Agent skill

Dependabot Alerts

by forcedotcom in forcedotcom/salesforcedx-vscode

Triage GitHub Dependabot security alerts into one-point GUS work items that bump the outermost consumer.

BSD-3-ClauseAuto-check passedDevelopment

Install Dependabot Alerts

skills CLI
$ npx skills add forcedotcom/salesforcedx-vscode --skill dependabot-alerts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/salesforcedx-vscode dependabot-alerts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/salesforcedx-vscode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dependabot-alerts .claude/skills/dependabot-alerts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot-alerts
GitHub stars
1k
Token cost
~1.5k tokens
SKILL.md length
832 words
Files
1
Skills in repo
37
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Triage GitHub Dependabot security alerts into one-point GUS work items that bump the outermost consumer.

  • Works in 2 steps: npm why (or npm ls ) from repo root →… → For each path, the outermost consumer is…
  • Tasks that involve Dependency management
  • SKILL.md covers Never, Input, Per alert: trace the thread and Per consumer: pick the fix, plus 4 more sections
  • Calls npm, gh and pnpm

What it does

Dependabot Alerts is an agent skill from forcedotcom/salesforcedx-vscode. Triage GitHub Dependabot security alerts into one-point GUS work items that bump the outermost consumer. User-invoked only.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. It works with GitHub and npm. The repository describes itself as: Salesforce Extensions for VS Code. The licence is BSD-3-Clause.

When your agent uses it

  • Tasks that involve Dependency management

Example prompts

  • “/dependabot-alerts”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. npm why (or npm ls ) from repo root → every path to a direct dep declared in a package.json (root or a packages/*).
  2. For each path, the outermost consumer is the direct dep at the top of that path. One alert can have several.

What it can do on your machine

Read from SKILL.md and the folder at commit 5972473. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • gh
    • pnpm
    • jq
    • tsc
    • sf

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, gh and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot Alerts loads about 1.5k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 832 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forcedotcom/salesforcedx-vscode at commit 5972473, republished under its BSD-3-Clause licence (© forcedotcom). 832 words, ~1,486 tokens.

Download SKILL.mdSave it as .claude/skills/dependabot-alerts/SKILL.md (or your agent's skills folder).
name
dependabot-alerts
description
Triage GitHub Dependabot security alerts into one-point GUS work items that bump the outermost consumer. User-invoked only.
review
never

Dependabot Alerts

Triage open Dependabot security alerts into GUS work items. Output is work items only — no branches, bumps, or PRs. The auto-build-wi workflow claims each WI and does the build/PR.

User-invoked only. Never auto-fire.

Never

  • No npm overrides in package.json. Ever.
  • No blind lockfile bumps. Trace the dependency to its outermost consumer first.

Input

  • Bare invocation → list open alerts: gh api repos/forcedotcom/salesforcedx-vscode/dependabot/alerts --paginate --jq '[.[] | select(.state=="open")]' | jq -s add. --paginate is required — the API defaults to 30/page and silently returns only page 1 without it (e.g. 33 open alerts, not the ~14 page 1 shows).
  • User-specified package / GHSA / CVE → act on that alert only.

(Repo is a monorepo, workspaces packages/*. npm 11.)

Per alert: trace the thread

Find who pulls the vulnerable package in, working outward to a package.json.

  1. npm why <vuln-pkg> (or npm ls <vuln-pkg>) from repo root → every path to a direct dep declared in a package.json (root or a packages/*).
  2. For each path, the outermost consumer is the direct dep at the top of that path. One alert can have several.

Per consumer: pick the fix

Try in order; stop at the first that works:

  1. Bump the consumer in package.json. A newer version of the consumer resolves <vuln-pkg> to a patched version (consumer already shipped the fix). Edit the version in whichever package.json declares it. Best — preferred.
  2. pnpm update <consumer>. Consumer's existing semver range already allows a patched <vuln-pkg>, but the lockfile is stale. No package.json change. Second best.
  3. Unfixable — consumer's latest still pins the vulnerable version. Skip this path silently. No WI.

Pick the lowest consumer version that resolves <vuln-pkg> to a patched version, never latest — fewer majors crossed, fewer breaking changes to vet.

Vet major-version bumps

If the chosen bump crosses a major version (e.g. ^1.x → ^3.0.0), spawn one subagent per crossing bump to vet it before drafting the WI. One bump may span several majors (1→3 = two changelogs); independent bumps vet in parallel.

Each subagent's task:

  1. Read the consumer's release notes / CHANGELOG for every major crossed (e.g. 1→3 means read 2.0.0 and 3.0.0). There may be one or five.
  2. For each breaking change found, grep our code for the affected API/behavior and decide if it breaks us specifically.
  3. Return: does the bump break us? What breaks, where (file:line), and the lowest version that clears the vuln without a breaking change.

What the subagent looks for:

  • ESM-only ("type": "module"). Our .github/actions/* and most packages are CJS (tsc module: node16, require() output). An ESM-only dep can't be require()d from a CJS build — breaking migration, not a bump.
  • Dropped Node engine support — must satisfy the consuming context (.github/actions/* run using: node20; extensions target their own engine).
  • Transitive major bumps the consumer drags in (e.g. Octokit majors) — only breaking if our usage touches the changed API.

Act on the verdict:

  • Breaking change avoidable at a lower major that still clears the vuln → prefer it, cap the range below the breaking major (e.g. ^2.0.0, not ^3.0.0). Note the cap + reason in Details__c.
  • Only fixing version forces a breaking migration → the WI is not a simple bump. Put the subagent's findings (what breaks, file:line, required changes) in Details__c so auto-build-wi plans for it.
Show full SKILL.md (301 more words)Show less

Dependabot dedup screen

Before creating a WI for a bump, check for an existing Dependabot PR proposing the same bump (gh pr list --author 'app/dependabot' --state open):

Dependabot PR stateAction
Green / mergeableSkip — let Dependabot merge it. No WI.
CI failingClose the Dependabot PR (gh pr close), then create the WI (manual AI loop is better than a broken Dependabot bump).
CI still runningWait — don't create a WI, don't close. Re-check later.
NoneProceed to create the WI.

Create the work items

One WI per consumer-bump, not per alert. If one alert needs three consumers bumped → three WIs → three PRs. Isolation: each PR's CI/regression runs against exactly one change, so a failure points at one bump.

Each WI:

  • 1 story point.
  • [ai-auto] at the front of Subject__c (e.g. [ai-auto] bump <consumer> to <ver> for <GHSA> (<vuln-pkg>)).
  • Assigned to the runner (you).
  • Epic: IDEx - Mandates and Updates a3QEE0000023Fm92AE. If that epic is closed (Health__c in Completed/Canceled), use the most recent open trust epic instead — query team epics, match by Name.

Details__c = the fix recipe so auto-build-wi can execute blind:

  • GHSA/CVE id, vulnerable package + affected range.
  • The fix: which package.json, which consumer, target version (case 1) or pnpm update <consumer> (case 2).
  • Verification: the exact version that should land in pnpm-lock.yaml after the build.
  • When an alert is split across consumers: 1 of N for <GHSA> (each PR stands alone; Dependabot closes the alert once all land).

Follow gus-cli/SKILL.md for create mechanics (fields, confirmation, temp-Subject + flags-dir flow) and runner identity. Show the draft and wait for confirmation before any sf data create record.

Completion criterion

Every open alert is one of: a created WI (with a lockfile-version verification line), skipped as unfixable, skipped as a green Dependabot PR, or waiting on a running Dependabot PR. Report the disposition of each.

© forcedotcom, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dependabot-alerts of forcedotcom/salesforcedx-vscode.

Open the folder on GitHubat commit 5972473

Compare with similar skills

Dependabot Alerts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot Alerts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot Alerts this skillforcedotcom/salesforcedx-vscode1k—~1.5kAutomated safety check: PassBSD-3-Clause
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Fix Security PRunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
Update Depsgithub/rust-gems134—~2.7kAutomated safety check: PassMIT
Stash Supply Chain Securitycipherstash/stack157—~5.2kAutomated safety check: WarnMIT

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check: warnings
  • Update Deps

    github/rust-gems

    Official

    Keep dependencies up-to-date. An agent skill from github/rust-gems.

    134 GitHub stars~2.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

    159 GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed

More from forcedotcom/salesforcedx-vscode

All 37 skills in this repo
  • Command UI

    forcedotcom/salesforcedx-vscode

    Command palette, CodeLens, context menus, package.nls titles, and NotificationModeService.

    1k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Services Extension Consumption

    forcedotcom/salesforcedx-vscode

    Consume the salesforcedx-vscode-services extension API. An agent skill from forcedotcom/salesforcedx-vscode.

    1k GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Changelog

    forcedotcom/salesforcedx-vscode

    Polish the automated CHANGELOG on develop before the next stable build.

    1k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Core Extension API

    forcedotcom/salesforcedx-vscode

    Public API exported by salesforcedx-vscode-core activate(). An agent skill from forcedotcom/salesforcedx-vscode.

    1k GitHub stars~842 tokensUpdated today
    Auto-check passed
  • Drivable Vscode

    forcedotcom/salesforcedx-vscode

    Operate a real VS Code instance through drivable-vscode. An agent skill from forcedotcom/salesforcedx-vscode.

    1k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Effect Best Practices

    forcedotcom/salesforcedx-vscode

    Enforces Effect-TS patterns for services, errors, layers, atoms, and Effect.pipe composition.

    1k GitHub stars~6.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Dependabot Alerts

What does Dependabot Alerts do?

Triage GitHub Dependabot security alerts into one-point GUS work items that bump the outermost consumer. Dependabot Alerts is an agent skill from forcedotcom/salesforcedx-vscode. Triage GitHub Dependabot security alerts into one-point GUS work items that bump the outermost consumer.

When should I use Dependabot Alerts?

Dependabot Alerts fits situations like: tasks that involve Dependency management.

How do I install Dependabot Alerts in Claude Code?

Run `npx skills add forcedotcom/salesforcedx-vscode --skill dependabot-alerts -a claude-code`. Or copy the skill folder (.claude/skills/dependabot-alerts in forcedotcom/salesforcedx-vscode) into .claude/skills/dependabot-alerts in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot Alerts in Codex?

Run `npx skills add forcedotcom/salesforcedx-vscode --skill dependabot-alerts -a codex`. Or copy the skill folder (.claude/skills/dependabot-alerts in forcedotcom/salesforcedx-vscode) into .agents/skills/dependabot-alerts in your project. Codex loads it when a task matches its description.

Can I use Dependabot Alerts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/salesforcedx-vscode --skill dependabot-alerts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-alerts, .gemini/skills/dependabot-alerts, .github/skills/dependabot-alerts and .opencode/skills/dependabot-alerts in your project.

What does Dependabot Alerts need to run?

Going by SKILL.md and its folder, Dependabot Alerts needs the command-line tools its instructions call (npm, gh, pnpm, jq, tsc and sf).

Does Dependabot Alerts access the network?

SKILL.md contains no URLs. Its commands use npm and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependabot Alerts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependabot Alerts use?

Dependabot Alerts is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependabot Alerts use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot Alerts?

Skills that share tags, products or a category with Dependabot Alerts: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Dependabot Alerts Update (livesession/xyd, 114 stars), Fix Security PR (unional/typescript-blackbook, 133 stars) and Update Deps (github/rust-gems, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot Alerts?

forcedotcom (a GitHub organization) maintains it in forcedotcom/salesforcedx-vscode, which has 1,035 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 9, 2026.

Source: forcedotcom/salesforcedx-vscode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.