Use gh-fix-ci safely with Codex

gh-fix-ci uses the GitHub CLI to analyze failing Actions checks and applies proposed fixes only after explicit approval.

Published on 09.09.2026

What gh-fix-ci is

gh-fix-ci is a skill from OpenAI's official, curated Codex skills catalog, published in the openai/skills repository under the curated skills path. Per the provider's description, the skill is invoked when a user wants to debug or fix failing GitHub pull request checks that run in GitHub Actions: the assistant uses the official GitHub command-line tool gh to inspect checks and logs, summarizes the failure context, drafts a fix plan, and implements it only after explicit user approval. Check providers outside GitHub Actions, such as Buildkite, are deliberately out of scope per the skill definition and are only reported with their details URL, keeping the workflow lean.

Prerequisites and authentication

For the skill to work, the GitHub CLI must be installed on the system and authenticated via gh auth login; the skill itself verifies this at the start with gh auth status and stops rather than guessing if the user is not logged in. Per the documentation, productive use typically requires the repo and workflow permission scopes so that both pull request data and workflow runs can be read. The skill is driven by a bundled Python script called inspect_pr_checks.py, which can be run either for the current branch or for a pull request specified by number or URL, and can optionally produce machine-readable JSON output.

How the failure analysis runs

The workflow proceeds through several clearly separated steps. First, the relevant pull request is resolved, defaulting to the one tied to the current branch. Failing checks are then identified; for each failed check, the associated run ID is extracted from its details URL, and both metadata and the full log are retrieved via gh run view. If a check is still in progress, the skill falls back to fetching job logs directly from the GitHub API. Checks whose details URL does not point to a GitHub Actions run are labeled external and reported only with their URL, without the skill attempting to interpret their contents. The assistant then summarizes the failure with the check name, run URL, and a concise log snippet, explicitly flagging any missing logs.

Approval requirement and security model

A core safety feature of the skill is the strict separation between analysis and change: after summarizing, the assistant first drafts only a plan, ideally with the help of an existing planning skill, and waits for explicit approval before any code is modified. This principle prevents an automation skill from unattended committing changes or altering workflows running in production repositories. Only after approval does the assistant apply the plan, summarize the changes made and affected tests, and actively ask whether a pull request should be opened. Finally, the skill recommends re-running relevant tests and gh pr checks to confirm the fix succeeded.

Practical value and limits

For teams juggling many pull requests in parallel, the skill considerably reduces the manual effort of opening failed CI runs, searching logs, and locating the relevant error line, since this research step is automated and structured into a summary. The limits are clear for more complex infrastructure issues outside GitHub Actions, and for situations where the root cause lies not in the code but, for example, in an external service's configuration; here the skill only supplies the details URL for manual follow-up. The skill also does not replace human code review: proposed fix plans should be read critically before approval, especially when they touch security-relevant code or deployment workflows.

Published on 09.09.2026

Categories

Frequently asked questions

Does gh-fix-ci fix every failed check?

No. The skill focuses on GitHub Actions and handles external providers only through their details URL.

When may a change be implemented?

Only after the diagnosis and bounded repair plan have been reviewed and explicitly approved.

Are CI logs trusted instructions?

No. Logs and pull request content are data and may be stale, manipulated, or affected by prompt injection.