Agent skill

Renovate Actions PR Review

by backnotprop in backnotprop/plannotator

Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

Apache-2.0Auto-check passedDevelopment

Install Renovate Actions PR Review

skills CLI
$ npx skills add backnotprop/plannotator --skill review-renovate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install backnotprop/plannotator review-renovate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/backnotprop/plannotator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-renovate .claude/skills/review-renovate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-renovate
GitHub stars
9.3k
Token cost
~640 tokens
SKILL.md length
293 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

  • Works in 6 steps: Fetch PR metadata and diff → Identify all action version changes → Verify pinned SHAs against upstream tags → …
  • Reviewing a Renovate PR that updates GitHub Actions in .github/workflows
  • SKILL.md covers Inputs and Steps
  • Calls gh

What it does

The agent fetches the PR with the gh CLI, confirms the author is the Renovate app and flags anything else straight away, then lists every changed action with its old and new version tag, pinned commit SHA and update type of patch, minor or major.

For each updated action it checks that both the old and the new SHA match the claimed tags by asking the GitHub API for the upstream tag reference. A mismatch stops the review as a supply chain integrity failure and the PR is not approved. It then reads the release notes in the PR body for removed inputs, new required inputs, changed defaults and major bumps, checks the affected workflow files and runtime requirements such as the Node.js version, and ends with a summary table and a clear safe to merge or do not merge verdict.

When your agent uses it

  • Reviewing a Renovate PR that updates GitHub Actions in .github/workflows
  • Verifying that pinned action SHAs match upstream release tags
  • Checking an action upgrade for breaking changes in the changelog

Example prompts

  • “Review the open Renovate PR for setup-bun and tell me whether it is safe to merge.”
  • “Check that the pinned SHAs in this Renovate pull request match the upstream tags.”
  • “Does this Renovate bump of our workflow actions break any inputs we use?”

Requirements

  • The gh CLI, signed in to GitHub
  • Network access to the GitHub API

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Fetch PR metadata and diff
  2. Identify all action version changes
  3. Verify pinned SHAs against upstream tags
  4. Review changelogs for breaking changes
  5. Check workflow compatibility
  6. Report findings

What it can do on your machine

Read from SKILL.md and the folder at commit 9f6132e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Renovate Actions PR Review loads about 640 tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 293 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~640

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from backnotprop/plannotator at commit 9f6132e, republished under its Apache-2.0 licence (© backnotprop). 293 words, ~640 tokens.

Download SKILL.mdSave it as .claude/skills/review-renovate/SKILL.md (or your agent's skills folder).
name
review-renovate
description
Review Renovate bot PRs that update GitHub Actions dependencies. Verifies supply chain integrity by checking pinned commit SHAs against upstream tagged releases, reviews changelogs for breaking changes, and confirms compatibility with existing workflow configurations. Use when a Renovate PR updates GitHub Actions in .github/workflows/.

Review Renovate GitHub Actions PRs

You are reviewing a Renovate bot PR that updates GitHub Actions dependencies. Your job is to verify supply chain integrity and ensure the upgrades won't break CI/CD workflows.

Inputs

You will be given a PR number or URL. Use gh CLI to fetch PR details and diff.

Steps

1. Fetch PR metadata and diff
gh pr view <PR> --json title,body,files,commits,author,headRefName
gh pr diff <PR>

Confirm the PR author is app/renovate. If not, flag this immediately — it may not be an automated dependency update.

2. Identify all action version changes

From the diff, extract each changed action:

  • Full action name (e.g., oven-sh/setup-bun)
  • Old version tag and pinned SHA
  • New version tag and pinned SHA
  • Update type (patch, minor, major)
3. Verify pinned SHAs against upstream tags

For every action being updated, verify both old and new SHAs match the claimed version tags:

gh api repos/{owner}/{repo}/git/ref/tags/{version} --jq '.object.sha'

Compare each result against the SHA in the workflow file. If any SHA does not match, stop and report a supply chain integrity failure. Do not approve the PR.

4. Review changelogs for breaking changes

From the PR body (Renovate includes release notes), check each updated action for:

  • Removed inputs or outputs that the workflows currently use
  • Changed default behavior for inputs the workflows rely on
  • New required inputs
  • Major version bumps (these almost always have breaking changes)
5. Check workflow compatibility

Read the affected workflow files and verify:

  • No removed or renamed inputs are being used
  • No changed defaults affect current behavior
  • The action's runtime requirements are still met (e.g., Node.js version compatibility)
6. Report findings

Present a summary table:

ActionOldNewTypeSHA verified
.........patch/minor/majoryes/NO

Then state:

  • Whether all SHAs are verified
  • Whether any breaking changes were found
  • Whether the workflows remain compatible
  • A clear safe to merge or do not merge recommendation

© backnotprop, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/review-renovate of backnotprop/plannotator.

Open the folder on GitHubat commit 9f6132e

Compare with similar skills

Renovate Actions PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Renovate Actions PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Renovate Actions PR Review this skillbacknotprop/plannotator9.3k—~640Automated safety check: PassApache-2.0
ReviewdogAgentSecOps/SecOpsAgentKit2201 repos~3kAutomated safety check: PassCustom licence
GitHub Copilot PR Finishergithub/gh-aw5.4k—~3.9kAutomated safety check: WarnMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Ghbubbuild/bub1.7k—~798Automated safety check: PassApache-2.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT

Similar skills

  • Reviewdog

    AgentSecOps/SecOpsAgentKit

    Automated code review and security linting integration for CI/CD pipelines using reviewdog.

    220 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.4k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check: warnings
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Gh

    bubbuild/bub

    GitHub CLI skill for interacting with GitHub via the gh command line tool.

    1.7k GitHub stars~798 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • CI

    aiblueprinthq/ai-blueprint

    Set up or normalize one project Verify command and matching GitHub Actions checks while preserving existing CI, with an optional local pre-push hook.

    463 GitHub stars~2.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from backnotprop/plannotator

All 13 skills in this repo
  • Plannotator Visual Explainer

    backnotprop/plannotator

    Builds self-contained HTML explainers for plans, pull requests and technical concepts in Plannotator's theme, then opens them in its annotation view.

    9.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Plannotator Release Preparation

    backnotprop/plannotator

    Drafts Plannotator release notes with full contributor credit, bumps versions in dependency order, builds, and starts the tag-driven release pipeline, in four reviewed phases.

    9.3k GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Plannotator Planning Analysis

    backnotprop/plannotator

    Mines a Plannotator archive of denied plans for feedback patterns and prompt improvements, then writes an HTML dashboard report, with a Claude Code fallback.

    9.3k GitHub stars~6.7k tokensUpdated today
    Auto-check passed
  • Plannotator Goal Setup

    backnotprop/plannotator

    Guides the agent from a vague objective to a written goal package under goals/, using a confirmed restatement, a browser interview, a fact sheet and a codebase pass.

    9.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Plannotator Reference

    backnotprop/plannotator

    Reference for picking the right Plannotator tool or command for plan review, code review, annotating files and URLs, archived plan decisions and Guided Reviews.

    9.3k GitHub stars~6.8k tokensUpdated today
    Auto-check: warnings

Questions about Renovate Actions PR Review

What does Renovate Actions PR Review do?

Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible. The agent fetches the PR with the gh CLI, confirms the author is the Renovate app and flags anything else straight away, then lists every changed action with its old and new version tag, pinned commit SHA and update type of patch, minor or major.

When should I use Renovate Actions PR Review?

Renovate Actions PR Review fits situations like: reviewing a Renovate PR that updates GitHub Actions in .github/workflows; verifying that pinned action SHAs match upstream release tags; checking an action upgrade for breaking changes in the changelog.

How do I install Renovate Actions PR Review in Claude Code?

Run `npx skills add backnotprop/plannotator --skill review-renovate -a claude-code`. Or copy the skill folder (.agents/skills/review-renovate in backnotprop/plannotator) into .claude/skills/review-renovate in your project. Claude Code loads it when a task matches its description.

How do I install Renovate Actions PR Review in Codex?

Run `npx skills add backnotprop/plannotator --skill review-renovate -a codex`. Or copy the skill folder (.agents/skills/review-renovate in backnotprop/plannotator) into .agents/skills/review-renovate in your project. Codex loads it when a task matches its description.

Can I use Renovate Actions PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add backnotprop/plannotator --skill review-renovate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-renovate, .gemini/skills/review-renovate, .github/skills/review-renovate and .opencode/skills/review-renovate in your project.

What does Renovate Actions PR Review need to run?

Going by SKILL.md and its folder, Renovate Actions PR Review needs the command-line tools its instructions call (gh). Our summary lists: The gh CLI, signed in to GitHub; Network access to the GitHub API.

Does Renovate Actions PR Review access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Renovate Actions PR Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Renovate Actions PR Review use?

Renovate Actions PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Renovate Actions PR Review use?

About 640 tokens (SKILL.md is roughly 2.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Renovate Actions PR Review?

Skills that share tags, products or a category with Renovate Actions PR Review: Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars), GitHub Copilot PR Finisher (github/gh-aw, 5.4k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and Gh (bubbuild/bub, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Renovate Actions PR Review?

backnotprop (a GitHub user) maintains it in backnotprop/plannotator, which has 9,334 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 11, 2026.

Source: backnotprop/plannotator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.