Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Built-in skill `github-pr-media` cannot run: `gh auth token` is empty in a cloud agent session, and the endpoint rejects `Bearer`

Open Beginner friendly
#4,932 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
75/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
github-actions, shell

Research direction

Look at builtin-skills/github-pr-media/SKILL.md. The issue describes three faults: the Authorization header uses the wrong scheme and token source, the final PR edit step requires an extra scope, and an unused environment variable. Start by reading the skill file to see the curl command and the gh pr edit call. Test the proposed fix: change 'Bearer $(gh auth token)' to 'token $GITHUB_COPILOT_API_TOKEN' and replace gh pr edit with gh api --method PATCH. Check if copilot_swe_agent_use_attachment_proxy is referenced anywhere in the codebase. Verify the changes work in a cloud agent session by running the skill end-to-end.

Written by the indexing model from the issue text.

Description

triage
Describe the bug

The runtime ships builtin-skills/github-pr-media/SKILL.md. Run as written inside a Copilot cloud agent session, it fails at every step. A session can attach media - its own credential works -but not by following this skill.

Fault 1 - the authorization line is wrong twice

-H "Authorization: Bearer $(gh auth token)"
  • gh auth token returns nothing in a session. GH_TOKEN, GITHUB_TOKEN and GH_ENTERPRISE_TOKEN are all unset, and gh auth status reports the default token as invalid.
  • Bearer is the wrong scheme for this endpoint. It answers 404 Not Found, which reads as a missing endpoint rather than a wrong header.

Fault 2 - the final step needs a scope the session does not have

The skill finishes with gh pr edit --body-file -. That always requests the reviewRequests field, so it needs read:org. See cli/cli #13575, still open. gh api --method PATCH repos/{owner}/{repo}/pulls/{n} has no such requirement.

What actually works

A session holds GITHUB_COPILOT_API_TOKEN, a ghu_ GitHub App user-to-server token, and the attachment endpoint accepts it:

curl --fail-with-body -sS -X POST "$GITHUB_UPLOADS_URL" \
  --url-query "name=e.png" --url-query "content_type=image/png" \
  --url-query "repository_id=$GITHUB_REPOSITORY_ID" \
  -H "Content-Type: application/octet-stream" \
  -H "X-GitHub-Api-Version: 2022-11-28" \
  -H "Authorization: token $GITHUB_COPILOT_API_TOKEN" \
  --data-binary @e.png
HTTP/2 201
{"url":"https://<host>/user-attachments/assets/<uuid>"}

Six variants in one session, changing only the Authorization header:

Credential Scheme Answer
GITHUB_COPILOT_API_TOKEN Bearer HTTP/2 404
GITHUB_COPILOT_API_TOKEN token HTTP/2 201
COPILOT_SDK_AUTH_TOKEN Bearer HTTP/2 404
COPILOT_SDK_AUTH_TOKEN token HTTP/2 201
GITHUB_VERIFICATION_TOKEN Bearer HTTP/2 404
none - HTTP/2 404

The whole route then ran end to end in one session: make a PNG, open a draft pull request, upload, place the URL in the description with the harness tool, delete the file from the branch. The capture still renders, because the asset does not live in the repository.

Fault 3 - a flag that names nothing

The session environment carries copilot_swe_agent_use_attachment_proxy=true. I tested every local listener looking for what it selects. The Copilot API proxy answers 403 and the git credential proxy answers 406, and nothing in the runtime bundle reads that variable. Either wire it up or drop it, because it reads like a supported route and is not one.

What I ask for

  1. Change the skill to Authorization: token $GITHUB_COPILOT_API_TOKEN.
  2. Change its final step to gh api --method PATCH, or to the harness tool that writes the description.
  3. Remove or implement copilot_swe_agent_use_attachment_proxy.

Related: cli/cli refuses ghu_ in --attach for the same endpoint, which is the other half of why this looks unreachable. I filed that separately in #14495

Affected version

No response

Steps to reproduce the behavior

No response

Expected behavior

No response

Additional context

No response

Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/copilot-cli

All issues in github/copilot-cli

Similar issues

More Shell/Bash issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.