Agent skill

Dependabot

by macro-inc in macro-inc/macro

Find all open Dependabot alerts for this repo and create a plan to resolve them using the appropriate package manager overrides (pnpm, bun, npm, cargo).

AGPL-3.0Auto-check: notesDevelopment

Install Dependabot

skills CLI
$ npx skills add macro-inc/macro --skill dependabot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install macro-inc/macro dependabot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/macro-inc/macro.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependabot .claude/skills/dependabot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot
GitHub stars
4.6k
Token cost
~747 tokens
SKILL.md length
282 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Find all open Dependabot alerts for this repo and create a plan to resolve them using the appropriate package manager overrides (pnpm, bun, npm, cargo).

  • Works in 6 steps: Fetch all open alerts → Group alerts by manifest/lockfile → Determine override strategy per manifest → …
  • Tasks that involve Dependency management
  • SKILL.md covers Step 1: Fetch all open alerts, Step 2: Group alerts by…, Step 3: Determine override… and Step 4: Present the plan, plus 3 more sections
  • Calls cargo, gh and bun

What it does

Dependabot is an agent skill from macro-inc/macro. Find all open Dependabot alerts for this repo and create a plan to resolve them using the appropriate package manager overrides (pnpm, bun, npm, cargo).

Its SKILL.md is about 750 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. It works with npm and pnpm. The repository describes itself as: Macro is a unified workspace for teams: email, chat, docs, tasks, agents, calls, and CRM — @-linked together with shared AI memory. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Dependency management

Example prompts

  • “/dependabot”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash, Read, Edit, Glob, Grep, Agent

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Fetch all open alerts
  2. Group alerts by manifest/lockfile
  3. Determine override strategy per manifest
  4. Present the plan
  5. Apply fixes
  6. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 49418e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Edit
    • Glob
    • Grep
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • gh
    • bun
    • pnpm
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, pnpm and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot loads about 747 tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 282 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~747

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Edit, Glob, Grep, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from macro-inc/macro at commit 49418e7, republished under its AGPL-3.0 licence (© macro-inc). 282 words, ~747 tokens.

Download SKILL.mdSave it as .claude/skills/dependabot/SKILL.md (or your agent's skills folder).
name
dependabot
description
Find all open Dependabot alerts for this repo and create a plan to resolve them using the appropriate package manager overrides (pnpm, bun, npm, cargo).
allowed-tools
Bash, Read, Edit, Glob, Grep, Agent

Dependabot Alert Resolution

Step 1: Fetch all open alerts

bash
REPO=$(gh repo view --json nameWithOwner -q .nameWithOwner)
gh api "repos/${REPO}/dependabot/alerts" \
  --jq '.[] | select(.state == "open") | {
    number,
    dependency: .dependency.package.name,
    ecosystem: .dependency.package.ecosystem,
    manifest: .dependency.manifest_path,
    vulnerable_range: .security_vulnerability.vulnerable_version_range,
    patched_version: .security_vulnerability.first_patched_version.identifier,
    severity: .security_vulnerability.severity,
    summary: .security_advisory.summary
  }'

Step 2: Group alerts by manifest/lockfile

Group the alerts by their manifest field (e.g. bun.lock, Cargo.lock, packages/loro-mirror/pnpm-lock.yaml). This determines which override mechanism to use.

Step 3: Determine override strategy per manifest

For each manifest/lockfile, determine the correct override mechanism:

LockfileOverride mechanism
bun.lock / bun.lockb"overrides" in the nearest package.json
pnpm-lock.yaml"pnpm": { "overrides": { ... } } in the workspace root package.json
package-lock.json"overrides" in the nearest package.json
yarn.lock"resolutions" in the nearest package.json
Cargo.lockcargo update -p <package> or workspace [patch.crates-io] in Cargo.toml

Read each target package.json or Cargo.toml to check for existing overrides before adding new ones.

Step 4: Present the plan

Present a table of all alerts grouped by manifest, showing:

  • Alert numbers
  • Package name
  • Current version (from lockfile)
  • Patched version
  • Severity
  • Override mechanism to use

Ask the user to confirm before making changes.

Step 5: Apply fixes

For each group:

npm/bun/pnpm overrides
  • Add override entries to the appropriate package.json
  • Reinstall: bun install / pnpm install / npm install
  • Verify: check the lockfile or <pm> ls for the patched version
Cargo
  • Try cargo update -p <package> first
  • If that doesn't reach the patched version, also try cargo update -p <parent-package> (the package that depends on the vulnerable one, found via cargo tree -i <package>)
  • Verify with cargo tree -i <package> and checking Cargo.lock

Step 6: Verify

After all changes, confirm patched versions are in place and no new audit issues were introduced.

Notes

  • Some alerts may be false positives (e.g. undici-types triggering undici alerts). Flag these to the user.
  • Prefer minimal version bumps (e.g. >=6.14.0 not ^8.0.0) to reduce breakage risk.
  • If a cargo update only bumps to a version below the patch, escalate the parent dependency.

© macro-inc, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/dependabot of macro-inc/macro.

Open the folder on GitHubat commit 49418e7

Compare with similar skills

Dependabot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot this skillmacro-inc/macro4.6k—~747Automated safety check: NotesAGPL-3.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Monorepo Tooling and Dependenciespierrecomputer/pierre6.2k—~1.1kAutomated safety check: PassApache-2.0
Sync Dependabot App Depsossf/oss-crs165—~1.7kAutomated safety check: NotesMIT
Fix Security PRunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
Migrate to Denodenoland/skills100—~2.2kAutomated safety check: WarnMIT

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.2k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

    165 GitHub stars~1.7k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Fix Security PR

    unional/typescript-blackbook

    Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

    133 GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Migrate to Deno

    denoland/skills

    Official

    Moves a Node.js, npm, Yarn, pnpm or Bun project to Deno in reversible steps, starting with Deno as the package manager and changing no code unless needed.

    100 GitHub stars~2.2k tokensUpdated 2 mo ago
    DevelopmentAuto-check: warnings
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings

More from macro-inc/macro

All 19 skills in this repo
  • Mintlify API

    macro-inc/macro

    Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.

    4.6k GitHub starsUsed in 2 repos~333 tokens
    Auto-check passed
  • Add Tour

    macro-inc/macro

    Add or change an in-app feature tour (a view's guided flyover) in the web app.

    4.6k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Define Feature Flag

    macro-inc/macro

    Define a frontend feature flag with defineFlag and wire its readers.

    4.6k GitHub stars~780 tokensUpdated today
    Auto-check passed
  • Run App

    macro-inc/macro

    Run the Macro app on Cursor Cloud and pick up edits. An agent skill from macro-inc/macro.

    4.6k GitHub stars~712 tokensUpdated today
    Auto-check passed
  • Add SDK Endpoint

    macro-inc/macro

    Wrap a new backend endpoint in the TypeScript SDK (packages/sdk), or record it as skipped.

    4.6k GitHub stars~1k tokensUpdated today
    Auto-check: notes
  • Enforce hexagonal architecture in the Rust backend. An agent skill from macro-inc/macro.

    4.6k GitHub stars~3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Dependabot

What does Dependabot do?

Find all open Dependabot alerts for this repo and create a plan to resolve them using the appropriate package manager overrides (pnpm, bun, npm, cargo). Dependabot is an agent skill from macro-inc/macro. Find all open Dependabot alerts for this repo and create a plan to resolve them using the appropriate package manager overrides (pnpm, bun, npm, cargo).

When should I use Dependabot?

Dependabot fits situations like: tasks that involve Dependency management.

How do I install Dependabot in Claude Code?

Run `npx skills add macro-inc/macro --skill dependabot -a claude-code`. Or copy the skill folder (.agents/skills/dependabot in macro-inc/macro) into .claude/skills/dependabot in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot in Codex?

Run `npx skills add macro-inc/macro --skill dependabot -a codex`. Or copy the skill folder (.agents/skills/dependabot in macro-inc/macro) into .agents/skills/dependabot in your project. Codex loads it when a task matches its description.

Can I use Dependabot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add macro-inc/macro --skill dependabot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot, .gemini/skills/dependabot, .github/skills/dependabot and .opencode/skills/dependabot in your project.

What does Dependabot need to run?

Going by SKILL.md and its folder, Dependabot needs the command-line tools its instructions call (cargo, gh, bun, pnpm and npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash, Read, Edit, Glob, Grep, Agent.

Does Dependabot access the network?

SKILL.md contains no URLs. Its commands use gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependabot safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dependabot use?

Dependabot is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dependabot use?

About 747 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot?

Skills that share tags, products or a category with Dependabot: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Monorepo Tooling and Dependencies (pierrecomputer/pierre, 6.2k stars), Sync Dependabot App Deps (ossf/oss-crs, 165 stars) and Fix Security PR (unional/typescript-blackbook, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot?

macro-inc (a GitHub organization) maintains it in macro-inc/macro, which has 4,590 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.

Source: macro-inc/macro on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.