Agent skill

Gh Attach

by sickn33 in sickn33/agentic-awesome-skills

Upload and download GitHub user-attachments (screenshots, PDFs, zips, videos) from the terminal; use when asked to attach or embed a file in a PR, issue, or comment, or download an attachment URL.

MITAuto-check passedDocuments & Office

Install Gh Attach

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill gh-attach -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills gh-attach --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gh-attach .claude/skills/gh-attach && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gh-attach
GitHub stars
47k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
727 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Upload and download GitHub user-attachments (screenshots, PDFs, zips, videos) from the terminal; use when asked to attach or embed a file in a PR, issue, or comment, or download an attachment URL.

  • Works in 4 steps: Verify prerequisites → Upload → Embed into the PR / issue / comment → …
  • Asked to attach
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Examples, plus 3 more sections
  • Calls gh

What it does

Gh Attach is an agent skill from sickn33/agentic-awesome-skills. Upload and download GitHub user-attachments (screenshots, PDFs, zips, videos) from the terminal; use when asked to attach or embed a file in a PR, issue, or comment, or download an attachment URL.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office. It works with GitHub. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Asked to attach
  • Embed a file in a PR
  • Download an attachment URL

Example prompts

  • “/gh-attach”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Verify prerequisites
  2. Upload
  3. Embed into the PR / issue / comment
  4. Download

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gh Attach loads about 1.6k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 727 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 727 words, ~1,584 tokens.

Download SKILL.mdSave it as .claude/skills/gh-attach/SKILL.md (or your agent's skills folder).
name
gh-attach
description
Upload and download GitHub user-attachments (screenshots, PDFs, zips, videos) from the terminal; use when asked to attach or embed a file in a PR, issue, or comment, or download an attachment URL.
category
developer-tools
risk
critical
source
community
source_type
community
source_repo
sudosubin/gh-attach
date_added
2026-08-01
author
sudosubin
license
MIT
license_source
https://github.com/sudosubin/gh-attach/blob/main/LICENSE
tags
github, attachments, screenshots, gh-extension, cli

Upload and download GitHub user-attachments (gh-attach)

GitHub has no public API for user-attachments. The web UI uses an internal endpoint that mints github.com/user-attachments URLs whose visibility follows the repository they belong to. gh-attach (MIT, sudosubin) replicates that drag-and-drop flow as a gh CLI extension, so an agent can upload a local file from the terminal, get a URL back, and later download an attachment URL to a file.

Overview

This skill drives gh-attach to turn a local file (screenshot, image, PDF, zip, log, or video) into a hosted GitHub user-attachments URL, then embeds that URL into a pull request, issue, or comment. It also downloads an existing attachment URL back to a local file. GitHub auto-renders the URL as an image, video, or file wherever it is pasted, and the URL inherits the repository's visibility, so a private-repo upload stays private. It works against GitHub Cloud and GitHub Enterprise Server.

When to Use This Skill

Use this skill when asked to:

  • "Attach a screenshot to the PR" or "add an image to the PR description"
  • "Attach this file (PDF, zip, log, video) to the issue or comment"
  • "Embed before/after screenshots" in a PR, issue, or README
  • "Download this GitHub attachment" from a user-attachments URL

How It Works

Step 1: Verify prerequisites
bash
gh auth status                                   # gh installed and authenticated
gh extension install sudosubin/gh-attach --pin v0.4.2 --force
gh extension list | grep -F 'sudosubin/gh-attach' # require the reviewed v0.4.2 release

Uploads use a GitHub user_session browser cookie, not the gh token (that endpoint rejects tokens). By default gh must be authenticated so gh-attach can select the matching browser account (Chromium family, Firefox family, or Safari). If the wrong account is selected, add --browser <name> --profile <name>. Obtain explicit approval before allowing the pinned extension to access that interactive browser profile. Headless and CI uploads are intentionally unsupported: never export, store, or pass a raw user_session cookie to the extension.

Step 2: Upload
bash
# Use an absolute quoted path; -R is optional inside a repo working dir.
URL=$(gh attach "/abs/path/screenshot.png" -R <owner>/<repo>)

gh attach prints the URL on one line to stdout. For GitHub Enterprise Server, use -R host/owner/repo. Capture the output; it is the embeddable reference.

Step 3: Embed into the PR / issue / comment
bash
printf '## Screenshots\n\n%s\n' "$URL" \
  | gh pr comment <pr> -R <owner>/<repo> --body-file -

Use gh pr edit, gh issue comment, or gh issue edit with --body-file - for other targets. Always pass --body-file - (not inline --body) so multi-line bodies and special characters cannot break shell quoting. GitHub auto-renders the URL, so paste it as-is.

Step 4: Download
bash
# Specify the destination explicitly.
gh attach download "$URL" -O "/abs/path/out.png"

Downloads of private attachments use the active gh token, with browser cookies as an authorization fallback.

Examples

  • Attach a screenshot to PR #42: upload the file, then append the URL under a ## Screenshots heading in the PR body with gh pr edit ... --body-file -.
  • Embed before/after screenshots in a README: upload both files, paste the two URLs into the README at the relevant section.
  • Download an attachment for review: run gh attach download "$URL" -O out.zip to fetch a user-attachments file locally.
Show full SKILL.md (277 more words)Show less

Best Practices

  • Resolve globs to absolute paths first, and quote paths that contain spaces or Unicode.
  • For display sizing, embed an HTML tag instead of the bare URL: <img width="800" src="$URL">.
  • Keep uploads interactive. Do not place a GitHub browser session in CI, an environment variable, a secret store consumed by this extension, or an agent log.
  • gh-attach can upload multiple files concurrently and emit Markdown or JSON output with jq-style filtering when you need to script around the result.

Limitations

  • Interactive session cookie required. A user_session cookie grants full account access and is not scoped like a PAT. The supported path is the reviewed, pinned extension reading an explicitly approved local browser profile; CI and headless cookie injection are out of scope.
  • Write access to the target repo is required to upload.
  • Private-repo attachments stay private: the user-attachments URL inherits repo visibility, so an anonymous fetch on a private repo returns 404 or 403 by design.
  • GitHub Cloud and GitHub Enterprise Server each decide which file extensions and content types they accept.
  • The skill embeds the URL itself; gh attach only prints it.

Security & Safety Notes

  • The user_session cookie is a full-account credential. Never print, export, paste, log, or commit it, and never make it available to CI or headless agents.
  • Do not install or upgrade gh-attach from a moving branch or an unpinned latest release. Re-review and update the exact --pin only in a repository change.
  • Uploaded attachments are auto-rendered by GitHub, so only upload files you intend to share with everyone who can view the target repository.
  • Confirm the destination -R <owner>/<repo> before uploading so an attachment is not created against the wrong repository.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/gh-attach of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Gh Attach next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gh Attach compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gh Attach this skillsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: PassMIT
Markitshift-labs-ai/markit1.3k—~299Automated safety check: PassMIT
Asu Resume Audit SkillClaycui828/ASu-resume-skills369—~1.5kAutomated safety check: PassMIT
Best SkillsLinklyAI/best-skills630—~575Automated safety check: PassCC-BY-4.0
Deepxiv Baseline TableDeepXiv/deepxiv_sdk802—~1.6kAutomated safety check: PassMIT
Editor Updateqwrtln/Homm3BG-mission-book110—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Markit

    shift-labs-ai/markit

    Convert files and URLs to Markdown. An agent skill from shift-labs-ai/markit.

    1.3k GitHub stars~299 tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Asu Resume Audit Skill

    Claycui828/ASu-resume-skills

    以证据为中心的简历真实性审计与报告生成技能。用户要求核验简历、打假履历、调查候选人经历、分析 GitHub/开源贡献、识别 contributor 到 maintainer/core author 的角色膨胀、核验中外合作办学或学校 title、检查业务指标、梳理公开争议,或者把调查结果制作成 HTML/PDF…

    369 GitHub stars~1.5k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Best Skills

    LinklyAI/best-skills

    Daily cross-platform rankings of AI agent skills (skills.sh, ClawHub, Tencent SkillHub, GitHub, X/HN/Bluesky).

    630 GitHub stars~575 tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Deepxiv Baseline Table

    DeepXiv/deepxiv_sdk

    Build a markdown baseline table for a research topic using deepxiv search, brief, head, and experiment-section reads, extracting paper title, URL, open-source status, datasets, benchmark scores, and…

    802 GitHub stars~1.6k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Editor Update

    qwrtln/Homm3BG-mission-book

    Build a feature or fix a bug in the browser scenario builder under web/ — app, shared parsers, compile/PDF preview, GitHub pull-request flow, picker, search, routes — with tests and every…

    110 GitHub stars~1.2k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Release Latex Fork

    zly2006/zhihu-plus-plus

    Release the LaTeX fork used by Zhihu++. An agent skill from zly2006/zhihu-plus-plus.

    4.2k GitHub stars~1.8k tokensUpdated today
    Documents & OfficeAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Questions about Gh Attach

What does Gh Attach do?

Upload and download GitHub user-attachments (screenshots, PDFs, zips, videos) from the terminal; use when asked to attach or embed a file in a PR, issue, or comment, or download an attachment URL. Gh Attach is an agent skill from sickn33/agentic-awesome-skills. Upload and download GitHub user-attachments (screenshots, PDFs, zips, videos) from the terminal; use when asked to attach or embed a file in a PR, issue, or comment, or download an attachment URL.

When should I use Gh Attach?

Gh Attach fits situations like: asked to attach; embed a file in a PR; download an attachment URL.

How do I install Gh Attach in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill gh-attach -a claude-code`. Or copy the skill folder (skills/gh-attach in sickn33/agentic-awesome-skills) into .claude/skills/gh-attach in your project. Claude Code loads it when a task matches its description.

How do I install Gh Attach in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill gh-attach -a codex`. Or copy the skill folder (skills/gh-attach in sickn33/agentic-awesome-skills) into .agents/skills/gh-attach in your project. Codex loads it when a task matches its description.

Can I use Gh Attach in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill gh-attach -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gh-attach, .gemini/skills/gh-attach, .github/skills/gh-attach and .opencode/skills/gh-attach in your project.

What does Gh Attach need to run?

Going by SKILL.md and its folder, Gh Attach needs the command-line tools its instructions call (gh).

Does Gh Attach access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Gh Attach safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gh Attach use?

Gh Attach is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gh Attach use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gh Attach?

Skills that share tags, products or a category with Gh Attach: Markit (shift-labs-ai/markit, 1.3k stars), Asu Resume Audit Skill (Claycui828/ASu-resume-skills, 369 stars), Best Skills (LinklyAI/best-skills, 630 stars) and Deepxiv Baseline Table (DeepXiv/deepxiv_sdk, 802 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gh Attach?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.