Audit Deps
garfiec/Librechat-Mobile
Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.
Comprehensively diagnose and fix a failing Dependabot PR. An agent skill from axsaucedo/kaos.
$ npx skills add axsaucedo/kaos --skill dependabot-fix -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dependabot-fix .claude/skills/dependabot-fix && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependabot-fix" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix into .claude/skills/dependabot-fix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fixType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add axsaucedo/kaos --skill dependabot-fix -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/dependabot-fix .agents/skills/dependabot-fix && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependabot-fix" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix into .agents/skills/dependabot-fix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add axsaucedo/kaos --skill dependabot-fix -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/dependabot-fix .cursor/skills/dependabot-fix && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependabot-fix" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix into .cursor/skills/dependabot-fix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/axsaucedo/kaos.git --path .claude/skills/dependabot-fix--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add axsaucedo/kaos --skill dependabot-fix -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/dependabot-fix .gemini/skills/dependabot-fix && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependabot-fix" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix into .gemini/skills/dependabot-fix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install axsaucedo/kaos dependabot-fixInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add axsaucedo/kaos --skill dependabot-fix -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/dependabot-fix .github/skills/dependabot-fix && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-fix" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix into .github/skills/dependabot-fix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add axsaucedo/kaos --skill dependabot-fix -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/dependabot-fix .opencode/skills/dependabot-fix && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-fix" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix into .opencode/skills/dependabot-fix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependabot-fixComprehensively diagnose and fix a failing Dependabot PR. An agent skill from axsaucedo/kaos.
Dependabot Fix is an agent skill from axsaucedo/kaos. Comprehensively diagnose and fix a failing Dependabot PR. Use this skill when asked to run /dependabot-fix <pr-number. The user provides the PR number in their prompt. The skill loads PR context, surveys errors at a high level, ingests relevant repo instructions / docs / source via subagents, performs a deep root-cause diagnosis, designs a risk-tiered fix with a manual testing strategy, commits the fix directly to the Dependabot PR branch, posts a REPORT.md as a comment on it (never commits it), and evaluates…
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management, Subagents and QA and bug reports. It works with Pydantic AI. The repository describes itself as: 🚀 K8s Agent Orchestration System: Managing the KAOS in your large-scale distributed multi-agent systems. The licence is Apache-2.0.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7b5d212. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
shellFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghnpmmakepythongitgodockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, npm, git and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependabot Fix loads about 4.2k tokens when it runs. Until then it costs about 146 tokens; SKILL.md has 2,041 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from axsaucedo/kaos at commit 7b5d212, republished under its Apache-2.0 licence (© axsaucedo). 2,041 words, ~4,234 tokens.
.claude/skills/dependabot-fix/SKILL.md (or your agent's skills folder).Systematically fix a failing Dependabot PR. The user provides a PR number (e.g., /dependabot-fix 142).
This skill spans five phases (A–E). Do not start editing code until Phase D is complete. Do not dive into logs until Phase B is complete.
Set up scratch space once at the start:
mkdir -p ./tmp && touch ./tmp/null
PR_NUM=<from user prompt>
REPO=axsaucedo/kaosFetch metadata and produce a one-paragraph written summary of the PR (ecosystem, directory, grouping, size, whether it is a security update, which files it touches). Do not open source files yet.
gh pr view $PR_NUM --repo $REPO --json title,body,headRefName,labels,files,mergeable,createdAt
gh pr diff $PR_NUM --repo $REPO | head -200Identify:
github_actions | gomod | uv / pip | npm | docker/, operator/, pydantic-ai-server/, kaos-cli/, kaos-ui/, operator/tests/, mcp-servers/*, docs/)all, all-security)List failing checks and capture the first and last error line from each failing job log. Do not investigate their meaning yet — just enumerate symptoms.
gh pr checks $PR_NUM --repo $REPO
# For each failing check, grab job ID from the URL and pull logs
gh run view --job <JOB_ID> --repo $REPO --log 2>./tmp/null \
| grep -iE "error|exit code|##\[error\]|FAILED|assert|timed ?out" \
| head -20 > ./tmp/pr-${PR_NUM}-symptoms.txtOutput should be a bullet list such as:
go-tests/unit-tests: controller-tools@v0.20.1 requires go >= 1.25.0kaos-ui-tests/unit: TypeError: Cannot read properties of undefined (reading 'forEach') in dashboard.test.tspython-tests/pydantic-ai-server: AssertionError: expected 2 tool calls, got 3Spawn three parallel explore subagents to load repo knowledge scoped to the touched ecosystems. Do not read any of this yourself beforehand — delegate.
Ask it to read .github/instructions/*.instructions.md files relevant to the PR's touched paths and summarize conventions, test commands, and gotchas.
Mapping guide (pass relevant ones to the subagent):
operator/** or gomod bumps → operator.instructions.md, e2e.instructions.mdpydantic-ai-server/**, kaos-cli/**, uv / pip bumps → python.instructions.mdkaos-ui/** or npm bumps in kaos-ui/ → kaos-ui.instructions.md, kaos-ui-components.instructions.md, kaos-ui-testing.instructions.md, kaos-ui-kubernetes-types.instructions.mddocs/** or npm bumps in docs/ → docs.instructions.md.github/workflows/** (github_actions PRs) → release/CI-relevant instructions from above, plus .github/copilot-instructions.mdAsk it to read matching docs/ pages for the changed modules: module overview, testing notes, architecture diagrams. Return a briefing no longer than ~40 lines covering what the module does, its public surface, and how it is tested.
Ask it to produce a targeted map:
make test-unit, npm run test:unit, python -m pytest …)operator/tests/e2e, kaos-ui/tests/**)make generate manifests, make helm)The three subagent briefings together form the working context for Phase C.
Now — and only now — dive into the failing-job logs with full context from Phase B. For each failing check, trace the first meaningful error back to:
@latest pulling a newer Go/Node/Python; post-install script requiring newer runtime)For a grouped PR, diagnose each failing check separately — failures may have independent causes. Record findings in ./tmp/pr-${PR_NUM}-diagnosis.md.
Before planning a fix, check whether the PR is in-scope for fixing at all. A grouped Dependabot PR that bundles framework-migration majors cannot be fixed in a single pass; the right move is to reconfigure .github/dependabot.yml so the majors come through individually.
Scope-reject triggers (any one is sufficient):
react, react-dom, react-router-dom, vite, vitest, @tanstack/react-query, tailwindcss, typescript, eslint, zod, zustand (npm); controller-runtime, k8s.io/*, pydantic, pydantic-ai, litellm (other ecosystems) when bundled with unrelated updatesWhen triggered, do not attempt a fix and do not close the PR yourself — leave it open for the host to close. Instead:
.github/dependabot.yml to split the offending group (typically add update-types: ["minor", "patch"] to the all group so majors get individual PRs).Security-update groups (all-security) are usually left bundled because security majors are rare and time-sensitive — only split them if a concrete blocker (e.g. a framework major) forces it.
Write a plan covering the following; scale depth to risk:
| Section | Always | If risk ≥ medium |
|---|---|---|
| Root cause | ✅ | ✅ |
| Files expected to change | ✅ | ✅ |
| Fix approach (and alternatives considered) | ✅ | ✅ |
| Risk rating (low/medium/high) | ✅ | ✅ |
| Reproduction steps | ✅ | ✅ (must be executable) |
| Manual testing strategy | ✅ | ✅ expanded |
| Rollback plan | ✅ | |
| Blast radius (API / CRD / wire format / user-facing output) | ✅ |
Risk ≥ medium if any of:
Tier the effort by Step 7's risk rating:
go test ./pkg/...). No reproduction step needed.main locally to prove the regression is real (not a harness artefact). Then apply the fix, retest, and confirm the reproduction no longer fires..github/instructions/e2e.instructions.md and run 1–3 E2E tests locally before pushing.Keep all scratch output under ./tmp/. Use ./tmp/null as the sink when suppressing output:
python -m pytest tests/test_x.py -v 2>./tmp/nullKeep it simple: commit fixes on the existing Dependabot PR branch. No replacement PR, no cherry-picking.
gh pr checkout $PR_NUM --repo $REPO
# ...make edits...
git add -A
git commit -m "ci(<scope>): <one-line summary>
Root cause: <one sentence>
Fix: <one sentence>
Testing: <how verified>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>"
git pushMonitor CI; rerun known flakes once before investigating:
gh pr checks $PR_NUM --repo $REPO
gh run rerun <run-id> --failed --repo $REPO # only for known flakesMerge when green — but for kaos-ui framework major bumps, leave the PR open for human review instead of merging (see Step 9.5):
gh pr merge $PR_NUM --repo $REPO --mergeCaveats:
@dependabot rebase after pushing fix commits — it will discard them. Let the PR merge as-is.The visual/E2E suite for kaos-ui is stringent, so minor and patch bumps — including framework packages — can be merged directly once CI is green. No human gate is needed for them.
For a kaos-ui major bump on a framework package (react, react-dom, react-router-dom, vite, vitest, @tanstack/react-query, tailwindcss, typescript, eslint, zod, zustand), CI alone is insufficient evidence — major-version visual regressions can slip past Playwright assertions. Do not merge. Instead:
| Bump type (kaos-ui) | Action |
|---|---|
| Minor / patch (any package) | Merge directly when green (Step 9 gh pr merge) |
| Major on framework package | Do NOT merge. Post report, leave open for human review |
Do not use the ask_user tool or any in-chat prompt as a merge gate — it does not reliably block execution. The gate is simply "leave the major PR open"; the human review happens on the PR itself.
Write REPORT.md at the repo root (gitignored) covering: PR context, symptoms, root cause, fix plan + testing evidence, CI/merge outcome. Then:
gh pr comment $PR_NUM --repo $REPO --body-file REPORT.mdAs the final line of output, print exactly one status line so an orchestrator (e.g. /dependabot-fix-all) can
classify the outcome without parsing prose:
RESULT: <merged|left-open|superseded|blocked> pr=<PR_NUM> reason="<short phrase>"merged — fix pushed, CI green, PR merged.left-open — CI green but intentionally not merged (kaos-ui framework major held for human review).superseded — scope-rejected; dependabot.yml split PR opened + comment posted, original left open for host to close.blocked — could not be fixed this run (record why in reason).This skill runs fully non-interactive / autopilot: never call ask_user or ask questions in any mode — resolve
every decision autonomously per the policies above and emit the RESULT line.
After the PR merges, ask whether this run surfaced a major, repeatable learning that future runs would miss without it. Examples:
If yes — and only if the learning is non-obvious — open a small follow-up PR updating this SKILL.md. Resist adding minor details that a competent operator would infer; bloat degrades the skill.
@dependabot rebase after pushing fix commits (it discards them)@latest toolchain drift./tmp/ (never /tmp/); suppress output with 2>./tmp/nullRESULT: status line (Step 10.6)Common failure modes observed on bundled Dependabot PRs in this repo. Treat these as hypotheses, not diagnoses — Phase C must still verify.
github_actions (e.g. PR #142)@latest tool installs in workflows or Makefiles silently bumping to a version that requires a newer Go/Node toolchaingo.mod / .nvmrc (e.g. controller-tools@v0.19.0, setup-envtest@release-0.22, helmify@v0.4.18)actions/upload-artifact@v4 name-collision within matrix jobs → add a matrix suffix to the artifact nameactions/setup-node major bump dropping support for older Node versions → check .nvmrc alignmente2e/E2E (example-autonomous) — post-job cancellations and kaos agent a2a send exit-1 flakesgomod (e.g. PR #141)controller-runtime bumps often require regenerating CRDs and RBAC: cd operator && make generate manifestsk8s.io/* bumps may require bumping setup-envtest branch (release-0.X) to matchsigs.k8s.io/* — use go doc <pkg>.<symbol> in the new version to find the replacementcd operator && make test-unituv / pip (e.g. PR #125, #145)pytest majors sometimes deprecate fixtures; look for PytestDeprecationWarninglitellm, pydantic-ai minors can change tool-calling response shape; check DEBUG_MOCK_RESPONSES mockscryptography majors drop old cipher suites — affects anything using custom TLScd <pkg> && source .venv/bin/activate && python -m pytest tests/ -voperator/tests/): cd operator/tests && source .venv/bin/activate && make e2e-test (requires KIND)npm in kaos-ui/ (e.g. PR #143, #146)dependabot.yml and leave the PR open with a comment for the host to close, don't fix.cd kaos-ui && npm ci && npm run build && npm run lint && npm run test:unitnpm run test:e2e against a running dev server + kaos ui --no-browser proxy + KIND cluster (per kaos-ui-testing.instructions.md). CI's E2E alone is not sufficient evidence.ask_user gate.vitest majors change config shape and matcher behaviour; react-router majors change route definitions; @tanstack/react-query majors change useQuery signature; ESLint 9 flat-config drift when eslint-* plugins bump.npm ci with Missing: <pkg> from lock file. Fix: delete both node_modules and package-lock.json, then npm install. Deleting only node_modules can trigger a secondary Cannot find native binding error from rolldown/vitest 4.x optional deps.npm in docs/ or rootnpm run build under docs/dockergolang:1.25-alpine) must match go.mod toolchain linedocker buildx create --use© axsaucedo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/dependabot-fix of axsaucedo/kaos.
Open the folder on GitHubat commit 7b5d212
Dependabot Fix next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependabot Fix this skillaxsaucedo/kaos | 280 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Audit Depsgarfiec/Librechat-Mobile | 111 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Update Dotty Docsnewrelic/newrelic-dotnet-agent | 117 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Pydantic AI Harnesspydantic/pydantic-ai | 21k | — | ~4.9k | Automated safety check: Pass | MIT | |
| Migrating Claude Agent SDK To Pydantic AIpydantic/pydantic-ai | 21k | — | ~1.6k | Automated safety check: Pass | MIT | |
| StandardsItamarZand88/CLI-Anything-WEB | 231 | — | ~4.2k | Automated safety check: Pass | MIT |
garfiec/Librechat-Mobile
Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.
newrelic/newrelic-dotnet-agent
A skill your agent uses when the user mentions a Dotty PR, dotty (package/dependency) updates, or asks to update the .NET agent compatibility docs / net-agent-compatibility-requirements after tested…
pydantic/pydantic-ai
Adds optional capabilities to Pydantic AI agents from pydantic-ai-harness, led by Code Mode, which runs many tool calls as one sandboxed Python script.
pydantic/pydantic-ai
Migrate Python applications from the Claude Agent SDK to Pydantic AI and, only when needed, Pydantic AI Harness.
ItamarZand88/CLI-Anything-WEB
Runs Phase 4 review/publish/verify for a cli-web- CLI: implementation review by 3 parallel agents, the tiered quality checklist (Tier 1 critical fail-fast, then comprehensive), pip install + smoke…
backnotprop/plannotator
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
axsaucedo/kaos
Fix every open Dependabot PR end-to-end on autopilot. An agent skill from axsaucedo/kaos.
axsaucedo/kaos
Execute a full KAOS release. An agent skill from axsaucedo/kaos.
axsaucedo/kaos
Plan and execute complex KAOS implementation work with staged context gathering, backend/UI synthesis, validation, PR/CI checks, and REPORT.md PR-comment output.
Works with
Categories
Comprehensively diagnose and fix a failing Dependabot PR. An agent skill from axsaucedo/kaos. Dependabot Fix is an agent skill from axsaucedo/kaos. Comprehensively diagnose and fix a failing Dependabot PR.
Dependabot Fix fits situations like: asked to run /dependabot-fix <pr-number; tasks that involve Dependency management; tasks that involve Subagents.
Run `npx skills add axsaucedo/kaos --skill dependabot-fix -a claude-code`. Or copy the skill folder (.claude/skills/dependabot-fix in axsaucedo/kaos) into .claude/skills/dependabot-fix in your project. Claude Code loads it when a task matches its description.
Run `npx skills add axsaucedo/kaos --skill dependabot-fix -a codex`. Or copy the skill folder (.claude/skills/dependabot-fix in axsaucedo/kaos) into .agents/skills/dependabot-fix in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add axsaucedo/kaos --skill dependabot-fix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-fix, .gemini/skills/dependabot-fix, .github/skills/dependabot-fix and .opencode/skills/dependabot-fix in your project.
Going by SKILL.md and its folder, Dependabot Fix needs the command-line tools its instructions call (gh, npm, make, python, git and go). Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: shell.
SKILL.md contains no URLs. Its commands use gh, npm, git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependabot Fix is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependabot Fix: Audit Deps (garfiec/Librechat-Mobile, 111 stars), Update Dotty Docs (newrelic/newrelic-dotnet-agent, 117 stars), Pydantic AI Harness (pydantic/pydantic-ai, 21k stars) and Migrating Claude Agent SDK To Pydantic AI (pydantic/pydantic-ai, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
axsaucedo (a GitHub user) maintains it in axsaucedo/kaos, which has 280 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.
Source: axsaucedo/kaos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.