Agent skill

Add To Dependabot CSV

by langfuse in langfuse/langfuse

Append GitHub Dependabot or Snyk/code-scanning alerts to an existing vulnerability CSV after verifying their API metadata.

Custom licenceAuto-check passedDevelopment

Install Add To Dependabot CSV

skills CLI
$ npx skills add langfuse/langfuse --skill add-to-dependabot-csv -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langfuse/langfuse add-to-dependabot-csv --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langfuse/langfuse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-to-dependabot-csv .claude/skills/add-to-dependabot-csv && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-to-dependabot-csv
GitHub stars
36k
Token cost
~1.5k tokens
SKILL.md length
743 words
Files
2
Skills in repo
33
Repo updated
First seen
Licence
Custom licence

At a glance

Append GitHub Dependabot or Snyk/code-scanning alerts to an existing vulnerability CSV after verifying their API metadata.

  • Works in 4 steps: Locate and inspect → Verify GitHub metadata → Map to the existing columns → …
  • Add to Dependabot CSV
  • SKILL.md covers 1. Locate and inspect, 2. Verify GitHub metadata, 3. Map to the existing columns and 4. Append and verify
  • Calls gh

What it does

Add To Dependabot CSV is an agent skill from langfuse/langfuse. Append GitHub Dependabot or Snyk/code-scanning alerts to an existing vulnerability CSV after verifying their API metadata. Use for "add to Dependabot CSV" or "dismissed it, add it to the list".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Dependency management and CSV and tabular files. It works with GitHub and Snyk. The repository describes itself as: 🪢 Open source agent evals & observability: Trace, evaluate, and improve LLM applications with one open platform.

When your agent uses it

  • Add to Dependabot CSV
  • Add it to the list

Example prompts

  • “add to Dependabot CSV”
  • “dismissed it, add it to the list”
  • “/add-to-dependabot-csv”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Locate and inspect
  2. Verify GitHub metadata
  3. Map to the existing columns
  4. Append and verify

What it can do on your machine

Read from SKILL.md and the folder at commit 389f393. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add To Dependabot CSV loads about 1.5k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 743 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 743 words (~1,452 tokens).

“Update the local tracker only. Read GitHub; do not dismiss alerts, change dependencies, or commit files as part of this workflow.”

— opening of SKILL.md by langfuse, Custom licence
name
add-to-dependabot-csv

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in .agents/skills/add-to-dependabot-csv of langfuse/langfuse.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 389f393

Compare with similar skills

Add To Dependabot CSV next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add To Dependabot CSV compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add To Dependabot CSV this skilllangfuse/langfuse36k—~1.5kAutomated safety check: PassCustom licence
Fix Security PRunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
Performing Sca Dependency Scanning With Snykmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Merge Dependabot PRsonyx-dot-app/onyx32k1 repos~2.2kAutomated safety check: PassMIT
Update .NET OS Packagesdotnet/core22k—~2.3kAutomated safety check: PassMIT
OBS Plugin Dependency Upgradesorayuki/obs-multi-rtmp5.1k—~609Automated safety check: PassGPL-2.0

Similar skills

  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated 2 days ago
    DevelopmentAuto-check: warnings
  • Performing Sca Dependency Scanning With Snyk

    mukul975/Anthropic-Cybersecurity-Skills

    This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines.

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Merge Dependabot PRs

    onyx-dot-app/onyx

    Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…

    32k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • OBS Plugin Dependency Upgrade

    sorayuki/obs-multi-rtmp

    Updates the obs-multi-rtmp plugin repo to the latest upstream plugin template and OBS Studio version, including dependency metadata, then rebuilds it with CMake.

    5.1k GitHub stars~609 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.2k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed

More from langfuse/langfuse

All 33 skills in this repo
  • Linear Context Handover

    langfuse/langfuse

    Use Linear as the org's memory: reconstruct a feature's history before touching it, and leave the reasoning behind finished work in the ticket description so the next agent inherits it.

    36k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Add Model Price

    langfuse/langfuse

    A skill your agent uses when editing worker/src/constants/default-model-prices.json, packages/shared/src/server/llm/types.ts, pricing tiers, tokenizer IDs, or matchPattern regexes for OpenAI…

    36k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Backend Dev Guidelines

    langfuse/langfuse

    Build or review Langfuse backend code. An agent skill from langfuse/langfuse.

    36k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Navigate Langfuse repositories, code areas, and agent skills.

    36k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Refactor React Effects

    langfuse/langfuse

    Refactor avoidable React useEffect usage in Langfuse frontend code.

    36k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Clickhouse Best Practices

    langfuse/langfuse

    MUST USE when reviewing ClickHouse schemas, queries, or configurations.

    36k GitHub stars~3.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Add To Dependabot CSV

What does Add To Dependabot CSV do?

Append GitHub Dependabot or Snyk/code-scanning alerts to an existing vulnerability CSV after verifying their API metadata. Add To Dependabot CSV is an agent skill from langfuse/langfuse. Append GitHub Dependabot or Snyk/code-scanning alerts to an existing vulnerability CSV after verifying their API metadata.

When should I use Add To Dependabot CSV?

Add To Dependabot CSV fits situations like: add to Dependabot CSV; add it to the list.

How do I install Add To Dependabot CSV in Claude Code?

Run `npx skills add langfuse/langfuse --skill add-to-dependabot-csv -a claude-code`. Or copy the skill folder (.agents/skills/add-to-dependabot-csv in langfuse/langfuse) into .claude/skills/add-to-dependabot-csv in your project. Claude Code loads it when a task matches its description.

How do I install Add To Dependabot CSV in Codex?

Run `npx skills add langfuse/langfuse --skill add-to-dependabot-csv -a codex`. Or copy the skill folder (.agents/skills/add-to-dependabot-csv in langfuse/langfuse) into .agents/skills/add-to-dependabot-csv in your project. Codex loads it when a task matches its description.

Can I use Add To Dependabot CSV in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langfuse/langfuse --skill add-to-dependabot-csv -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-to-dependabot-csv, .gemini/skills/add-to-dependabot-csv, .github/skills/add-to-dependabot-csv and .opencode/skills/add-to-dependabot-csv in your project.

What does Add To Dependabot CSV need to run?

Going by SKILL.md and its folder, Add To Dependabot CSV needs the command-line tools its instructions call (gh).

Does Add To Dependabot CSV access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Add To Dependabot CSV safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add To Dependabot CSV use?

Add To Dependabot CSV has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Add To Dependabot CSV use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add To Dependabot CSV?

Skills that share tags, products or a category with Add To Dependabot CSV: Fix Security PR (unional/typescript-blackbook, 133 stars), Performing Sca Dependency Scanning With Snyk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Merge Dependabot PRs (onyx-dot-app/onyx, 32k stars) and Update .NET OS Packages (dotnet/core, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add To Dependabot CSV?

langfuse (a GitHub organization) maintains it in langfuse/langfuse, which has 35,555 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.

Source: langfuse/langfuse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.