CatalogOpenAI Codex Skills · OpenAI

gh-fix-ci

Use when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions; use `gh` to inspect checks and logs, summarize failure context, draft a fix plan, and implement only after explicit approval. Treat external providers (for example Buildkite) as out of scope and report only the details URL.

Review advisedOfficial28k starsalso listed on skills.sh

Savant verdict: Review advised

SkillSpector or the source hub flagged patterns to review before use.

Live evaluation

57overall
46quality
58compliance
77grounding
45actionability
69efficiency
Why this score may understate the skillThe live evaluation is a chat-only run: the model follows the skill's instructions but can't execute its scripts, call tools or reach the network.
  • Ships 1 script the live run can't execute; outputs describe those steps rather than perform them.
Live telemetry from real runs (via the Savant skill router) replaces this estimate as it accumulates.

0 pass · 1 investigate · 6 fail across 7 cases. Jev accepted 7 of 13 LLM-drafted cases. Drafted and run by nvidia/nemotron-3-super-120b-a12b, validated and scored by jev-latest.

  • The GitHub Actions checks for PR #42 in my repo are failing. Can you inspect the logs and help me fix the issue?positive case · fail
  • PR #15 has a failing lint job. Show me the error and suggest a fix.positive case · fail
  • The Docker build step in GitHub Actions is failing for PR #88. Help me debug.positive case · fail
  • The tests are failing in the workflow. What's wrong?edge case · fail
  • Check why the build is failing. I think it's the dependencies.edge case · fail
  • Fix the failing Buildkite pipeline for PR #10.negative case · investigate
  • Update the README to fix the CI badge.negative case · fail

Safety (NVIDIA SkillSpector)

Risk score
22/100
Recommendation
CAUTION
Severity
MEDIUM
Savant decision
Review advised
SkillSpector rated it CAUTION with a risk score of 20/100 or more; review the findings before use. SkillSpector 2.12.0, static analysis.

4 patterns found

  • MCP Least Privilege: Skill declares no tool scope ('permissions' or 'allowed-tools') but code capabilities were detected: shell.medium · SKILL.md:1 · Without declared permissions the skill's intent is opaque and cannot be validated.
  • Dangerous Code Execution: subprocess.run( ["gh", *args], cwd=cwd, text=True, capture_output=True, )medium · scripts/inspect_pr_checks.py:59 · subprocess module calls execute external commands. Without careful input validation, this enables command injection.
  • Dangerous Code Execution: subprocess.run( ["gh", *args], cwd=cwd, capture_output=True, )medium · scripts/inspect_pr_checks.py:69 · subprocess module calls execute external commands. Without careful input validation, this enables command injection.
  • Dangerous Code Execution: subprocess.run( ["git", "rev-parse", "--show-toplevel"], cwd=start, text=True, capture_output=True, )medium · scripts/inspect_pr_checks.py:139 · subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Structure

  • Ships 1 executable scriptscripts/inspect_pr_checks.py. Review what they do before enabling the skill for agents with tool access.

SKILL.md

---
name: "gh-fix-ci"
description: "Use when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions; use `gh` to inspect checks and logs, summarize failure context, draft a fix plan, and implement only after explicit approval. Treat external providers (for example Buildkite) as out of scope and report only the details URL."
---


# Gh Pr Checks Plan Fix

## Overview

Use gh to locate failing PR checks, fetch GitHub Actions logs for actionable failures, summarize the failure snippet, then propose a fix plan and implement after explicit approval.
- If a plan-oriented skill (for example `create-plan`) is available, use it; otherwise draft a concise plan inline and request approval before implementing.

Prereq: authenticate with the standard GitHub CLI once (for example, run `gh auth login`), then confirm with `gh auth status` (repo + workflow scopes are typically required).

## Inputs

- `repo`: path inside the repo (default `.`)
- `pr`: PR number or URL (optional; defaults to current branch PR)
- `gh` authentication for the repo host

## Quick start

- `python "<path-to-skill>/scripts/inspect_pr_checks.py" --repo "." --pr "<number-or-url>"`
- Add `--json` if you want machine-friendly output for summarization.

## Workflow

1. Verify gh authentication.
   - Run `gh auth status` in the repo.
   - If unauthenticated, ask the user to run `gh auth login` (ensuring repo + workflow scopes) before proceeding.
2. Resolve the PR.
   - Prefer the current branch PR: `gh pr view --json number,url`.
   - If the user provides a PR number or URL, use that directly.
3. Inspect failing checks (GitHub Actions only).
   - Preferred: run the bundled script (handles gh field drift and job-log fallbacks):
     - `python "<path-to-skill>/scripts/inspect_pr_checks.py" --repo "." --pr "<number-or-url>"`
     - Add `--json` for machine-friendly output.
   - Manual fallback:
     - `gh pr checks <pr> --json name,state,bucket,link,startedAt,completedAt,workflow`
       - If a field is rejected, rerun with the available fields reported by `gh`.
     - For each failing check, extract the run id from `detailsUrl` and run:
       - `gh run view <run_id> --json name,workflowName,conclusion,status,url,event,headBranch,headSha`
       - `gh run view <run_id> --log`
     - If the run log says it is still in progress, fetch job logs directly:
       - `gh api "/repos/<owner>/<repo>/actions/jobs/<job_id>/logs" > "<path>"`
4. Scope non-GitHub Actions checks.
   - If `detailsUrl` is not a GitHub Actions run, label it as external and only report the URL.
   - Do not attempt Buildkite or other providers; keep the workflow lean.
5. Summarize failures for the user.
   - Provide the failing check name, run URL (if any), and a concise log snippet.
   - Call out missing logs explicitly.
6. Create a plan.
   - Use the `create-plan` skill to draft a concise plan and request approval.
7. Implement after approval.
   - Apply the approved plan, summarize diffs/tests, and ask about opening a PR.
8. Recheck status.
   - After changes, suggest re-running the relevant tests and `gh pr checks` to confirm.

## Bundled Resources

### scripts/inspect_pr_checks.py

Fetch failing PR checks, pull GitHub Actions logs, and extract a failure snippet. Exits non-zero when failures remain so it can be used in automation.

Usage examples:
- `python "<path-to-skill>/scripts/inspect_pr_checks.py" --repo "." --pr "123"`
- `python "<path-to-skill>/scripts/inspect_pr_checks.py" --repo "." --pr "https://github.com/org/repo/pull/123" --json`
- `python "<path-to-skill>/scripts/inspect_pr_checks.py" --repo "." --max-lines 200 --context 40`