Official agent skill

Unblock Dependabot PR

by kubernetes-sigs in kubernetes-sigs/cloud-provider-azure

Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked…

OfficialApache-2.0Auto-check passedDevelopment

Install Unblock Dependabot PR

skills CLI
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill unblock-dependabot-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubernetes-sigs/cloud-provider-azure unblock-dependabot-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/unblock-dependabot-pr .claude/skills/unblock-dependabot-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
unblock-dependabot-pr
GitHub stars
294
Token cost
~1.5k tokens
SKILL.md length
733 words
Files
5 (incl. references)
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked…

  • A Dependabot PR fails go-mod-consistency
  • SKILL.md covers When To Use, Triage First and PR Update Rules
  • Calls gh and git
  • Pull-cloud-provider-azure-e2e jobs

What it does

Unblock Dependabot PR is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked e2e jobs, and updating PR status. Use when a Dependabot PR fails go-mod-consistency, pull-cloud-provider-azure-e2e jobs, or dependency/toolchain CI.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/act-patterns.md`, `references/failure-patterns.md` and `references/guard-patterns.md`).

It sits in Development, covering Dependency management, Pull requests and Container orchestration. It works with Kubernetes, Go and Microsoft Azure. The repository describes itself as: Cloud provider for Azure. The licence is Apache-2.0.

When your agent uses it

  • A Dependabot PR fails go-mod-consistency
  • Pull-cloud-provider-azure-e2e jobs
  • Dependency/toolchain CI

Example prompts

  • “/unblock-dependabot-pr”

What it can do on your machine

Read from SKILL.md and the folder at commit 0201852. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Unblock Dependabot PR loads about 1.5k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 733 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kubernetes-sigs/cloud-provider-azure at commit 0201852, republished under its Apache-2.0 licence (© kubernetes-sigs). 733 words, ~1,501 tokens.

Download SKILL.mdSave it as .claude/skills/unblock-dependabot-pr/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
unblock-dependabot-pr
description
Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked e2e jobs, and updating PR status. Use when a Dependabot PR fails go-mod-consistency, pull-cloud-provider-azure-e2e jobs, or dependency/toolchain CI.

Unblock Dependabot Pull Requests

When To Use

Use this skill when a Dependabot PR in cloud-provider-azure has failed CI and the user wants the agent to unblock it with the smallest safe action.

Expected inputs:

  • PR URL or number
  • Permission to push to the PR branch when a local fix is needed
  • A clean or intentionally scoped working tree

Triage First

Start by reading these references once:

The engine never hard-codes a pattern — it walks the catalog by the staged algorithm below. Do not read references/act-patterns.md until the act stage. Read references/shared-actions.md only when a matched guard or act workflow links to it. Read each reference at most once per triage; following a cross-file link never requires reloading a file already read.

Fetch the PR metadata shared by guard rows first, before any CI or log I/O:

bash
gh pr view <pr> --json number,title,headRefName,headRepositoryOwner,headRefOid,baseRefName,author,labels,mergeable

When each guard row is reached, its linked Details fetch any extra allowed input, such as the go.mod diff or PR comment/commit history, in priority order.

Then walk the catalog as an explicit staged algorithm:

Guard stage — metadata/diff/comment/commit-history only. Before running gh pr checks, reading statusCheckRollup, or fetching any Prow log, evaluate every guard row whose Signal is computable from PR metadata, the go.mod diff, and PR comment/commit history alone. If a guard row matches and is marked Stop, follow its linked Details action (e.g. /close) and end triage immediately — do not inspect CI, sync modules, retest, /lgtm, or report no-action.

Classification gate. Only if no guard Stop fired: fetch CI status and checkout as needed, then build the current failed required job list. Do not require a full up-front classification before acting.

Act stage. Read references/act-patterns.md, then process failed required jobs one at a time. For one failed job, walk act rows by ascending Priority, inspect only enough current evidence to match a row or escalate, take that row's linked Details action only when its Details preconditions and exclusions hold, then move to the next failed job. Read references/shared-actions.md only if that matched workflow links to it. Continue until every failed required job is examined, resolved, rerun, or escalated. Track the actions already taken this triage: a push reruns CI but does not resolve other failures, so still classify each later failed job from its current evidence and skip only an action whose sole effect would be to retest a job the push reruns. Prefer the push-triggered rerun. An act row marked Stop ends triage after it is handled.

Finalize. If no Stop fired and a push recorded a pending approval, evaluate Post-push /lgtm once, never inside the per-failure loop. Then post the single Attempt stamp summary if a retry-budgeted act-stage action completed.

Classification inspects CI only after no guard Stop fired:

bash
gh pr view <pr> --json number,title,headRefName,headRepositoryOwner,headRefOid,baseRefName,author,labels,mergeable,statusCheckRollup
gh pr checks <pr>

If the local checkout is needed, fetch and check out the PR head, then check for unrelated work:

bash
gh pr checkout <pr>
git status --short

Stop and report a conflict if unrelated uncommitted changes exist. Do not stage or overwrite unrelated files.

Show full SKILL.md (233 more words)Show less

PR Update Rules

  • Preserve the generated Dependabot PR body. If a manual compatibility fix was pushed, append a concise reviewer-facing note instead of replacing the body; include why the note is needed and the smallest useful evidence, such as the compatibility issue, commit SHA, changed files, and validation result.
  • Use specific staging commands, never git add ..
  • Push only the current task's files.
  • Use one PR-comment-backed retry counter. The Retry budget exhausted guard reads N once, before any rebase/recreate directive or CI/log I/O; reuse it for the whole triage and write at most one attempt stamp per triage. When the budget is exhausted, mutate nothing and escalate. Public-IP quota reruns are unbudgeted; Attempt stamp owns the accounting.
  • Use the retry mechanism for the CI system that produced the failure, and only after the failure is classified as transient or safe to rerun. For Prow jobs, rerun with a per-job /test <job-name> comment; never use /retest. For GitHub Actions check runs, rerun through GitHub Actions (gh run rerun), not through a PR slash command.
  • Report pending jobs, tide status, and any residual risk clearly instead of claiming the PR is green before CI finishes. When an escalate row matched (retry budget spent, or a toolchain / SDK / policy blocker), report the PR as needing human review, naming the blocker and any failing jobs already known under that row's I/O rules, rather than claiming it was unblocked.

© kubernetes-sigs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .agents/skills/unblock-dependabot-pr of kubernetes-sigs/cloud-provider-azure.

  • SKILL.md
  • references/act-patterns.md
  • references/failure-patterns.md
  • references/guard-patterns.md
  • references/shared-actions.md

Open the folder on GitHubat commit 0201852

Compare with similar skills

Unblock Dependabot PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unblock Dependabot PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unblock Dependabot PR this skillkubernetes-sigs/cloud-provider-azure294—~1.5kAutomated safety check: PassApache-2.0
Fix Flakeskubernetes-sigs/agent-sandbox4.2k—~1.1kAutomated safety check: PassApache-2.0
Iterate PRmeshery/meshery-operator1517 repos~2.2kAutomated safety check: PassApache-2.0
Must Gather Investigationscylladb/scylla-operator401—~2.4kAutomated safety check: PassApache-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
Provider Bug Reviewmondoohq/mql412—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Fix Flakes

    kubernetes-sigs/agent-sandbox

    Official

    Diagnose and fix flaky tests tracked as open kind/flake issues in kubernetes-sigs/agent-sandbox — reproduce the flake, apply a minimal fix, and open a PR linking the issue.

    4.2k GitHub stars~1.1k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Iterate PR

    meshery/meshery-operator

    Iterate on a PR until CI passes. An agent skill from meshery/meshery-operator.

    151 GitHub starsUsed in 7 repos~2.2k tokens
    DevelopmentAuto-check passed
  • Must Gather Investigation

    scylladb/scylla-operator

    Investigate failed e2e tests from Ginkgo JSON reports and must-gather artifacts, systematically analyzing logs, events, and resource states to identify root causes.

    401 GitHub stars~2.4k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    412 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Kubelb Dependency Updates

    kubermatic/kubelb

    Sweep and update every dependency surface in the kubelb repo (go.mod, Makefile tool versions, prow images, GitHub Actions, hack/ci pins, addon Helm charts, pinned container images) and split the…

    148 GitHub stars~1.3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed

More from kubernetes-sigs/cloud-provider-azure

All 12 skills in this repo
  • Run E2E Test

    kubernetes-sigs/cloud-provider-azure

    Official

    Parse a Go e2e test from tests/e2e/, translate each step to kubectl and az CLI commands, and interactively replay the test against a live cluster.

    294 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check passed
  • Build Images

    kubernetes-sigs/cloud-provider-azure

    Official

    Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

    294 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Cherry Pick PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Cherry-pick a merged pull request onto a release branch with Prow-style branch naming, manual conflict resolution, targeted validation, and GitHub PR creation.

    294 GitHub stars~636 tokensUpdated 2 days ago
    Auto-check passed
  • Create Release Note Doc PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Generate or update the documentation-site release note for a given tag, commit it on a branch, push it to a writable remote, and open a GitHub PR to the docs branch.

    294 GitHub stars~768 tokensUpdated 2 days ago
    Auto-check passed
  • Create Release Tags

    kubernetes-sigs/cloud-provider-azure

    Official

    Create and optionally push the next Kubernetes-style release tag (vX.Y.Z) from a release-X.Y branch by resolving the remote branch tip, computing the next patch tag, and tagging the commit directly…

    294 GitHub stars~574 tokensUpdated 2 days ago
    Auto-check passed
  • Cve Remediator V2

    kubernetes-sigs/cloud-provider-azure

    Official

    Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…

    294 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Unblock Dependabot PR

What does Unblock Dependabot PR do?

Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked…. Unblock Dependabot PR is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Diagnose and unblock failed Dependabot pull requests in cloud-provider-azure by closing Kubernetes minor-version dependency bumps, classifying CI failures, syncing Go modules, retesting quota-flaked e2e jobs, and updating PR status.

When should I use Unblock Dependabot PR?

Unblock Dependabot PR fits situations like: A Dependabot PR fails go-mod-consistency; pull-cloud-provider-azure-e2e jobs; dependency/toolchain CI.

How do I install Unblock Dependabot PR in Claude Code?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill unblock-dependabot-pr -a claude-code`. Or copy the skill folder (.agents/skills/unblock-dependabot-pr in kubernetes-sigs/cloud-provider-azure) into .claude/skills/unblock-dependabot-pr in your project. Claude Code loads it when a task matches its description.

How do I install Unblock Dependabot PR in Codex?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill unblock-dependabot-pr -a codex`. Or copy the skill folder (.agents/skills/unblock-dependabot-pr in kubernetes-sigs/cloud-provider-azure) into .agents/skills/unblock-dependabot-pr in your project. Codex loads it when a task matches its description.

Can I use Unblock Dependabot PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubernetes-sigs/cloud-provider-azure --skill unblock-dependabot-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unblock-dependabot-pr, .gemini/skills/unblock-dependabot-pr, .github/skills/unblock-dependabot-pr and .opencode/skills/unblock-dependabot-pr in your project.

What does Unblock Dependabot PR need to run?

Going by SKILL.md and its folder, Unblock Dependabot PR needs the command-line tools its instructions call (gh and git).

Does Unblock Dependabot PR access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Unblock Dependabot PR safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Unblock Dependabot PR use?

Unblock Dependabot PR is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unblock Dependabot PR use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.5k tokens, read only when the agent opens those files.

What are the alternatives to Unblock Dependabot PR?

Skills that share tags, products or a category with Unblock Dependabot PR: Fix Flakes (kubernetes-sigs/agent-sandbox, 4.2k stars), Iterate PR (meshery/meshery-operator, 151 stars), Must Gather Investigation (scylladb/scylla-operator, 401 stars) and NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unblock Dependabot PR?

kubernetes-sigs (a GitHub organization, an official publisher) maintains it in kubernetes-sigs/cloud-provider-azure, which has 294 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.

Source: kubernetes-sigs/cloud-provider-azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.