Agent skill

Upload GitHub Attachment

by moeru-ai in moeru-ai/airi

Upload a local image or file to GitHub's user-attachments storage and return a URL suitable for issue, pull request, discussion, or comment Markdown.

MITAuto-check passedDevelopment

Install Upload GitHub Attachment

skills CLI
$ npx skills add moeru-ai/airi --skill upload-github-attachment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install moeru-ai/airi upload-github-attachment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/moeru-ai/airi.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/upload-github-attachment .claude/skills/upload-github-attachment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
upload-github-attachment
GitHub stars
50k
Token cost
~554 tokens
SKILL.md length
214 words
Files
3 (incl. scripts)
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Upload a local image or file to GitHub's user-attachments storage and return a URL suitable for issue, pull request, discussion, or comment Markdown.

  • Works in 4 steps: Require a successful upload command and… → Use that URL for the intended local… → Do not treat anonymous access returning… → …
  • Codex must embed local screenshots
  • SKILL.md covers Requirements, Upload and Verification
  • Runs Shell scripts from its folder; calls gh; reaches github.com; needs GH_TOKEN and GITHUB_TOKEN

What it does

Upload GitHub Attachment is an agent skill from moeru-ai/airi. Upload a local image or file to GitHub's user-attachments storage and return a URL suitable for issue, pull request, discussion, or comment Markdown. Use when Codex must embed local screenshots, videos, logs, or other evidence in GitHub content without committing the files to a repository.

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/upload-github-attachment.sh`).

It sits in Development, covering Pull requests. It works with GitHub. The repository describes itself as: 💖🧸 Self hosted, you-owned Grok Companion, a container of souls of waifu, cyber livings to bring them into our worlds, wishing to achieve Neuro-sama's altitude. Capable of… The licence is MIT.

When your agent uses it

  • Codex must embed local screenshots
  • Other evidence in GitHub content without committing the files to a repository

Example prompts

  • “/upload-github-attachment”

Requirements

  • A Bash shell
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Require a successful upload command and a returned https://github.com/user-attachments/assets/... URL.
  2. Use that URL for the intended local file. Do not issue GET or HEAD requests to verify the uploaded asset.
  3. Do not treat anonymous access returning 404 as an upload failure or a reason to stop the workflow.
  4. After creating or editing GitHub content, reopen it and verify the attachment Markdown uses the returned URL.

What it can do on your machine

Read from SKILL.md and the folder at commit 82225c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • island94.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Upload GitHub Attachment loads about 554 tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 214 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~554

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from moeru-ai/airi at commit 82225c9, republished under its MIT licence (© moeru-ai). 214 words, ~554 tokens.

Download SKILL.mdSave it as .claude/skills/upload-github-attachment/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
upload-github-attachment
description
Upload a local image or file to GitHub's user-attachments storage and return a URL suitable for issue, pull request, discussion, or comment Markdown. Use when Codex must embed local screenshots, videos, logs, or other evidence in GitHub content without committing the files to a repository.

Upload GitHub Attachment

Use the bundled script so authentication, repository resolution, MIME detection, and URL extraction remain consistent.

Requirements

  • Require the gh CLI and curl.
  • Prefer an existing gh auth login session.
  • When interactive gh authentication is unavailable, require GH_TOKEN or GITHUB_TOKEN in the environment.
  • Stop and ask the user to configure one of those authentication methods if gh auth token cannot resolve a token. Never print, persist, or interpolate the token into diagnostic output.

Upload

Run from a checkout of the destination repository:

bash
.agents/skills/upload-github-attachment/scripts/upload-github-attachment.sh /absolute/path/to/image.png

Specify the repository when the current directory cannot resolve it:

bash
.agents/skills/upload-github-attachment/scripts/upload-github-attachment.sh \
  --repo moeru-ai/airi \
  /absolute/path/to/image.png

The script prints only the final https://github.com/user-attachments/assets/... URL. Embed it with ![](URL) for an image or [label](URL) for another file.

Verification

  1. Require a successful upload command and a returned https://github.com/user-attachments/assets/... URL.
  2. Use that URL for the intended local file. Do not issue GET or HEAD requests to verify the uploaded asset.
  3. Do not treat anonymous access returning 404 as an upload failure or a reason to stop the workflow.
  4. After creating or editing GitHub content, reopen it and verify the attachment Markdown uses the returned URL.

The upload endpoint is currently undocumented by GitHub. Treat a rejected upload request as a blocking capability change instead of committing PR-only artifacts. Background and the observed Bearer-token flow: https://island94.org/2026/08/programmatically-upload-attachments-to-github-issues-pull-requests-comments.

© moeru-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .agents/skills/upload-github-attachment of moeru-ai/airi.

  • SKILL.md
  • agents/openai.yaml
  • scripts/upload-github-attachment.sh

Open the folder on GitHubat commit 82225c9

Compare with similar skills

Upload GitHub Attachment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Upload GitHub Attachment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Upload GitHub Attachment this skillmoeru-ai/airi50k—~554Automated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Pull Request Title and Body Writeropeninterpreter/openinterpreter69k2 repos~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from moeru-ai/airi

All 24 skills in this repo
  • Simple English

    moeru-ai/airi

    Write or rewrite technical text with the rules of ASD-STE100 Simplified Technical English so it is clear, unambiguous, and free of AI slop.

    50k GitHub starsUsed in 2 repos~4.6k tokens
    Auto-check passed
  • Review pending AIRI translations on Crowdin in a batch, then sync them into the repository.

    50k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Create PR

    moeru-ai/airi

    Prepare and create an AIRI pull request with verifiable change context, architecture evidence, and required visual evidence.

    50k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Test AIRI display-model imports with agent-browser across stage-tamagotchi Electron, stage-web, and stage-pocket mobile web layouts.

    50k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • A skill your agent uses when Codex needs to inspect, debug, or automate an Electron app through agent-browser and Chrome DevTools Protocol, especially when the app has multiple BrowserWindow…

    50k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Analyze Io Traces

    moeru-ai/airi

    Read and analyze AIRI IO traces that Tamagotchi saved to local files.

    50k GitHub stars~542 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Upload GitHub Attachment

What does Upload GitHub Attachment do?

Upload a local image or file to GitHub's user-attachments storage and return a URL suitable for issue, pull request, discussion, or comment Markdown. Upload GitHub Attachment is an agent skill from moeru-ai/airi. Upload a local image or file to GitHub's user-attachments storage and return a URL suitable for issue, pull request, discussion, or comment Markdown.

When should I use Upload GitHub Attachment?

Upload GitHub Attachment fits situations like: Codex must embed local screenshots; other evidence in GitHub content without committing the files to a repository.

How do I install Upload GitHub Attachment in Claude Code?

Run `npx skills add moeru-ai/airi --skill upload-github-attachment -a claude-code`. Or copy the skill folder (.agents/skills/upload-github-attachment in moeru-ai/airi) into .claude/skills/upload-github-attachment in your project. Claude Code loads it when a task matches its description.

How do I install Upload GitHub Attachment in Codex?

Run `npx skills add moeru-ai/airi --skill upload-github-attachment -a codex`. Or copy the skill folder (.agents/skills/upload-github-attachment in moeru-ai/airi) into .agents/skills/upload-github-attachment in your project. Codex loads it when a task matches its description.

Can I use Upload GitHub Attachment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add moeru-ai/airi --skill upload-github-attachment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upload-github-attachment, .gemini/skills/upload-github-attachment, .github/skills/upload-github-attachment and .opencode/skills/upload-github-attachment in your project.

What does Upload GitHub Attachment need to run?

Going by SKILL.md and its folder, Upload GitHub Attachment needs a shell for the scripts in its folder, the command-line tools its instructions call (gh) and credentials named GH_TOKEN and GITHUB_TOKEN. Our summary lists: A Bash shell; A credential in GITHUB_TOKEN.

Does Upload GitHub Attachment access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: island94.org. This is read from the text; nothing was executed.

Is Upload GitHub Attachment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Upload GitHub Attachment use?

Upload GitHub Attachment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Upload GitHub Attachment use?

About 554 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Upload GitHub Attachment?

Skills that share tags, products or a category with Upload GitHub Attachment: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Create Pull Request (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Upload GitHub Attachment?

moeru-ai (a GitHub organization) maintains it in moeru-ai/airi, which has 50,109 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 7, 2026.

Source: moeru-ai/airi on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.