Agent skill

Dependabot Review

by davila7 in davila7/claude-code-templates

Review and manage Dependabot PRs. An agent skill from davila7/claude-code-templates.

MITAuto-check passedDevelopment

Install Dependabot Review

skills CLI
$ npx skills add davila7/claude-code-templates --skill dependabot-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davila7/claude-code-templates dependabot-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-tool/components/skills/workflow-automation/dependabot-review .claude/skills/dependabot-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot-review
GitHub stars
33k
Token cost
~915 tokens
SKILL.md length
403 words
Files
1
Skills in repo
479
Repo updated
First seen
Licence
MIT

At a glance

Review and manage Dependabot PRs. An agent skill from davila7/claude-code-templates.

  • Works in 5 steps: Discovery → Classification → CI Check → …
  • The user says review dependabot
  • SKILL.md covers Workflow, Guardrails and Common Patterns
  • Calls gh and jest

What it does

Dependabot Review is an agent skill from davila7/claude-code-templates. Review and manage Dependabot PRs. Categorizes by risk, checks CI status, auto-merges safe updates, and reports issues. Use when the user says "review dependabot", "merge dependabot", "dependabot PRs", or "update dependencies".

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. The repository describes itself as: CLI tool for configuring and monitoring Claude Code. The licence is MIT.

When your agent uses it

  • The user says review dependabot
  • Merge dependabot
  • Update dependencies

Example prompts

  • “review dependabot”
  • “merge dependabot”
  • “dependabot PRs”
  • “/dependabot-review”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Discovery
  2. Classification
  3. CI Check
  4. Merge Safe PRs
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit c0ca7da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • jest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot Review loads about 915 tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 403 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~915

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davila7/claude-code-templates at commit c0ca7da, republished under its MIT licence (© davila7). 403 words, ~915 tokens.

Download SKILL.mdSave it as .claude/skills/dependabot-review/SKILL.md (or your agent's skills folder).
name
dependabot-review
description
Review and manage Dependabot PRs. Categorizes by risk, checks CI status, auto-merges safe updates, and reports issues. Use when the user says "review dependabot", "merge dependabot", "dependabot PRs", or "update dependencies".
license
MIT
metadata.author
claude-code-templates
metadata.version
1.0.0

Dependabot PR Review

You are a dependency management specialist. Your job is to review all open Dependabot PRs, assess risk, and take action.

Workflow

Step 1: Discovery

List all open Dependabot PRs:

bash
gh pr list --author "dependabot[bot]" --state open --json number,title,labels,createdAt,headRefName --limit 50

If no PRs are found, inform the user and stop.

Step 2: Classification

For each PR, classify it into a risk tier based on the branch name and title:

TierCriteriaAction
SafeGitHub Actions updates (dependabot/github_actions/), patch bumps (1.2.3 -> 1.2.4)Auto-merge
Low RiskMinor bumps (1.2.0 -> 1.3.0) for well-known librariesAuto-merge after CI check
Review RequiredMajor bumps (1.x -> 2.x), unknown libraries, security-tagged PRsReport to user

To determine bump type, parse the PR title. Dependabot titles follow patterns like:

  • Bump X from 1.2.3 to 1.2.4 (patch)
  • Bump X from 1.2.0 to 1.3.0 (minor)
  • Bump X from 1.0.0 to 2.0.0 (major)
Step 3: CI Check

For each PR you plan to merge, check CI status:

bash
gh pr checks <number> --json name,state,bucket
  • If all checks pass: proceed with merge
  • If checks are pending: wait up to 2 minutes (poll every 30s). If still pending, skip and report as "CI pending"
  • If any check fails: skip and report to user
Step 4: Merge Safe PRs

For PRs classified as Safe or Low Risk with passing CI:

bash
gh pr merge <number> --merge --delete-branch

Important rules:

  • Never force-merge
  • Never merge PRs with failing CI
  • Never merge major version bumps without user confirmation
  • Merge one at a time to avoid conflicts
Step 5: Report

After processing, present a summary table to the user:

## Dependabot Review Summary

### Merged (X PRs)
| PR | Update | Type |
|----|--------|------|
| #123 | actions/checkout v4 -> v6 | GitHub Actions |

### Needs Review (X PRs)
| PR | Update | Risk | Reason |
|----|--------|------|--------|
| #456 | jest 29 -> 30 | Major | Breaking changes possible |

### Skipped (X PRs)
| PR | Update | Reason |
|----|--------|--------|
| #789 | chalk 5.5 -> 5.6 | CI failing |
Show full SKILL.md (164 more words)Show less

Guardrails

  • Always check CI before merging — never merge red PRs
  • Major bumps need user approval — present the changelog and ask
  • Rate limit merges — if there are more than 10 PRs, process in batches of 5 and ask the user before continuing
  • Conflict handling — if a merge fails due to conflicts, skip it and report. Do not attempt to resolve conflicts
  • Security PRs — if a PR has a security label or mentions a CVE, always flag it to the user even if it's a patch, so they are aware
  • Rebase cascades — after merging several PRs, remaining ones may need rebase. Run gh pr list --author "dependabot[bot]" again after each batch to see updated status

Common Patterns

Quick safe merge (GitHub Actions only): The user says "merge the actions PRs" — filter to dependabot/github_actions/ branches only.

Full review: The user says "review dependabot" — run the complete workflow above.

Dry run: The user says "check dependabot" or "show dependabot PRs" — run Steps 1-2 only, report classification without merging.

© davila7, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in cli-tool/components/skills/workflow-automation/dependabot-review of davila7/claude-code-templates.

Open the folder on GitHubat commit c0ca7da

Compare with similar skills

Dependabot Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot Review this skilldavila7/claude-code-templates33k—~915Automated safety check: PassMIT
Add TTS Engine to Voiceboxjamiepine/voicebox57k—~1.3kAutomated safety check: PassMIT
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Merge Dependabot PRsonyx-dot-app/onyx32k1 repos~2.2kAutomated safety check: PassMIT
Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit2608 repos~1.2kAutomated safety check: NotesCustom licence
Update .NET OS Packagesdotnet/core22k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Add TTS Engine to Voicebox

    jamiepine/voicebox

    Walks through adding a new text-to-speech engine to Voicebox end to end: dependency audit, backend, frontend wiring, PyInstaller bundling and frozen-build testing.

    57k GitHub stars~1.3k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Merge Dependabot PRs

    onyx-dot-app/onyx

    Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…

    32k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Senior Architect Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…

    260 GitHub starsUsed in 8 repos~1.2k tokens
    DevelopmentAuto-check: notes
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed

More from davila7/claude-code-templates

All 479 skills in this repo
  • Perplexity Web Search

    davila7/claude-code-templates

    Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.

    33k GitHub starsUsed in 11 repos~3.5k tokens
    Auto-check: notes
  • Neuropixels Data Analysis

    davila7/claude-code-templates

    Analyzes Neuropixels recordings from SpikeGLX or Open Ephys through preprocessing, drift correction, Kilosort4 spike sorting, quality metrics and curation.

    33k GitHub starsUsed in 9 repos~2.8k tokens
    Auto-check passed
  • Scientific Venue Templates

    davila7/claude-code-templates

    Supplies LaTeX templates and formatting rules for journals, conferences, posters, and grant proposals, then can check a draft against them.

    33k GitHub starsUsed in 9 repos~5.1k tokens
    Auto-check: notes
  • Brand Voice Content Creator

    davila7/claude-code-templates

    Analyzes a brand's existing writing to lock in a consistent voice, then builds SEO blog posts and platform-specific social content around it.

    33k GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • CAPA Officer

    davila7/claude-code-templates

    Guides corrective and preventive action (CAPA) work in a quality management system, from initiation and root cause analysis through effectiveness verification.

    33k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Categories

Questions about Dependabot Review

What does Dependabot Review do?

Review and manage Dependabot PRs. An agent skill from davila7/claude-code-templates. Dependabot Review is an agent skill from davila7/claude-code-templates. Review and manage Dependabot PRs.

When should I use Dependabot Review?

Dependabot Review fits situations like: the user says review dependabot; merge dependabot; update dependencies.

How do I install Dependabot Review in Claude Code?

Run `npx skills add davila7/claude-code-templates --skill dependabot-review -a claude-code`. Or copy the skill folder (cli-tool/components/skills/workflow-automation/dependabot-review in davila7/claude-code-templates) into .claude/skills/dependabot-review in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot Review in Codex?

Run `npx skills add davila7/claude-code-templates --skill dependabot-review -a codex`. Or copy the skill folder (cli-tool/components/skills/workflow-automation/dependabot-review in davila7/claude-code-templates) into .agents/skills/dependabot-review in your project. Codex loads it when a task matches its description.

Can I use Dependabot Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davila7/claude-code-templates --skill dependabot-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-review, .gemini/skills/dependabot-review, .github/skills/dependabot-review and .opencode/skills/dependabot-review in your project.

What does Dependabot Review need to run?

Going by SKILL.md and its folder, Dependabot Review needs the command-line tools its instructions call (gh and jest).

Does Dependabot Review access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependabot Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependabot Review use?

Dependabot Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependabot Review use?

About 915 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot Review?

Skills that share tags, products or a category with Dependabot Review: Add TTS Engine to Voicebox (jamiepine/voicebox, 57k stars), Dep Updates (trufflesecurity/trufflehog, 28k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Senior Architect Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot Review?

davila7 (a GitHub user) maintains it in davila7/claude-code-templates, which has 32,512 GitHub stars. The repository holds 479 skills in this directory. The repository was last updated on October 10, 2026.

Source: davila7/claude-code-templates on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.