Update V8 Version
openinterpreter/openinterpreter
Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…
$ npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install onyx-dot-app/onyx merge-dependabot-prs --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/onyx-dot-app/onyx.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/merge-dependabot-prs .claude/skills/merge-dependabot-prs && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "merge-dependabot-prs" agent skill from https://github.com/onyx-dot-app/onyx/tree/main/.agents/skills/merge-dependabot-prs into .claude/skills/merge-dependabot-prs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "merge-dependabot-prs", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/onyx-dot-app/onyx/tree/main/.agents/skills/merge-dependabot-prsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install onyx-dot-app/onyx merge-dependabot-prs --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/onyx-dot-app/onyx.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/merge-dependabot-prs .agents/skills/merge-dependabot-prs && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "merge-dependabot-prs" agent skill from https://github.com/onyx-dot-app/onyx/tree/main/.agents/skills/merge-dependabot-prs into .agents/skills/merge-dependabot-prs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "merge-dependabot-prs", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install onyx-dot-app/onyx merge-dependabot-prs --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/onyx-dot-app/onyx.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/merge-dependabot-prs .cursor/skills/merge-dependabot-prs && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "merge-dependabot-prs" agent skill from https://github.com/onyx-dot-app/onyx/tree/main/.agents/skills/merge-dependabot-prs into .cursor/skills/merge-dependabot-prs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "merge-dependabot-prs", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/onyx-dot-app/onyx.git --path .agents/skills/merge-dependabot-prs--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install onyx-dot-app/onyx merge-dependabot-prs --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/onyx-dot-app/onyx.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/merge-dependabot-prs .gemini/skills/merge-dependabot-prs && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "merge-dependabot-prs" agent skill from https://github.com/onyx-dot-app/onyx/tree/main/.agents/skills/merge-dependabot-prs into .gemini/skills/merge-dependabot-prs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "merge-dependabot-prs", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install onyx-dot-app/onyx merge-dependabot-prsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/onyx-dot-app/onyx.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/merge-dependabot-prs .github/skills/merge-dependabot-prs && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "merge-dependabot-prs" agent skill from https://github.com/onyx-dot-app/onyx/tree/main/.agents/skills/merge-dependabot-prs into .github/skills/merge-dependabot-prs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "merge-dependabot-prs", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install onyx-dot-app/onyx merge-dependabot-prs --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/onyx-dot-app/onyx.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/merge-dependabot-prs .opencode/skills/merge-dependabot-prs && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "merge-dependabot-prs" agent skill from https://github.com/onyx-dot-app/onyx/tree/main/.agents/skills/merge-dependabot-prs into .opencode/skills/merge-dependabot-prs/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "merge-dependabot-prs", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
merge-dependabot-prsTriages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…
Merge Dependabot PRs is an agent skill from onyx-dot-app/onyx. Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes mechanical CI failures (stale backend/requirements exports, stale bun.lock), tells real regressions apart from pre-existing breakage and flakes, and tracks every PR through to merge. Use when the user asks to merge, clean up, clear out, or land Dependabot (or similar bot-authored) PRs.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/graphql-queries.md`). Compatibility notes: Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx.
It sits in Development, covering Dependency management. It works with GitHub, Python and Playwright. The repository describes itself as: Open Source AI Platform - AI Chat with advanced features that works with every LLM. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ab2e6bb. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(gh:*)Bash(git:*)Bash(pre-commit:*)Bash(bun install:*)Bash(ods audit:*)From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghbunjestuvgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, uv and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx.
From compatibility in the SKILL.md frontmatter.
Merge Dependabot PRs loads about 2.2k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 1,029 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from onyx-dot-app/onyx at commit ab2e6bb, republished under its MIT licence (© onyx-dot-app). 1,029 words, ~2,176 tokens.
.claude/skills/merge-dependabot-prs/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Treat each blocked PR as its own small diagnosis, not one "just merge it" action.
Confirm before anything consequential. Approving, closing, pushing to a PR
branch, merging main into someone's branch, and rerunning CI all touch shared
state. Triage everything into buckets first, then confirm the plan per bucket
with AskUserQuestion — not per PR, and not after the fact. Re-confirm if a
genuinely new kind of problem appears mid-flight (e.g. a real regression where
a mechanical fix was expected).
main merges exclusively through the merge queue ("Main Protection"
ruleset). Enqueue with gh pr merge <pr> --auto — no strategy flag; the
queue picks the method. --squash/--merge/--rebase will be rejected.quality-checks, playwright-required, database-tests,
backend-check, mypy-check, Jest Tests, required.required (in pr-integration-tests.yml) and playwright-required (in
pr-playwright-tests.yml) are aggregate needs: [...] + if: always()
jobs over the slow integration/playwright matrices. If either is absent
from gh pr checks, its matrix is still running — the PR isn't blocked.
(merge-group.yml provides fast same-named jobs inside the queue itself;
they only check that the PR run's verdict used a base that landed, and skip
that check for Dependabot PRs, which cannot record it.)mergeStateStatus/autoMergeRequest are unreliable for "is it actually
queued" — query the queue directly: references/graphql-queries.md.gh pr list --search "is:open author:app/dependabot assignee:<user>" \
--json number,title,headRefName,mergeable,mergeStateStatus,reviewDecision,statusCheckRollupPRs are labeled by ecosystem (dependabot:python, dependabot:javascript,
dependabot:docker, dependabot:actions, plus dependabot:sandbox) and
assigned per .github/dependabot.yml. Flag duplicates: two PRs bumping the
same package, or a manual bump PR overlapping a bot one.
These PRs aren't in a rush. Wait for every check to complete — required and advisory alike — and treat any red check as a failure to classify, never as noise to skip. Two advisory checks matter here even though the queue ignores them:
storybook-build (pr-storybook-build.yml) on web/** changes — never
gates the queue, but pages Slack if broken post-merge.
audit (audit.yml) — runs on every lockfile, pyproject.toml,
.github/workflows/**, and tools/ods/** change, so it runs on almost every
Dependabot PR. Treat it as required for this skill: a Dependabot PR does
not get enqueued while audit is red. A red audit means the bump either
pulled in a vulnerable version or landed next to one, and merging it ships
the finding.
Green & ready — every check completed and passing, advisory included.
Failing — mechanical — only a generated/lock file wasn't regenerated after the bump (see step 5 for the Onyx cases).
Failing — needs diagnosis — anything else; requires reading the failing job's log first, never just the check name.
Conflicting — real merge conflict against main.
Superseded — a newer PR in the batch covers it.
Independent of bucket, assess compatibility: note each PR's semver jump and whether the package is production or dev-only. Major bumps (and 0.x minors, which semver allows to break) are never covered by a blanket "enqueue the green ones" — green CI proves the build, not the behavior. Surface each one individually in the confirmation with a one-line breaking-changes summary from the release notes Dependabot embeds in the PR body, and let the user opt in per PR.
Summarize buckets and proposed actions, confirm with AskUserQuestion, then act.
Run ods audit on the PR's code before you enqueue it. CI's audit job covers
this, but it is skipped when the PR touches no audited path, and it is advisory
in the queue — so confirm it yourself for every Dependabot PR.
gh pr checkout <pr>
source .venv/bin/activate # ods ships in the repo venv
ods audit --fail-on=criticalods audit scans bun.lock and uv.lock plus open Dependabot alerts, and
exits non-zero on an unignored finding at or above --fail-on
(tools/ods/README.md). It reads the working
tree, so the PR branch must be checked out — a run on main says nothing
about the bump.
If it exits non-zero, STOP. Don't enqueue and don't try to work out whether
the finding came from this bump or was already on main. Report the advisory ids
and let the user say how to proceed.
Then, once clean:
gh pr review <pr> --approve
gh pr merge <pr> --autoIf a PR falls out of the queue (e.g. head_ref_force_pushed after a Dependabot
rebase), re-running gh pr merge <pr> --auto is routine, not a failure.
gh pr closeOnce the bucket is approved, individual stale-generated-file fixes don't need per-PR confirmation. Known Onyx cases:
dependabot:python): the exported backend/requirements/*.txt
files go stale when only pyproject.toml/uv.lock were bumped. Regenerate
via the same pre-commit hooks CI uses:pre-commit run --files pyproject.toml uv.lock backend/requirements/*.txtdependabot:javascript): stale bun.lock — run
bun install in the bumped directory (repo root or web/).Getting the branch: prefer the harness's isolated-worktree feature if it has
one (Claude Code: EnterWorktree). Otherwise, if the current checkout is
clean, work in place — gh pr checkout <pr>, fix, push, and return to the
previous branch. If neither applies (e.g. dirty checkout), ask the user where
to resolve (AskUserQuestion) rather than picking a spot — and steer away
from tmpfs paths like /tmp, which can hit "Disk quota exceeded"
mid-post-checkout hook (uv sync/bun install) even when they look roomy.
gh run rerun <runId> --failed). If the same
failure recurs, stop and ask — a persisting "flake" may not be one.@dependabot rebase (or
recreate) — Dependabot owns the branch and will redo it properly.@dependabot rebase discards
non-Dependabot commits. Instead rebase onto origin/main yourself, rerun
the step 5 regeneration if lockfiles conflicted, push with
--force-with-lease, and verify git diff origin/main...HEAD --stat still
shows only the intended bump. If a pre-push hook trips on a stale local
cache (e.g. dev type-gen referencing a file deleted upstream), clear the
cache and retry — don't skip the hook.Prefer one polling loop (e.g. Monitor) over repeated manual checks: watch
both queue state and PR state (MERGED/CLOSED), and surface new failures as
they appear rather than staying silent until success.
Merged (N): #A, #B, #C
Closed as superseded (N): #D (superseded by #E)
Left for you (N): #F — <specific unresolved reason>© onyx-dot-app, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .agents/skills/merge-dependabot-prs of onyx-dot-app/onyx.
Open the folder on GitHubat commit ab2e6bb
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in onyx-dot-app/onyx, which our catalogue first saw on October 7, 2026.
Merge Dependabot PRs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Merge Dependabot PRs this skillonyx-dot-app/onyx | 32k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Update V8 Versionopeninterpreter/openinterpreter | 69k | 2 repos | ~845 | Automated safety check: Pass | Apache-2.0 | |
| OpenROAD Issue TriageThe-OpenROAD-Project/OpenROAD | 3.2k | — | ~842 | Automated safety check: Pass | BSD-3-Clause | |
| LangBot Environment Setuplangbot-app/LangBot | 18k | — | ~496 | Automated safety check: Notes | Apache-2.0 | |
| Deps Bumplkmeta/txtify | 135 | — | ~585 | Automated safety check: Pass | Apache-2.0 | |
| Debug Sessionai-dynamo/dynamo | 8.3k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 |
openinterpreter/openinterpreter
Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.
The-OpenROAD-Project/OpenROAD
Reproduces an OpenROAD GitHub bug from an attached tarball and shrinks the failing design with whittle.py so maintainers get a minimal test case.
langbot-app/LangBot
Prepares a LangBot development and testing environment for an agent, covering service startup, proxy settings and browser access through Computer Use or Playwright MCP.
lkmeta/txtify
Safely update Txtify dependencies or resolve Dependabot alerts.
ai-dynamo/dynamo
Sets up a structured debugging session for a Dynamo bug — pull the report from a Linear ticket, GitHub issue, or pasted text, capture the environment, create a persistent worklog markdown file, and…
LeoYeAI/openclaw-master-skills
Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
onyx-dot-app/onyx
Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.
onyx-dot-app/onyx
Generate or edit raster images (photos, illustrations, textures, sprites, mockups, logos, infographics) using the workspace's configured image-generation provider via onyx-cli image.
onyx-dot-app/onyx
Query the Onyx knowledge base using the onyx-cli command. An agent skill from onyx-dot-app/onyx.
onyx-dot-app/onyx
Write and maintain Playwright end-to-end tests for the Onyx application.
onyx-dot-app/onyx
Core browser usage guide. An agent skill from onyx-dot-app/onyx.
Works with
Categories
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…. Merge Dependabot PRs is an agent skill from onyx-dot-app/onyx.lock), tells real regressions apart from pre-existing breakage and flakes, and tracks every PR through to merge.
Merge Dependabot PRs fits situations like: the user asks to merge; land Dependabot (or similar bot-authored) PRs.
Run `npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a claude-code`. Or copy the skill folder (.agents/skills/merge-dependabot-prs in onyx-dot-app/onyx) into .claude/skills/merge-dependabot-prs in your project. Claude Code loads it when a task matches its description.
Run `npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a codex`. Or copy the skill folder (.agents/skills/merge-dependabot-prs in onyx-dot-app/onyx) into .agents/skills/merge-dependabot-prs in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/merge-dependabot-prs, .gemini/skills/merge-dependabot-prs, .github/skills/merge-dependabot-prs and .opencode/skills/merge-dependabot-prs in your project.
Going by SKILL.md and its folder, Merge Dependabot PRs needs the command-line tools its instructions call (gh, bun, jest, uv and git). Our summary lists: Docker. Its frontmatter pre-approves these tools: Bash(gh:*), Bash(git:*), Bash(pre-commit:*), Bash(bun install:*), Bash(ods audit:*). Compatibility (from SKILL.md): Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx..
SKILL.md contains no URLs. Its commands use gh, uv and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Merge Dependabot PRs is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 317 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Merge Dependabot PRs: Update V8 Version (openinterpreter/openinterpreter, 69k stars), OpenROAD Issue Triage (The-OpenROAD-Project/OpenROAD, 3.2k stars), LangBot Environment Setup (langbot-app/LangBot, 18k stars) and Deps Bump (lkmeta/txtify, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
onyx-dot-app (a GitHub organization) maintains it in onyx-dot-app/onyx, which has 32,381 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.
Source: onyx-dot-app/onyx on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.