Add TTS Engine to Voicebox
jamiepine/voicebox
Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.
Fix every open Dependabot PR end-to-end on autopilot. An agent skill from axsaucedo/kaos.
$ npx skills add axsaucedo/kaos --skill dependabot-fix-all -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix-all --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dependabot-fix-all .claude/skills/dependabot-fix-all && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependabot-fix-all" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix-all into .claude/skills/dependabot-fix-all/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix-all", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix-allType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add axsaucedo/kaos --skill dependabot-fix-all -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix-all --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/dependabot-fix-all .agents/skills/dependabot-fix-all && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependabot-fix-all" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix-all into .agents/skills/dependabot-fix-all/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix-all", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add axsaucedo/kaos --skill dependabot-fix-all -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix-all --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/dependabot-fix-all .cursor/skills/dependabot-fix-all && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependabot-fix-all" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix-all into .cursor/skills/dependabot-fix-all/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix-all", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/axsaucedo/kaos.git --path .claude/skills/dependabot-fix-all--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add axsaucedo/kaos --skill dependabot-fix-all -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix-all --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/dependabot-fix-all .gemini/skills/dependabot-fix-all && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependabot-fix-all" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix-all into .gemini/skills/dependabot-fix-all/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix-all", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install axsaucedo/kaos dependabot-fix-allInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add axsaucedo/kaos --skill dependabot-fix-all -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/dependabot-fix-all .github/skills/dependabot-fix-all && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-fix-all" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix-all into .github/skills/dependabot-fix-all/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix-all", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add axsaucedo/kaos --skill dependabot-fix-all -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install axsaucedo/kaos dependabot-fix-all --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/axsaucedo/kaos.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/dependabot-fix-all .opencode/skills/dependabot-fix-all && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-fix-all" agent skill from https://github.com/axsaucedo/kaos/tree/main/.claude/skills/dependabot-fix-all into .opencode/skills/dependabot-fix-all/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-fix-all", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependabot-fix-allFix every open Dependabot PR end-to-end on autopilot. An agent skill from axsaucedo/kaos.
Dependabot Fix All is an agent skill from axsaucedo/kaos. Fix every open Dependabot PR end-to-end on autopilot. Use this skill when asked to run /dependabot-fix-all (no arguments). This skill acts as an orchestrator that discovers all open Dependabot PRs once, triages their CI state, risk-orders the ones that actually need work, then processes them one at a time by spawning an isolated child agent per PR that runs the dependabot-fix skill. It verifies each PR independently via gh, applies the merge policy, records state in a durable ledger, and is bounded so it always…
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. The repository describes itself as: 🚀 K8s Agent Orchestration System: Managing the KAOS in your large-scale distributed multi-agent systems. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7b5d212. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
shellFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitpython3makeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependabot Fix All loads about 4.5k tokens when it runs. Until then it costs about 144 tokens; SKILL.md has 2,303 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from axsaucedo/kaos at commit 7b5d212, republished under its Apache-2.0 licence (© axsaucedo). 2,303 words, ~4,485 tokens.
.claude/skills/dependabot-fix-all/SKILL.md (or your agent's skills folder).Orchestrate the dependabot-fix skill across every open Dependabot PR, fully autonomously. Invoked as
/dependabot-fix-all (no arguments).
This session is the orchestrator. It does not diagnose or edit PRs itself — it spawns one isolated child agent per PR (each child runs the heavyweight dependabot-fix skill in a fresh context), then independently verifies the result via gh and moves on. This keeps the orchestrator's context lean and avoids cross-PR contamination.
The child agent is whatever the host provides. This skill is deliberately agent-agnostic: it never assumes a particular CLI is installed. See Phase 1.3 — Spawn the child for how to pick a backend. A PR whose CI is already green never gets a child at all.
ask_user/interactive prompts anywhere in this path. Resolve every decision
autonomously. If something cannot be resolved, mark the PR blocked and continue.gh pr checkout). Never run children in
parallel. Clean tree + default branch between children.tail/grep on its log and treat gh
output as the ground truth for verification.dependabot-fix-all never spawns another dependabot-fix-all), no extra retry
loops, no cleverness beyond what is written here.Durable state lives in the SQLite todos ledger (resumable), not in conversation memory.
mkdir -p ./tmp && touch ./tmp/null
REPO=axsaucedo/kaosPreflight (abort early with a clear message if any fails):
gh auth status is OK.git rev-parse --abbrev-ref HEAD # expect main
git status --porcelain # expect emptymain and confirm clean before proceeding (do not discard user work
silently — if the tree is dirty with unrelated changes, mark the whole run blocked and report).Discover once and snapshot — this is the only discovery; never list PRs again during the loop:
gh pr list --repo $REPO --author app/dependabot \
--json number,title,labels,headRefName,files --limit 100 > ./tmp/dfa-prs.jsonRisk-order easy → hard (process low-risk first so the run banks wins before tackling fragile UI majors):
github_actions / docker, and any minor/patch-only bumpsgomod (operator) — may need make generate manifestsuv / pip (pydantic-ai-server, kaos-cli, operator/tests)npm in docs/ or rootnpm in kaos-ui/ — framework majors last (highest risk; may be left open for review)Infer ecosystem/scope from the PR title, headRefName, and files (e.g. /kaos-ui, /operator, github_actions).
Seed the ledger — one row per discovered PR, in processing order. Use a dfa-pr-<number> id convention so rows are
unambiguous:
-- one INSERT per PR (status pending). Record ecosystem + risk in the description for traceability.
INSERT INTO todos (id, title, description) VALUES
('dfa-pr-245', 'Fixing PR #245 (github_actions)', 'ecosystem=github_actions risk=low order=1');Print the ordered plan (PR number, ecosystem, risk) so the run is auditable, then proceed without pausing.
Iterate the snapshot in risk order. For each PR <n>:
gh pr view <n> --repo $REPO --json state,mergeStateStatus,labels,titlestate is MERGED or CLOSED → ledger done (note "already merged/closed"), continue.main before handing off (the previous child should have restored it; if not, git checkout main and clean up first).Mark the ledger row in_progress.
Most Dependabot PRs do not need fixing. Spawning a child for a PR whose CI is already green wastes 10–30 minutes and risks a child "fixing" something that was never broken. Triage first.
Always read check state as JSON. Plain gh pr checks <n> renders a cancelled run as fail in its human output, which makes a concurrency-cancelled or timed-out job look like a genuine failure. Use --json and read state literally:
gh pr checks <n> --repo $REPO --json name,state,link > ./tmp/pr-<n>-checks.json
python3 - "$PWD/tmp/pr-<n>-checks.json" <<'PY'
import json, sys
checks = json.load(open(sys.argv[1]))
buckets = {}
for c in checks:
buckets.setdefault(c["state"], []).append(c["name"])
for state, names in sorted(buckets.items()):
print(f"{state}: {len(names)} -> {', '.join(sorted(names))}")
PYClassify into exactly one of three triage outcomes:
SUCCESS/NEUTRAL/SKIPPED. No child. Skip straight to the merge policy (step 6).CANCELLED and zero FAILURE/TIMED_OUT/ACTION_REQUIRED. This is almost always a superseded push (cancel-in-progress) or a job that tipped over its timeout-minutes — not a dependency problem. No child. Re-run the workflow and re-triage once:gh pr checks <n> --repo $REPO --json name,state,link # grab a link to get the run id
gh run rerun <run-id> --failedFAILURE → treat as genuinely-failing below. Re-run at most once per PR; a second cancellation is blocked.FAILURE, TIMED_OUT, or ACTION_REQUIRED. This is the only case that spawns a child.If checks are still PENDING/IN_PROGRESS, wait for them (gh pr checks <n> --watch --interval 30 with a wall-clock cap of 30 min) before classifying. A cap breach is blocked.
Record the triage outcome in the ledger description — it is the audit trail for why a child did or did not run.
Only for genuinely-failing PRs. Run serially and wait. The child runs the dependabot-fix skill in its own fresh context.
Pick a backend from what the host actually offers — do not hardcode a vendor. In order of preference:
Task/Agent tool that spawns a fresh-context child). Preferred: no PATH dependency, no auth setup, works in sandboxed and cloud sessions where no CLI is installed. The child's final message comes back as a return value, so there is no log to parse.PATH. Detect, do not assume — e.g. command -v claude, command -v copilot, command -v codex. Invoke it in whatever non-interactive, all-tools-allowed, machine-readable mode that CLI provides, wrapped in timeout 1800, with output redirected to ./tmp/pr-<n>-child.log — never streamed into context.blocked with note no child-agent backend, and continue.Whichever backend is used, the child gets the same brief:
Use the
dependabot-fixskill to fix Dependabot PR<n>fully autonomously. Do not ask any questions; run on autopilot to completion and emit a finalRESULT:line.
Notes:
timeout 1800 (30 min) guards against a hung child; a timeout is treated as blocked.Extract only the child's final RESULT: line and its exit status.
RESULT: line out of it. Nothing else to do.grep '^RESULT:' ./tmp/pr-<n>-child.log | tail -1. Either way, never read the full log — it is large.If no RESULT: line is found or the child exited non-zero, treat the run as blocked and rely on the step 5 gh verification to classify the real PR state.
Never trust the child's prose; re-derive truth. Use the same JSON check reading as step 2 — the cancelled-vs-failed distinction matters just as much here:
gh pr checks <n> --repo $REPO --json name,state
gh pr view <n> --repo $REPO --json state,mergeStateStatus,labelsIn a cloud session, gh does not work at all — use the mcp__github__* tools. This is measured behaviour, not a precaution. In a Claude Code cloud session every repo-scoped gh call fails: GraphQL returns 403 This GraphQL query is not enabled for this session, and the REST path that error names (gh api repos/{owner}/{repo}/...) returns its own 403 GitHub access is not enabled for this session. gh auth status fails too, because GH_TOKEN is the literal placeholder proxy-injected and gh treats it as an invalid token. Supplying your own GH_TOKEN changes nothing. Only non-repo paths such as gh api user succeed.
Detect the environment once, at preflight, and pick a lane for the whole run:
gh api repos/axsaucedo/kaos --jq .full_name >/dev/null 2>&1 && echo "local: use gh" || echo "cloud: use mcp__github__* tools"| Operation | Local | Cloud session |
|---|---|---|
| Read PR / check state | gh pr view, gh pr checks --json | mcp__github__pull_request_read, mcp__github__get_check_run |
| Create PR | gh pr create | mcp__github__create_pull_request |
| Comment | gh pr comment | mcp__github__add_issue_comment |
| Merge | gh pr merge --merge | mcp__github__merge_pull_request |
| Re-run / dispatch a workflow | gh run rerun, gh workflow run | mcp__github__actions_run_trigger |
Cloud sessions have no tool that writes refs/tags/* and no branch- or tag-deletion tool. So a cloud run cannot create a tag, cannot delete the claude/ branches it creates, and must reach a release by dispatching create-tag.yaml followed by release.yaml at the resulting tag. Merged claude/ branches accumulate and are reaped outside the session.
Classify the outcome:
state=MERGED.dependabot.yml split, or a claude/ replacement branch) and a comment posted on the original; note the replacement PR number.A PR that never needed a child (triage green, or cancelled-only that re-ran clean) is classified by the same list — it simply reaches it via the merge policy rather than via a child. Note no-child-needed in the ledger so the summary shows how much work was avoided.
Merge only when all of these hold:
state=OPEN (not already merged/closed)SUCCESS/NEUTRAL/SKIPPED — no CANCELLED left unresolved, and the expected check suite actually ran (a PR with zero checks is not green, it is unverified)mergeStateStatus=CLEAN — reject BEHIND (needs a rebase first), UNSTABLE, DIRTY, BLOCKEDgh pr merge <n> --repo $REPO --mergeAlways a merge commit — never squash, never rebase. The child already attempts this in its own Step 9; the orchestrator only acts if the PR is verifiably green but still open. Never merge a kaos-ui framework major — leave it open for human review.
A fix commit must never be pushed onto dependabot/**. Dependabot force-pushes those branches on its own schedule and will silently discard the work, and some hosts reject the push outright — a cloud/sandboxed session can only push to branches it owns (typically a claude/-prefixed branch), and a branch carrying commits authored by someone else, or backing someone else's open PR, is rejected on both counts.
When the fix cannot live on the Dependabot branch, re-home it:
git checkout -b claude/deps-<ecosystem>-<short-desc> origin/mainLedger this as superseded with the replacement PR number in the note. This is the standard path in unattended cloud runs; locally, pushing to the Dependabot branch is still fine when the host allows it.
Update the ledger row to done (with a one-line outcome note: merged / left-open / superseded / blocked <reason>). Restore a clean state for the next child:
git checkout main && git reset --hard origin/main >/dev/null 2>./tmp/null
git status --porcelain # expect emptyMove to the next PR. Do not re-discover, do not retry a blocked PR, do not re-queue.
The loop is bounded by the Phase 0 snapshot; once every row is done, stop. There is no re-discovery and no retry, so
the run always terminates.
Print a concise summary table built from the ledger — not from child logs:
SELECT id, title, status, description FROM todos WHERE id LIKE 'dfa-pr-%' ORDER BY id;Render as: PR | ecosystem | outcome | note. Each child already posted its own REPORT comment on its PR — the
orchestrator does not duplicate those. Write the session summary to ./tmp/dfa-summary.md if useful; never commit
it.
Close with a one-paragraph wrap-up: how many merged, how many left open for review, how many superseded, how many blocked (and the single-line reason for each blocked PR).
/dependabot-fix A,B) — deferredDeliberately not supported. Dependabot already bundles related dependencies into single grouped PRs, so genuine
cross-PR coupling is rare; serial single-PR runs handle ordering safely on the shared working tree. Batching two PRs
into one child would require two gh pr checkouts, intertwined diagnosis, and ambiguous merge/REPORT semantics — more
complexity than value. The orchestrator therefore always runs one PR per child. Revisit only if a concrete, repeated
need emerges.
--json name,state — never the human-rendered output, which shows CANCELLED as fail. Only genuinely-failing PRs get a child.blocked if none.main between runs.timeout.RESULT: line and the exit status; use gh as the ground truth.gh is unusable — every repo-scoped call 403s on both GraphQL and REST, and a supplied GH_TOKEN does not lift it. Detect at preflight and use mcp__github__* for all PR, check and workflow operations. Locally, gh is fine.create-tag.yaml then release.yaml at the tag; leave claude/ branch cleanup to a local or scheduled reaper.tmp/ is gitignored — a report file written there needs git add -f to be committed.dependabot/** branch. Re-home onto a claude/-prefixed branch and supersede the original when the host disallows the push.state=OPEN + all checks SUCCESS/NEUTRAL/SKIPPED (and the suite actually ran) + mergeStateStatus=CLEAN; always --merge, never squash or rebase.ask_user../tmp/ (never /tmp/); the SQLite todos ledger is the durable, resumable state.dependabot-fix-all.© axsaucedo, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/dependabot-fix-all of axsaucedo/kaos.
Open the folder on GitHubat commit 7b5d212
Dependabot Fix All next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependabot Fix All this skillaxsaucedo/kaos | 280 | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Add TTS Engine to Voiceboxjamiepine/voicebox | 57k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Dep Updatestrufflesecurity/trufflehog | 28k | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | |
| Merge Dependabot PRsonyx-dot-app/onyx | 32k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 8 repos | ~1.2k | Automated safety check: Notes | Custom licence | |
| Update .NET OS Packagesdotnet/core | 22k | — | ~2.3k | Automated safety check: Pass | MIT |
jamiepine/voicebox
Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.
trufflesecurity/trufflehog
Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.
onyx-dot-app/onyx
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…
dotnet/core
Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
axsaucedo/kaos
Comprehensively diagnose and fix a failing Dependabot PR. An agent skill from axsaucedo/kaos.
axsaucedo/kaos
Execute a full KAOS release. An agent skill from axsaucedo/kaos.
axsaucedo/kaos
Plan and execute complex KAOS implementation work with staged context gathering, backend/UI synthesis, validation, PR/CI checks, and REPORT.md PR-comment output.
Categories
Fix every open Dependabot PR end-to-end on autopilot. An agent skill from axsaucedo/kaos. Dependabot Fix All is an agent skill from axsaucedo/kaos. Fix every open Dependabot PR end-to-end on autopilot.
Dependabot Fix All fits situations like: asked to run /dependabot-fix-all (no arguments); tasks that involve Dependency management.
Run `npx skills add axsaucedo/kaos --skill dependabot-fix-all -a claude-code`. Or copy the skill folder (.claude/skills/dependabot-fix-all in axsaucedo/kaos) into .claude/skills/dependabot-fix-all in your project. Claude Code loads it when a task matches its description.
Run `npx skills add axsaucedo/kaos --skill dependabot-fix-all -a codex`. Or copy the skill folder (.claude/skills/dependabot-fix-all in axsaucedo/kaos) into .agents/skills/dependabot-fix-all in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add axsaucedo/kaos --skill dependabot-fix-all -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-fix-all, .gemini/skills/dependabot-fix-all, .github/skills/dependabot-fix-all and .opencode/skills/dependabot-fix-all in your project.
Going by SKILL.md and its folder, Dependabot Fix All needs the command-line tools its instructions call (gh, git, python3 and make) and credentials named GH_TOKEN. Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: shell.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dependabot Fix All is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependabot Fix All: Add TTS Engine to Voicebox (jamiepine/voicebox, 57k stars), Dep Updates (trufflesecurity/trufflehog, 28k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Senior Architect Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
axsaucedo (a GitHub user) maintains it in axsaucedo/kaos, which has 280 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.
Source: axsaucedo/kaos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.