Agent skill

Sync Renovate

by agntcy in agntcy/coffeeAgntcy

Runs Renovate against this repo via task renovate:sync to open or update dependency update PRs.

Apache-2.0Auto-check passedDevelopment

Install Sync Renovate

skills CLI
$ npx skills add agntcy/coffeeAgntcy --skill sync-renovate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agntcy/coffeeAgntcy sync-renovate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agntcy/coffeeAgntcy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/repo-tooling/sync-renovate .claude/skills/sync-renovate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sync-renovate
GitHub stars
112
Token cost
~623 tokens
SKILL.md length
194 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs Renovate against this repo via task renovate:sync to open or update dependency update PRs.

  • Reason about the dependency update sync
  • SKILL.md covers When to use, What it does, Workflow and Rules
  • Needs GITHUB_COM_TOKEN and RENOVATE_TOKEN
  • Change what Renovate does (renovate.json)

What it does

Sync Renovate is an agent skill from agntcy/coffeeAgntcy. Runs Renovate against this repo via task renovate:sync to open or update dependency update PRs. Use when asked to run, debug, or reason about the dependency update sync, or to change what Renovate does (renovate.json).

Its SKILL.md is about 620 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. The repository describes itself as: End-to-end reference application for AGNTCY Components. The licence is Apache-2.0.

When your agent uses it

  • Reason about the dependency update sync
  • Change what Renovate does (renovate.json)

Example prompts

  • “/sync-renovate”

Requirements

  • A credential in GITHUB_COM_TOKEN
  • A credential in RENOVATE_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 78f588c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_COM_TOKEN
    • RENOVATE_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sync Renovate loads about 623 tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 194 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~623

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agntcy/coffeeAgntcy at commit 78f588c, republished under its Apache-2.0 licence (© agntcy). 194 words, ~623 tokens.

Download SKILL.mdSave it as .claude/skills/sync-renovate/SKILL.md (or your agent's skills folder).
name
sync-renovate
description
Runs Renovate against this repo via task renovate:sync to open or update dependency update PRs. Use when asked to run, debug, or reason about the dependency update sync, or to change what Renovate does (renovate.json).

Sync Renovate

When to use

When asked to run the dependency update sync by hand, to debug why a dependency update PR did or didn't appear, or to change Renovate's behavior. In normal operation nobody runs this locally: the Renovate workflow runs task renovate:sync every six hours (and on manual dispatch), the only caller today.

What it does

task renovate:sync (defined in Taskfile.yaml, wrapping scripts/renovate/sync_renovate.bash) runs the repo-local renovate binary, installed into .tools/bin/ by scripts/setup.sh at the version pinned in scripts/lib/versions.sh (see the manage-repo-tooling skill to bump it). Behavior is driven entirely by renovate.json and the RENOVATE_* / GITHUB_COM_TOKEN environment variables the caller sets; neither the task nor the script adds any configuration of its own.

This is a generative action, not a standing check, so it isn't part of task check:all; the Renovate workflow runs it on a schedule instead, and it has no separate rule. See "Scheduled generative operations" in the "Known exceptions" of .agents/rules/meta/repo-operation-pipeline.md.

Workflow

- [ ] 1. Run: ./scripts/setup.sh, then source scripts/env.sh (puts the pinned renovate on PATH)
- [ ] 2. To validate a config change without touching GitHub, run: renovate-config-validator renovate.json
- [ ] 3. To run a sync for real, ask the user first: it creates and updates branches and PRs on the remote repo. Set the same RENOVATE_* variables .github/workflows/renovate.yaml sets (RENOVATE_PLATFORM, RENOVATE_TOKEN, GITHUB_COM_TOKEN, ...), then run: task renovate:sync
- [ ] 4. Prefer RENOVATE_DRY_RUN=full for a local run that only logs what it would do

Rules

  • Never run a non-dry-run sync without the user's explicit go-ahead each time - it writes to a remote system.
  • Tool version pins carry # renovate: annotations in scripts/lib/versions.sh; keep them in that shape so Renovate keeps tracking them.

© agntcy, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/repo-tooling/sync-renovate of agntcy/coffeeAgntcy.

Open the folder on GitHubat commit 78f588c

Compare with similar skills

Sync Renovate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sync Renovate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sync Renovate this skillagntcy/coffeeAgntcy112—~623Automated safety check: PassApache-2.0
Add TTS Engine to Voiceboxjamiepine/voicebox57k—~1.3kAutomated safety check: PassMIT
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Merge Dependabot PRsonyx-dot-app/onyx32k1 repos~2.2kAutomated safety check: PassMIT
Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit2608 repos~1.2kAutomated safety check: NotesCustom licence
Update .NET OS Packagesdotnet/core22k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Add TTS Engine to Voicebox

    jamiepine/voicebox

    Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.

    57k GitHub stars~1.3k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Merge Dependabot PRs

    onyx-dot-app/onyx

    Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…

    32k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Senior Architect Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…

    260 GitHub starsUsed in 8 repos~1.2k tokens
    DevelopmentAuto-check: notes
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from agntcy/coffeeAgntcy

All 20 skills in this repo
  • A2a Protocol

    agntcy/coffeeAgntcy

    A skill your agent uses when the user asks about A2A (Agent-to-Agent) protocol communication, OASF record formats, AGNTCY directory operations, agent card parsing, or dirctl CLI usage.

    112 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Add Repo Operation

    agntcy/coffeeAgntcy

    Guides adding a new repository operation (a check, validation, or piece of tooling) through this repo's standard script - Taskfile task - skill - CI enforcement - rule pipeline.

    112 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Authors and maintains the human-facing Agentic Workflows API documentation for the lungo subproject at coffeeAGNTCY/coffeeagents/lungo/docs/workflow-instanceapi.md.

    112 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Checks whether any Helm chart under coffeeAGNTCY/coffeeagents/{corto,lungo}/deployment/helm// has content changes not covered by a later Chart.yaml version: bump, anywhere in that chart's history…

    112 GitHub stars~886 tokensUpdated yesterday
    Auto-check passed
  • Checking Pinned References

    agntcy/coffeeAgntcy

    Runs task pins:check to find any third-party GitHub Action, reusable-workflow, or image reference that isn't pinned to an immutable SHA/digest, and pins each one it finds.

    112 GitHub stars~578 tokensUpdated yesterday
    Auto-check passed
  • Runs task workflows:check-permissions to find any GitHub Actions workflow file with a write-all grant or no declared permissions, and scopes it down to least privilege.

    112 GitHub stars~513 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Sync Renovate

What does Sync Renovate do?

Runs Renovate against this repo via task renovate:sync to open or update dependency update PRs. Sync Renovate is an agent skill from agntcy/coffeeAgntcy. Runs Renovate against this repo via task renovate:sync to open or update dependency update PRs.

When should I use Sync Renovate?

Sync Renovate fits situations like: reason about the dependency update sync; change what Renovate does (renovate.json).

How do I install Sync Renovate in Claude Code?

Run `npx skills add agntcy/coffeeAgntcy --skill sync-renovate -a claude-code`. Or copy the skill folder (.agents/skills/repo-tooling/sync-renovate in agntcy/coffeeAgntcy) into .claude/skills/sync-renovate in your project. Claude Code loads it when a task matches its description.

How do I install Sync Renovate in Codex?

Run `npx skills add agntcy/coffeeAgntcy --skill sync-renovate -a codex`. Or copy the skill folder (.agents/skills/repo-tooling/sync-renovate in agntcy/coffeeAgntcy) into .agents/skills/sync-renovate in your project. Codex loads it when a task matches its description.

Can I use Sync Renovate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agntcy/coffeeAgntcy --skill sync-renovate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sync-renovate, .gemini/skills/sync-renovate, .github/skills/sync-renovate and .opencode/skills/sync-renovate in your project.

What does Sync Renovate need to run?

Going by SKILL.md and its folder, Sync Renovate needs credentials named GITHUB_COM_TOKEN and RENOVATE_TOKEN. Our summary lists: A credential in GITHUB_COM_TOKEN; A credential in RENOVATE_TOKEN.

Does Sync Renovate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sync Renovate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sync Renovate use?

Sync Renovate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sync Renovate use?

About 623 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sync Renovate?

Skills that share tags, products or a category with Sync Renovate: Add TTS Engine to Voicebox (jamiepine/voicebox, 57k stars), Dep Updates (trufflesecurity/trufflehog, 28k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Senior Architect Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sync Renovate?

agntcy (a GitHub organization) maintains it in agntcy/coffeeAgntcy, which has 112 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 9, 2026.

Source: agntcy/coffeeAgntcy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.