github-pr-proof-assets
Installation
SKILL.md
GitHub PR Proof Assets
Upload local proof assets through GitHub's undocumented but working user-attachments endpoint, then post their returned URLs with gh.
Safety
- Treat the upload endpoint as undocumented and subject to change.
- Never print, log, or store
gh auth token. Expand it only inside theAuthorizationheader. - Never commit proof assets or place them in
.github/pr-assets. - Confirm the target repository and PR/issue before posting.
- Delete only temporary or transcoded files created by this task. Never delete source assets.