All skills
github avatar

/gh-attach

@bfefe9d official
by githubgithub/awesome-copilot40k stars
5,040

Uploads a local file (screenshot, image, PDF, zip, video) to GitHub user-attachments, downloads GitHub user-attachments, and embeds local files in a PR, issue, or comment. Use when asked to "attach a screenshot to the PR", "add an image to the issue", "embed before/after screenshots", "attach this file", or "download this GitHub attachment". Powered by `gh-attach`.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/gh-attach

This session only. Nothing lands on disk.

SKILL.md

≈95 tokens always: the name and description. ≈427 when used: this file.

gh-attach

gh attach uploads a file to GitHub's internal user-attachments endpoint (no public API exists) and prints the URL, which GitHub auto-renders (image/video/file) wherever it's pasted. The URL inherits the repo's visibility, so private-repo uploads stay private.

Prerequisites

gh extension list | grep -q 'gh attach' || gh extension install sudosubin/gh-attach

Uploads use a GitHub browser session cookie, not the gh token. By default, gh must be authenticated so gh-attach can select the matching browser account. If the wrong account is selected, add --browser <name> --profile <name>. For headless use, set GH_ATTACH_SESSION_TOKEN to the bare user_session cookie value. Treat it as a full account credential.

Steps

1. Upload: Use an absolute quoted path. -R is optional inside a repository. For GHES, use -R host/owner/repo. The command prints the URL on one line. GitHub auto-renders it (image/video/file), so use it as-is:

URL=$(gh attach "$FILE" -R <owner>/<repo>)

2. Embed (always --body-file -, e.g. gh pr comment/edit, gh issue comment/edit):

printf '## Screenshots\n\n%s\n' "$URL" | gh pr comment <pr> -R <owner>/<repo> --body-file -

3. Download: Specify the destination explicitly. Private attachments use the active gh token, with browser cookies as an authorization fallback:

gh attach download "$URL" -O "$FILE"

Notes

  • Private repo: URL renders only for authorized viewers. An anonymous fetch is expected to return 404 or 403.
  • Sizing: embed <img width="800" src="$URL"> instead of the bare URL.
  • GitHub Cloud and GHES decide which file extensions and content types they accept.

Source: SKILL.md on GitHub

3 warnings1mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub1mo

    This skill installs a third-party GitHub CLI extension and facilitates the upload of local files to GitHub. It presents security risks including unverified code execution, potential sensitive data exfiltration, and the exposure of account session credentials.

  • Socket1mo

    1 alert: gptSecurity

  • Snyk1mo

    Risk: MEDIUM · 1 issue

Signed by skilld at bfefe9d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated 2 months ago

README badge

README badge for github/awesome-copilot/gh-attach