Agent skill

Dependabot PR Review

by kernitus in kernitus/BukkitOldCombatMechanics

A skill your agent uses for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and…

MPL-2.0Auto-check passedDevelopment

Install Dependabot PR Review

skills CLI
$ npx skills add kernitus/BukkitOldCombatMechanics --skill dependabot-pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kernitus/BukkitOldCombatMechanics dependabot-pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kernitus/BukkitOldCombatMechanics.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependabot-pr-review .claude/skills/dependabot-pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot-pr-review
GitHub stars
225
Token cost
~882 tokens
SKILL.md length
380 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MPL-2.0

At a glance

A skill your agent uses for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and…

  • Works in 9 steps: Identify the update manager, dependency… → Read the PR diff and the upstream… → Check licence changes and whether the… → …
  • Dependency bumps
  • SKILL.md covers Cross-load related skills, Review workflow, Validation expectations and Verdicts, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dependabot PR Review is an agent skill from kernitus/BukkitOldCombatMechanics. Use for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and validation recommendations.

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Changelog and release notes and Pull requests. It works with GitHub Actions, Gradle and Java. The repository describes itself as: Minecraft plugin to configure combat mechanics for 1.9 onwards. The licence is MPL-2.0.

When your agent uses it

  • Dependency bumps
  • Maven dependency updates
  • GitHub Actions updates
  • Dependency changelog/licence/release-note review

Example prompts

  • “/dependabot-pr-review”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Identify the update manager, dependency scope, touched files, and whether the dependency is production, compile-only, test-only…
  2. Read the PR diff and the upstream release notes, changelog, migration guide, and security notes for every updated version range.
  3. Check licence changes and whether the dependency ships in the release jar, shaded jar, or integration-test jar.
  4. Check JVM bytecode, classfile version, toolchain, and Gradle module metadata against main Java 8 support and the integration-test Java…
  5. Check Bukkit/Paper/Spigot compatibility when the dependency is server-facing, API-adjacent, PacketEvents-adjacent, or affects plugin…
  6. Check shading, relocation, service files, transitive dependency, and duplicate class risks, especially for anything bundled into the…
  7. For GitHub Actions bumps, check Node/runtime changes, runner image requirements, permission model changes, and deprecated input/output…
  8. Inspect CI status and rerun the narrowest relevant validation where appropriate; prefer static checks for documentation-only or…
  9. Root and user-facing agents must not open build/integration-test-logs/*.log directly. If compact summaries are insufficient, delegate full…

What it can do on your machine

Read from SKILL.md and the folder at commit e66e7a9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot PR Review loads about 882 tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 380 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~882

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kernitus/BukkitOldCombatMechanics at commit e66e7a9, republished under its MPL-2.0 licence (© kernitus). 380 words, ~882 tokens.

Download SKILL.mdSave it as .claude/skills/dependabot-pr-review/SKILL.md (or your agent's skills folder).
name
dependabot-pr-review
description
Use for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and validation recommendations.

Dependabot PR Review

Use this skill when reviewing dependency or workflow version updates. Keep the review evidence-based, scoped to the changed dependency, and explicit about what must be checked before merge.

  • Use integration-test-verification for integration-test matrix selection, compact failure triage, Kotest registration, or any full integration log hand-off.
  • Use compatibility-strategy for Java 8, Bukkit/Paper/Spigot, NMS/reflection, PacketEvents, fake-player, or API compatibility concerns.
  • Use release-readiness-review for licence, shaded dependency, release-note, publishing, or asset-impact questions.

Review workflow

  1. Identify the update manager, dependency scope, touched files, and whether the dependency is production, compile-only, test-only, integration-test-only, or GitHub Actions.
  2. Read the PR diff and the upstream release notes, changelog, migration guide, and security notes for every updated version range.
  3. Check licence changes and whether the dependency ships in the release jar, shaded jar, or integration-test jar.
  4. Check JVM bytecode, classfile version, toolchain, and Gradle module metadata against main Java 8 support and the integration-test Java bands.
  5. Check Bukkit/Paper/Spigot compatibility when the dependency is server-facing, API-adjacent, PacketEvents-adjacent, or affects plugin loading.
  6. Check shading, relocation, service files, transitive dependency, and duplicate class risks, especially for anything bundled into the plugin jar.
  7. For GitHub Actions bumps, check Node/runtime changes, runner image requirements, permission model changes, and deprecated input/output behaviour.
  8. Inspect CI status and rerun the narrowest relevant validation where appropriate; prefer static checks for documentation-only or metadata-only bumps.
  9. Root and user-facing agents must not open build/integration-test-logs/*.log directly. If compact summaries are insufficient, delegate full integration log inspection to a subagent.
Show full SKILL.md (126 more words)Show less

Validation expectations

  • Do not skip, weaken, disable, or version-gate tests to make a dependency update pass.
  • Match validation to risk: build metadata can often use wrapper/config checks; runtime libraries may need unit or integration tests; server-facing changes may need selected Paper matrix runs.
  • Prefer checking the produced dependency graph or shaded jar contents when packaging impact is plausible.

Verdicts

  • merge: low-risk update, relevant notes reviewed, CI/validation is green, and no follow-up is needed.
  • merge after checks: likely safe, but wait for named CI jobs, dependency graph checks, or narrow validation.
  • hold: compatibility, licence, packaging, JVM, server API, or validation concerns need investigation or code changes.
  • close/ignore: update is incompatible, not useful for this branch, duplicates another update, or should be deferred by policy.

Review output template

markdown
### Dependency review
- Scope: production / compile-only / test-only / integration-test-only / GitHub Actions
- Release notes checked:
- Licence/packaging impact:
- JVM and server compatibility:
- Shading/duplicate class risk:
- Validation:
- Verdict: merge / merge after checks / hold / close/ignore

© kernitus, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/dependabot-pr-review of kernitus/BukkitOldCombatMechanics.

Open the folder on GitHubat commit e66e7a9

Compare with similar skills

Dependabot PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot PR Review this skillkernitus/BukkitOldCombatMechanics225—~882Automated safety check: PassMPL-2.0
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
Renovate Actions PR Reviewbacknotprop/plannotator9.3k—~640Automated safety check: PassApache-2.0
Minecraft CI ReleaseJahrome907/minecraft-agent-skills170—~3.6kAutomated safety check: PassMIT
Releasesol4k/sol4k135—~949Automated safety check: PassApache-2.0
ReleasePipelex/pipelex942—~4.8kAutomated safety check: NotesCustom licence

Similar skills

  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.3k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed
  • Minecraft CI Release

    Jahrome907/minecraft-agent-skills

    Set up and review CI, artifact publishing, versioning, and release management for Minecraft 26.x or legacy 1.21.x mods and Paper plugins.

    170 GitHub stars~3.6k tokensUpdated 28 days ago
    DevelopmentAuto-check passed
  • Release

    sol4k/sol4k

    Bump the sol4k library version everywhere, open a release PR, and draft GitHub release notes.

    135 GitHub stars~949 tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • Release

    Pipelex/pipelex

    Cut a release of pipelex, which ships the pipelex and pipelex-api packages and the pipelex/pipelex-api Docker image under one version: the gates, the migration-ledger cross-check, the CHANGELOG.md…

    942 GitHub stars~4.8k tokensUpdated today
    DevelopmentAuto-check: notes
  • Sake CI Release

    kattouf/Sake

    A skill your agent uses when working on CI workflows, GitHub Actions, release process, changelog generation (git-cliff), or dependabot configuration.

    116 GitHub stars~731 tokensUpdated 6 mo ago
    DevelopmentAuto-check passed

More from kernitus/BukkitOldCombatMechanics

All 9 skills in this repo
  • Integration Test Verification

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses when running, selecting, authoring, or triaging integration tests, Kotest specs, Gradle matrix tasks, FakePlayer-backed test cases, or compact test-result files; do not use…

    225 GitHub stars~1.2k tokensUpdated 7 days ago
    Auto-check passed
  • Module Config Change

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses for config.yml, module enablement, modesets, config migration, configurable module assignment, and per-module option changes; do not use for unrelated integration-test…

    225 GitHub stars~914 tokensUpdated 7 days ago
    Auto-check passed
  • PR Draft Summary

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses when drafting pull-request titles, descriptions, change summaries, risk notes, validation sections, or reviewer handoff text; do not use for implementation design, release…

    225 GitHub stars~526 tokensUpdated 7 days ago
    Auto-check passed
  • Release Readiness Review

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses for GitHub release, Hangar, CurseForge/BukkitDev upload, Spigot release handoff, licence, asset naming, supported-version, and workflow readiness checks; do not use for…

    225 GitHub stars~1.5k tokensUpdated 7 days ago
    Auto-check passed
  • User Facing Changelog

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses when rewriting CHANGELOG.md, GitHub release notes, or Release Please PR changelog sections into user-facing release notes; do not use for release publishing, assets, licence…

    225 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check passed
  • Compatibility Strategy

    kernitus/BukkitOldCombatMechanics

    A skill your agent uses for Java 8 backports, Bukkit/Paper version differences, NMS/reflection, PacketEvents compatibility, fake-player implementation choices, and feature-detection design; do not…

    225 GitHub stars~824 tokensUpdated 7 days ago
    Auto-check passed

Categories

Questions about Dependabot PR Review

What does Dependabot PR Review do?

A skill your agent uses for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and…. Dependabot PR Review is an agent skill from kernitus/BukkitOldCombatMechanics. Use for Dependabot PRs, dependency bumps, Gradle or Maven dependency updates, GitHub Actions updates, dependency changelog/licence/release-note review, JVM/classfile checks, and validation recommendations.

When should I use Dependabot PR Review?

Dependabot PR Review fits situations like: dependency bumps; maven dependency updates; GitHub Actions updates; dependency changelog/licence/release-note review.

How do I install Dependabot PR Review in Claude Code?

Run `npx skills add kernitus/BukkitOldCombatMechanics --skill dependabot-pr-review -a claude-code`. Or copy the skill folder (.agents/skills/dependabot-pr-review in kernitus/BukkitOldCombatMechanics) into .claude/skills/dependabot-pr-review in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot PR Review in Codex?

Run `npx skills add kernitus/BukkitOldCombatMechanics --skill dependabot-pr-review -a codex`. Or copy the skill folder (.agents/skills/dependabot-pr-review in kernitus/BukkitOldCombatMechanics) into .agents/skills/dependabot-pr-review in your project. Codex loads it when a task matches its description.

Can I use Dependabot PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kernitus/BukkitOldCombatMechanics --skill dependabot-pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-pr-review, .gemini/skills/dependabot-pr-review, .github/skills/dependabot-pr-review and .opencode/skills/dependabot-pr-review in your project.

What does Dependabot PR Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Dependabot PR Review is instructions for the agent only.

Does Dependabot PR Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dependabot PR Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependabot PR Review use?

Dependabot PR Review is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependabot PR Review use?

About 882 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot PR Review?

Skills that share tags, products or a category with Dependabot PR Review: ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Renovate Actions PR Review (backnotprop/plannotator, 9.3k stars), Minecraft CI Release (Jahrome907/minecraft-agent-skills, 170 stars) and Release (sol4k/sol4k, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot PR Review?

kernitus (a GitHub user) maintains it in kernitus/BukkitOldCombatMechanics, which has 225 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 4, 2026.

Source: kernitus/BukkitOldCombatMechanics on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.