Agent skill

Dependabot Fix

by axsaucedo in axsaucedo/kaos

Comprehensively diagnose and fix a failing Dependabot PR. An agent skill from axsaucedo/kaos.

Apache-2.0Auto-check passedDevelopment

Install Dependabot Fix

skills CLI
$ npx skills add axsaucedo/kaos --skill dependabot-fix -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install axsaucedo/kaos dependabot-fix --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dependabot-fix .claude/skills/dependabot-fix && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot-fix
GitHub stars
280
Token cost
~4.2k tokens
SKILL.md length
2,041 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Comprehensively diagnose and fix a failing Dependabot PR. An agent skill from axsaucedo/kaos.

  • Works in 12 steps: PR context → High-level error survey → Instructions subagent → …
  • Asked to run /dependabot-fix <pr-number
  • SKILL.md covers Phase A — Context, Phase B — Context ingestion…, Phase C — Deep root-cause… and Phase D — Fix design, plus 3 more sections
  • Calls gh, npm and make

What it does

Dependabot Fix is an agent skill from axsaucedo/kaos. Comprehensively diagnose and fix a failing Dependabot PR. Use this skill when asked to run /dependabot-fix <pr-number. The user provides the PR number in their prompt. The skill loads PR context, surveys errors at a high level, ingests relevant repo instructions / docs / source via subagents, performs a deep root-cause diagnosis, designs a risk-tiered fix with a manual testing strategy, commits the fix directly to the Dependabot PR branch, posts a REPORT.md as a comment on it (never commits it), and evaluates…

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Subagents and QA and bug reports. It works with Pydantic AI. The repository describes itself as: 🚀 K8s Agent Orchestration System: Managing the KAOS in your large-scale distributed multi-agent systems. The licence is Apache-2.0.

When your agent uses it

  • Asked to run /dependabot-fix <pr-number
  • Tasks that involve Dependency management
  • Tasks that involve Subagents

Example prompts

  • “/dependabot-fix”

Requirements

  • Python 3
  • Docker
  • Pre-approved tools (allowed-tools): shell

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. PR context
  2. High-level error survey
  3. Instructions subagent
  4. Docs subagent
  5. Codebase subagent
  6. Diagnose
  7. 5 · Scope triage — is this a fix, or a Dependabot config problem?
  8. Comprehensive plan
  9. Manual testing strategy (tiered)
  10. Ship directly on the Dependabot PR
  11. 5 · kaos-ui review gate (framework majors only)
  12. REPORT.md as PR comment — never commit

What it can do on your machine

Read from SKILL.md and the folder at commit 7b5d212. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • shell

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • make
    • python
    • git
    • go
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, npm, git and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot Fix loads about 4.2k tokens when it runs. Until then it costs about 146 tokens; SKILL.md has 2,041 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~146
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from axsaucedo/kaos at commit 7b5d212, republished under its Apache-2.0 licence (© axsaucedo). 2,041 words, ~4,234 tokens.

Download SKILL.mdSave it as .claude/skills/dependabot-fix/SKILL.md (or your agent's skills folder).
name
dependabot-fix
description
Comprehensively diagnose and fix a failing Dependabot PR. Use this skill when asked to run /dependabot-fix <pr-number>. The user provides the PR number in their prompt. The skill loads PR context, surveys errors at a high level, ingests relevant repo instructions / docs / source via subagents, performs a deep root-cause diagnosis, designs a risk-tiered fix with a manual testing strategy, commits the fix directly to the Dependabot PR branch, posts a REPORT.md as a comment on it (never commits it), and evaluates whether the skill itself needs updating afterwards.
allowed-tools
shell

Dependabot Fix

Systematically fix a failing Dependabot PR. The user provides a PR number (e.g., /dependabot-fix 142).

This skill spans five phases (A–E). Do not start editing code until Phase D is complete. Do not dive into logs until Phase B is complete.

Set up scratch space once at the start:

bash
mkdir -p ./tmp && touch ./tmp/null
PR_NUM=<from user prompt>
REPO=axsaucedo/kaos

Phase A — Context

Step 1 · PR context

Fetch metadata and produce a one-paragraph written summary of the PR (ecosystem, directory, grouping, size, whether it is a security update, which files it touches). Do not open source files yet.

bash
gh pr view $PR_NUM --repo $REPO --json title,body,headRefName,labels,files,mergeable,createdAt
gh pr diff $PR_NUM --repo $REPO | head -200

Identify:

  • Ecosystem: github_actions | gomod | uv / pip | npm | docker
  • Directory scope (/, operator/, pydantic-ai-server/, kaos-cli/, kaos-ui/, operator/tests/, mcp-servers/*, docs/)
  • Grouping: single-dep vs grouped (all, all-security)
  • Size: list number of files and approximate LOC changed
Step 2 · High-level error survey

List failing checks and capture the first and last error line from each failing job log. Do not investigate their meaning yet — just enumerate symptoms.

bash
gh pr checks $PR_NUM --repo $REPO

# For each failing check, grab job ID from the URL and pull logs
gh run view --job <JOB_ID> --repo $REPO --log 2>./tmp/null \
  | grep -iE "error|exit code|##\[error\]|FAILED|assert|timed ?out" \
  | head -20 > ./tmp/pr-${PR_NUM}-symptoms.txt

Output should be a bullet list such as:

  • go-tests/unit-tests: controller-tools@v0.20.1 requires go >= 1.25.0
  • kaos-ui-tests/unit: TypeError: Cannot read properties of undefined (reading 'forEach') in dashboard.test.ts
  • python-tests/pydantic-ai-server: AssertionError: expected 2 tool calls, got 3

Phase B — Context ingestion via subagents

Spawn three parallel explore subagents to load repo knowledge scoped to the touched ecosystems. Do not read any of this yourself beforehand — delegate.

Step 3 · Instructions subagent

Ask it to read .github/instructions/*.instructions.md files relevant to the PR's touched paths and summarize conventions, test commands, and gotchas.

Mapping guide (pass relevant ones to the subagent):

  • operator/** or gomod bumps → operator.instructions.md, e2e.instructions.md
  • pydantic-ai-server/**, kaos-cli/**, uv / pip bumps → python.instructions.md
  • kaos-ui/** or npm bumps in kaos-ui/ → kaos-ui.instructions.md, kaos-ui-components.instructions.md, kaos-ui-testing.instructions.md, kaos-ui-kubernetes-types.instructions.md
  • docs/** or npm bumps in docs/ → docs.instructions.md
  • .github/workflows/** (github_actions PRs) → release/CI-relevant instructions from above, plus .github/copilot-instructions.md
Step 4 · Docs subagent

Ask it to read matching docs/ pages for the changed modules: module overview, testing notes, architecture diagrams. Return a briefing no longer than ~40 lines covering what the module does, its public surface, and how it is tested.

Step 5 · Codebase subagent

Ask it to produce a targeted map:

  • Primary source directories and entry points for the touched area
  • Build and test commands (e.g. make test-unit, npm run test:unit, python -m pytest …)
  • Integration/E2E entry points (operator/tests/e2e, kaos-ui/tests/**)
  • Any Makefile targets that generate code (make generate manifests, make helm)
  • Docker images built from this code (for local reproduction)

The three subagent briefings together form the working context for Phase C.


Phase C — Deep root-cause diagnosis

Step 6 · Diagnose

Now — and only now — dive into the failing-job logs with full context from Phase B. For each failing check, trace the first meaningful error back to:

  1. A direct regression from the bumped dep (removed symbol, signature change, behaviour change, stricter validation)
  2. A transitive toolchain issue (e.g. @latest pulling a newer Go/Node/Python; post-install script requiring newer runtime)
  3. Pre-existing test fragility exposed by a harmless dep bump
  4. Infra flake (post-job cancellation after tests passed, timeouts, registry rate-limits)

For a grouped PR, diagnose each failing check separately — failures may have independent causes. Record findings in ./tmp/pr-${PR_NUM}-diagnosis.md.


Phase D — Fix design

Step 6.5 · Scope triage — is this a fix, or a Dependabot config problem?

Before planning a fix, check whether the PR is in-scope for fixing at all. A grouped Dependabot PR that bundles framework-migration majors cannot be fixed in a single pass; the right move is to reconfigure .github/dependabot.yml so the majors come through individually.

Scope-reject triggers (any one is sufficient):

  • A single group PR contains ≥ 2 major bumps on framework-tier packages
  • A major bump on: react, react-dom, react-router-dom, vite, vitest, @tanstack/react-query, tailwindcss, typescript, eslint, zod, zustand (npm); controller-runtime, k8s.io/*, pydantic, pydantic-ai, litellm (other ecosystems) when bundled with unrelated updates
  • The PR touches > ~40 packages and the majority are routine but a minority are migrations

When triggered, do not attempt a fix and do not close the PR yourself — leave it open for the host to close. Instead:

  1. Update .github/dependabot.yml to split the offending group (typically add update-types: ["minor", "patch"] to the all group so majors get individual PRs).
  2. Open that config change as a separate small PR (leave it for the host to review/merge).
  3. Verbalise the scope-reject decision as a comment on the original Dependabot PR(s): explain why it cannot be fixed in one pass, link the config PR, and recommend the host close it once smaller PRs replace it next cycle. Leave the PR open — do not pause for a decision, do not close it.
  4. Skip Phase E's "commit on Dependabot branch" flow — there is no fix. The REPORT.md content can be folded into that comment.

Security-update groups (all-security) are usually left bundled because security majors are rare and time-sensitive — only split them if a concrete blocker (e.g. a framework major) forces it.

Step 7 · Comprehensive plan

Write a plan covering the following; scale depth to risk:

SectionAlwaysIf risk ≥ medium
Root cause✅✅
Files expected to change✅✅
Fix approach (and alternatives considered)✅✅
Risk rating (low/medium/high)✅✅
Reproduction steps✅✅ (must be executable)
Manual testing strategy✅✅ expanded
Rollback plan✅
Blast radius (API / CRD / wire format / user-facing output)✅

Risk ≥ medium if any of:

  • bump touches public API of an exported library (gomod, kaos-cli, pydantic-ai-server)
  • changes a Kubernetes CRD generated surface
  • changes an HTTP/JSON-RPC wire format
  • changes a runtime image that ships in a release
Step 8 · Manual testing strategy (tiered)

Tier the effort by Step 7's risk rating:

  • Low (isolated) — apply fix, run the narrowest relevant suite (e.g. one pytest file, one vitest spec, go test ./pkg/...). No reproduction step needed.
  • Medium (cross-module or cross-ecosystem) — first reproduce the failure on main locally to prove the regression is real (not a harness artefact). Then apply the fix, retest, and confirm the reproduction no longer fires.
  • High (runtime / wire) — reproduce against a locally-built Docker image for the affected component (see ecosystem appendix). If it touches operator/agent behaviour, bring up a KIND cluster per .github/instructions/e2e.instructions.md and run 1–3 E2E tests locally before pushing.

Keep all scratch output under ./tmp/. Use ./tmp/null as the sink when suppressing output:

bash
python -m pytest tests/test_x.py -v 2>./tmp/null

Phase E — Finalise

Step 9 · Ship directly on the Dependabot PR

Keep it simple: commit fixes on the existing Dependabot PR branch. No replacement PR, no cherry-picking.

bash
gh pr checkout $PR_NUM --repo $REPO

# ...make edits...
git add -A
git commit -m "ci(<scope>): <one-line summary>

Root cause: <one sentence>
Fix: <one sentence>
Testing: <how verified>

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>"

git push

Monitor CI; rerun known flakes once before investigating:

bash
gh pr checks $PR_NUM --repo $REPO
gh run rerun <run-id> --failed --repo $REPO  # only for known flakes

Merge when green — but for kaos-ui framework major bumps, leave the PR open for human review instead of merging (see Step 9.5):

bash
gh pr merge $PR_NUM --repo $REPO --merge

Caveats:

  • Do not use @dependabot rebase after pushing fix commits — it will discard them. Let the PR merge as-is.
  • If Step 9.5 says leave-open (kaos-ui framework major), do not merge. Post the report and leave the PR open; the host merges after their own visual review.
Step 9.5 · kaos-ui review gate (framework majors only)

The visual/E2E suite for kaos-ui is stringent, so minor and patch bumps — including framework packages — can be merged directly once CI is green. No human gate is needed for them.

For a kaos-ui major bump on a framework package (react, react-dom, react-router-dom, vite, vitest, @tanstack/react-query, tailwindcss, typescript, eslint, zod, zustand), CI alone is insufficient evidence — major-version visual regressions can slip past Playwright assertions. Do not merge. Instead:

  1. Push the fix commits so CI is green.
  2. Post REPORT.md as a PR comment (Step 10), explicitly noting it is a framework major held for human visual review.
  3. Leave the PR open. The host reviews and merges manually.
Bump type (kaos-ui)Action
Minor / patch (any package)Merge directly when green (Step 9 gh pr merge)
Major on framework packageDo NOT merge. Post report, leave open for human review

Do not use the ask_user tool or any in-chat prompt as a merge gate — it does not reliably block execution. The gate is simply "leave the major PR open"; the human review happens on the PR itself.

Show full SKILL.md (764 more words)Show less
Step 10 · REPORT.md as PR comment — never commit

Write REPORT.md at the repo root (gitignored) covering: PR context, symptoms, root cause, fix plan + testing evidence, CI/merge outcome. Then:

bash
gh pr comment $PR_NUM --repo $REPO --body-file REPORT.md
Step 10.6 · Emit a machine-readable result line

As the final line of output, print exactly one status line so an orchestrator (e.g. /dependabot-fix-all) can classify the outcome without parsing prose:

RESULT: <merged|left-open|superseded|blocked> pr=<PR_NUM> reason="<short phrase>"
  • merged — fix pushed, CI green, PR merged.
  • left-open — CI green but intentionally not merged (kaos-ui framework major held for human review).
  • superseded — scope-rejected; dependabot.yml split PR opened + comment posted, original left open for host to close.
  • blocked — could not be fixed this run (record why in reason).

This skill runs fully non-interactive / autopilot: never call ask_user or ask questions in any mode — resolve every decision autonomously per the policies above and emit the RESULT line.

Step 11 · Evaluate skill currency

After the PR merges, ask whether this run surfaced a major, repeatable learning that future runs would miss without it. Examples:

  • A new failure pattern not in the appendix (new ecosystem, new toolchain)
  • A repo-level invariant that changed (e.g. Go toolchain bump, new CI job name)
  • A workflow step that proved redundant in practice

If yes — and only if the learning is non-obvious — open a small follow-up PR updating this SKILL.md. Resist adding minor details that a competent operator would infer; bloat degrades the skill.


Invariants

  • Work directly on the Dependabot PR branch; do not open replacement PRs
  • Never @dependabot rebase after pushing fix commits (it discards them)
  • Prefer version pinning over version rollback for @latest toolchain drift
  • Scratch files under ./tmp/ (never /tmp/); suppress output with 2>./tmp/null
  • Conventional-commit style with Copilot co-author trailer
  • REPORT.md is posted as a PR comment, never committed
  • Runs fully non-interactive (autopilot); the final output line is the RESULT: status line (Step 10.6)

Appendix · Ecosystem cheat-sheet

Common failure modes observed on bundled Dependabot PRs in this repo. Treat these as hypotheses, not diagnoses — Phase C must still verify.

github_actions (e.g. PR #142)
  • @latest tool installs in workflows or Makefiles silently bumping to a version that requires a newer Go/Node toolchain
    • Fix: pin to the last version compatible with go.mod / .nvmrc (e.g. controller-tools@v0.19.0, setup-envtest@release-0.22, helmify@v0.4.18)
  • actions/upload-artifact@v4 name-collision within matrix jobs → add a matrix suffix to the artifact name
  • actions/setup-node major bump dropping support for older Node versions → check .nvmrc alignment
  • Known flakes to rerun: e2e/E2E (example-autonomous) — post-job cancellations and kaos agent a2a send exit-1 flakes
gomod (e.g. PR #141)
  • controller-runtime bumps often require regenerating CRDs and RBAC: cd operator && make generate manifests
  • k8s.io/* bumps may require bumping setup-envtest branch (release-0.X) to match
  • API rename/removal from sigs.k8s.io/* — use go doc <pkg>.<symbol> in the new version to find the replacement
  • Local reproduction: cd operator && make test-unit
uv / pip (e.g. PR #125, #145)
  • pytest majors sometimes deprecate fixtures; look for PytestDeprecationWarning
  • litellm, pydantic-ai minors can change tool-calling response shape; check DEBUG_MOCK_RESPONSES mocks
  • cryptography majors drop old cipher suites — affects anything using custom TLS
  • Local reproduction: cd <pkg> && source .venv/bin/activate && python -m pytest tests/ -v
  • For E2E deps (operator/tests/): cd operator/tests && source .venv/bin/activate && make e2e-test (requires KIND)
npm in kaos-ui/ (e.g. PR #143, #146)
  • Scope-reject first (see Step 6.5). React / React Router / Vite / Vitest / Zod / Zustand / Tailwind majors bundled with routine bumps = reconfigure dependabot.yml and leave the PR open with a comment for the host to close, don't fix.
  • Risk is automatically high for any kaos-ui PR with a major bump on a framework package — visual regressions do not show up in CI.
  • Local reproduction: cd kaos-ui && npm ci && npm run build && npm run lint && npm run test:unit
  • Playwright required, not optional: npm run test:e2e against a running dev server + kaos ui --no-browser proxy + KIND cluster (per kaos-ui-testing.instructions.md). CI's E2E alone is not sufficient evidence.
  • Merge policy (Step 9.5): kaos-ui minor/patch bumps merge directly when CI is green; framework major bumps are left open for human review, never auto-merged. No ask_user gate.
  • Common breakage: vitest majors change config shape and matcher behaviour; react-router majors change route definitions; @tanstack/react-query majors change useQuery signature; ESLint 9 flat-config drift when eslint-* plugins bump.
  • Lockfile desync is the dominant failure mode on routine grouped PRs — every UI check fails at npm ci with Missing: <pkg> from lock file. Fix: delete both node_modules and package-lock.json, then npm install. Deleting only node_modules can trigger a secondary Cannot find native binding error from rolldown/vitest 4.x optional deps.
npm in docs/ or root
  • VitePress / mermaid plugin API drift — verify npm run build under docs/
  • Root-level tooling bumps rarely affect runtime; usually a simple rebuild suffices
docker
  • Base-image bumps (e.g. golang:1.25-alpine) must match go.mod toolchain line
  • Multi-arch buildx bumps require local docker buildx create --use

© axsaucedo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dependabot-fix of axsaucedo/kaos.

Open the folder on GitHubat commit 7b5d212

Compare with similar skills

Dependabot Fix next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot Fix compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot Fix this skillaxsaucedo/kaos280—~4.2kAutomated safety check: PassApache-2.0
Audit Depsgarfiec/Librechat-Mobile111—~2.4kAutomated safety check: NotesMIT
Update Dotty Docsnewrelic/newrelic-dotnet-agent117—~2.1kAutomated safety check: PassApache-2.0
Pydantic AI Harnesspydantic/pydantic-ai21k—~4.9kAutomated safety check: PassMIT
Migrating Claude Agent SDK To Pydantic AIpydantic/pydantic-ai21k—~1.6kAutomated safety check: PassMIT
StandardsItamarZand88/CLI-Anything-WEB231—~4.2kAutomated safety check: PassMIT

Similar skills

  • Audit Deps

    garfiec/Librechat-Mobile

    Audit open dependabot PRs in this repo. An agent skill from garfiec/Librechat-Mobile.

    111 GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check: notes
  • Update Dotty Docs

    newrelic/newrelic-dotnet-agent

    A skill your agent uses when the user mentions a Dotty PR, dotty (package/dependency) updates, or asks to update the .NET agent compatibility docs / net-agent-compatibility-requirements after tested…

    117 GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Pydantic AI Harness

    pydantic/pydantic-ai

    Official

    Adds optional capabilities to Pydantic AI agents from pydantic-ai-harness, led by Code Mode, which runs many tool calls as one sandboxed Python script.

    21k GitHub stars~4.9k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Official

    Migrate Python applications from the Claude Agent SDK to Pydantic AI and, only when needed, Pydantic AI Harness.

    21k GitHub stars~1.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Standards

    ItamarZand88/CLI-Anything-WEB

    Runs Phase 4 review/publish/verify for a cli-web- CLI: implementation review by 3 parallel agents, the tiered quality checklist (Tier 1 critical fail-fast, then comprehensive), pip install + smoke…

    231 GitHub stars~4.2k tokensUpdated 9 days ago
    Testing & QAAuto-check passed
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed

More from axsaucedo/kaos

  • Dependabot Fix All

    axsaucedo/kaos

    Fix every open Dependabot PR end-to-end on autopilot. An agent skill from axsaucedo/kaos.

    280 GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Release Kaos

    axsaucedo/kaos

    Execute a full KAOS release. An agent skill from axsaucedo/kaos.

    280 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Plan and execute complex KAOS implementation work with staged context gathering, backend/UI synthesis, validation, PR/CI checks, and REPORT.md PR-comment output.

    280 GitHub stars~2.4k tokensUpdated today
    Auto-check passed

Works with

Questions about Dependabot Fix

What does Dependabot Fix do?

Comprehensively diagnose and fix a failing Dependabot PR. An agent skill from axsaucedo/kaos. Dependabot Fix is an agent skill from axsaucedo/kaos. Comprehensively diagnose and fix a failing Dependabot PR.

When should I use Dependabot Fix?

Dependabot Fix fits situations like: asked to run /dependabot-fix <pr-number; tasks that involve Dependency management; tasks that involve Subagents.

How do I install Dependabot Fix in Claude Code?

Run `npx skills add axsaucedo/kaos --skill dependabot-fix -a claude-code`. Or copy the skill folder (.claude/skills/dependabot-fix in axsaucedo/kaos) into .claude/skills/dependabot-fix in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot Fix in Codex?

Run `npx skills add axsaucedo/kaos --skill dependabot-fix -a codex`. Or copy the skill folder (.claude/skills/dependabot-fix in axsaucedo/kaos) into .agents/skills/dependabot-fix in your project. Codex loads it when a task matches its description.

Can I use Dependabot Fix in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add axsaucedo/kaos --skill dependabot-fix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-fix, .gemini/skills/dependabot-fix, .github/skills/dependabot-fix and .opencode/skills/dependabot-fix in your project.

What does Dependabot Fix need to run?

Going by SKILL.md and its folder, Dependabot Fix needs the command-line tools its instructions call (gh, npm, make, python, git and go). Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: shell.

Does Dependabot Fix access the network?

SKILL.md contains no URLs. Its commands use gh, npm, git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependabot Fix safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependabot Fix use?

Dependabot Fix is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependabot Fix use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot Fix?

Skills that share tags, products or a category with Dependabot Fix: Audit Deps (garfiec/Librechat-Mobile, 111 stars), Update Dotty Docs (newrelic/newrelic-dotnet-agent, 117 stars), Pydantic AI Harness (pydantic/pydantic-ai, 21k stars) and Migrating Claude Agent SDK To Pydantic AI (pydantic/pydantic-ai, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot Fix?

axsaucedo (a GitHub user) maintains it in axsaucedo/kaos, which has 280 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: axsaucedo/kaos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.