Agent skill

PR Bump

by akitaonrails in akitaonrails/my-skills

Merge Dependabot / dependency-bot bump PRs quickly and safely.

No licenceAuto-check passedDevelopment

Install PR Bump

skills CLI
$ npx skills add akitaonrails/my-skills --skill pr-bump -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akitaonrails/my-skills pr-bump --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akitaonrails/my-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/pr-bump .claude/skills/pr-bump && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pr-bump
GitHub stars
216
Token cost
~2.7k tokens
SKILL.md length
1,321 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
None found

At a glance

Merge Dependabot / dependency-bot bump PRs quickly and safely.

  • Works in 5 steps: Inspect Open PRs → Consolidate with the Package Manager → Verify Locally → …
  • Tasks that involve Dependency management
  • SKILL.md covers Fast Path Summary, Preconditions and Guardrails, Step 1: Inspect Open PRs and Step 2: Consolidate with the…, plus 4 more sections
  • Calls git, gh and bundle; needs ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY and ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY

What it does

PR Bump is an agent skill from akitaonrails/my-skills. Merge Dependabot / dependency-bot bump PRs quickly and safely. Use only for bot-authored dependency-only PRs (Dependabot, gem/npm/pip bumps); anything touching application code, migrations, Dockerfiles, or non-dependency config goes to pr-audit instead.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Code migrations and Containers. It works with npm and Git. The repository describes itself as: akitaonrails' personal skills (not tailored for general usage).

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Code migrations
  • Tasks that involve Containers

Example prompts

  • “/pr-bump”

Requirements

  • Docker
  • A credential in ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY
  • A credential in ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Inspect Open PRs
  2. Consolidate with the Package Manager
  3. Verify Locally
  4. Commit and Push
  5. Deploy When Requested

What it can do on your machine

Read from SKILL.md and the folder at commit 285ca82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • bundle
    • rails

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY
    • ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

PR Bump loads about 2.7k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 1,321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,321 words (~2,729 tokens).

“Use this workflow to clear routine Dependabot dependency bump PRs without breaking the app or accidentally shipping unrelated local changes.”

— opening of SKILL.md by akitaonrails
name
pr-bump

Read the full SKILL.md on GitHub

Files

Just SKILL.md in pr-bump of akitaonrails/my-skills.

Open the folder on GitHubat commit 285ca82

Compare with similar skills

PR Bump next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

PR Bump compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
PR Bump this skillakitaonrails/my-skills216—~2.7kAutomated safety check: PassNone
Flowfile Build and Environment SetupEdwardvaneechoud/Flowfile389—~7.3kAutomated safety check: NotesMIT
Migrate Internal Package into GhostTryGhost/Ghost56k—~3.8kAutomated safety check: PassMIT
OBS Plugin Dependency Upgradesorayuki/obs-multi-rtmp5.1k—~609Automated safety check: PassGPL-2.0
CLIProxy Core Synccaidaoli/ccLoad419—~1.5kAutomated safety check: PassMIT
Breaking Change Analysisruby-git/ruby-git1.8k—~1.7kAutomated safety check: PassMIT

Similar skills

  • Flowfile Build and Environment Setup

    Edwardvaneechoud/Flowfile

    Recreates every Flowfile development and build environment from scratch, with exact version pins and an explanation of what each Makefile target really does.

    389 GitHub stars~7.3k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    56k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • OBS Plugin Dependency Upgrade

    sorayuki/obs-multi-rtmp

    Updates the obs-multi-rtmp plugin repo to the latest upstream plugin template and OBS Studio version, including dependency metadata, then rebuilds it with CMake.

    5.1k GitHub stars~609 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • CLIProxy Core Sync

    caidaoli/ccLoad

    Syncs or audits ccLoad's CLIProxyAPI protocol-conversion core and registered provider adapters against one pinned upstream commit, then verifies the result.

    419 GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Breaking Change Analysis

    ruby-git/ruby-git

    Assesses what an API change would break before it is made, finds every usage, documents the impact and plans a deprecation or migration path.

    1.8k GitHub stars~1.7k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    171 GitHub stars~3.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes

More from akitaonrails/my-skills

All 18 skills in this repo
  • Fact Check

    akitaonrails/my-skills

    Adversarial fact-checking of the user's articles and essays (typically blog posts from akitaonrails-hugo, any markdown/text file), verifying every claim against online primary sources via cheap…

    220 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Blog Cost Charts

    akitaonrails/my-skills

    Generate dark-themed cost-vs-score bubble scatter charts and score/(costtime) value-ranking bar charts for a blog post comparing LLM benchmark results (or any dataset with a score/cost/time shape)…

    220 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Codemap

    akitaonrails/my-skills

    Generate comprehensive hierarchical codemaps for UNFAMILIAR repositories.

    220 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Clonedeps

    akitaonrails/my-skills

    Clone important project dependency source code into an ignored local workspace so OpenCode can inspect library internals.

    220 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • GitHub Resolution

    akitaonrails/my-skills

    Execute the approved outcomes of a pr-audit and/or iss-audit — fix or adjust everything the audit found necessary before merging, verify no regressions, cover every new behavior with unit tests…

    220 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Post Refactor

    akitaonrails/my-skills

    Post-refactor clean-code check after recent refactors or a few merged PRs.

    220 GitHub stars~1.5k tokensUpdated today
    Auto-check: notes

Works with

Questions about PR Bump

What does PR Bump do?

Merge Dependabot / dependency-bot bump PRs quickly and safely. PR Bump is an agent skill from akitaonrails/my-skills. Merge Dependabot / dependency-bot bump PRs quickly and safely.

When should I use PR Bump?

PR Bump fits situations like: tasks that involve Dependency management; tasks that involve Code migrations; tasks that involve Containers.

How do I install PR Bump in Claude Code?

Run `npx skills add akitaonrails/my-skills --skill pr-bump -a claude-code`. Or copy the skill folder (pr-bump in akitaonrails/my-skills) into .claude/skills/pr-bump in your project. Claude Code loads it when a task matches its description.

How do I install PR Bump in Codex?

Run `npx skills add akitaonrails/my-skills --skill pr-bump -a codex`. Or copy the skill folder (pr-bump in akitaonrails/my-skills) into .agents/skills/pr-bump in your project. Codex loads it when a task matches its description.

Can I use PR Bump in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akitaonrails/my-skills --skill pr-bump -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pr-bump, .gemini/skills/pr-bump, .github/skills/pr-bump and .opencode/skills/pr-bump in your project.

What does PR Bump need to run?

Going by SKILL.md and its folder, PR Bump needs the command-line tools its instructions call (git, gh, bundle and rails) and credentials named ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY and ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY. Our summary lists: Docker; A credential in ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY; A credential in ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY.

Does PR Bump access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is PR Bump safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does PR Bump use?

No licence was found for PR Bump or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does PR Bump use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to PR Bump?

Skills that share tags, products or a category with PR Bump: Flowfile Build and Environment Setup (Edwardvaneechoud/Flowfile, 389 stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 56k stars), OBS Plugin Dependency Upgrade (sorayuki/obs-multi-rtmp, 5.1k stars) and CLIProxy Core Sync (caidaoli/ccLoad, 419 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains PR Bump?

akitaonrails (a GitHub user) maintains it in akitaonrails/my-skills, which has 216 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 23, 2026.

Source: akitaonrails/my-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.