitHub's pages do not compare skills with custom agents, so treat them as separate features. The relationship between the instruction files and skills is explored in CLAUDE.md vs AGENTS.md vs skills.

Which skills suit Copilot users?

Copilot code review and the cloud agent both read skills, so review and pull request skills are a natural fit. These are described from the directory's listings, each with its licence and automated safety result. We have not run them inside Copilot, so check a skill's own README for notes about other agents.

  • GitHub Review Iteration loops on a pull request: it fetches review state, triages comments into actions, implements them and resolves threads. Apache-2.0.
  • Create Pull Request opens a pull request with the gh CLI after reviewing the commits and diff. Apache-2.0.
  • PR Finalize Review checks that a pull request's title and description match its implementation, and reviews the code. MIT.
  • PR Babysitter watches an open pull request, handles review comments and diagnoses CI failures. Apache-2.0.

Browse the code review topic, the pull requests topic or the most-used skills for more.

Update, remove and stay safe

gh skill update checks for upstream changes using the provenance metadata that install wrote. gh skill update --all updates everything, and pinned skills are skipped until you reinstall them with a new --pin. In Copilot CLI, /skills remove SKILL-DIRECTORY removes a skill you added directly, and /skills lets you enable or disable one. Otherwise, delete the folder, or use npx skills update and npx skills remove.

If a skill is not offered, check that the file is named exactly SKILL.md and sits in its own subdirectory under one of the folders above. In Copilot CLI, run /skills reload after adding one mid-session. If gh skill is not found, update GitHub CLI to 2.90.0 or later.

GitHub warns that skills are not verified by GitHub and may contain prompt injections, hidden instructions or malicious scripts, and it advises inspecting a skill before installing it. Pre-approving the shell or bash tools in allowed-tools removes the confirmation step for terminal commands, so reserve that for skills and scripts you have reviewed and fully trust.

Frequently asked questions

Where do GitHub Copilot agent skills go?

In a repository, put each skill in its own subfolder of .github/skills, .claude/skills or .agents/skills. For personal skills that follow you across projects, use ~/.copilot/skills or ~/.agents/skills in your home directory. Every skill folder needs a file named SKILL.md.

Which GitHub Copilot features can use agent skills?

GitHub's documentation lists the Copilot cloud agent, Copilot code review, the GitHub Copilot CLI, the GitHub Copilot app, and agent mode in Visual Studio Code and JetBrains IDEs. Support for a given field, such as the extra VS Code frontmatter options, can differ by surface.

What does gh skill install do?

It downloads a skill from a GitHub repository or a local folder into the right directory for an agent. The default agent is GitHub Copilot and the default scope is the current project, with a user scope for a personal install. It needs GitHub CLI 2.90.0 or later, where the command is in public preview.

How are Copilot skills different from copilot-instructions.md?

Custom instructions define coding standards that apply to requests all the time. A skill holds task-specific instructions, and optionally scripts and examples, that Copilot loads only when the task matches the skill's description. Use instructions for standing rules and a skill for a repeatable procedure.

Are Copilot agent skills safe to install?

GitHub states that skills are not verified by GitHub and may contain prompt injections, hidden instructions or malicious scripts. Preview a skill with gh skill preview before installing it, and avoid pre-approving the shell tool in allowed-tools unless you have read the skill and trust its source.