Agent skill

Merge Dependabot PRs

by onyx-dot-app in onyx-dot-app/onyx

Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…

MITAuto-check passedDevelopment

Install Merge Dependabot PRs

skills CLI
$ npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install onyx-dot-app/onyx merge-dependabot-prs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/onyx-dot-app/onyx.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/merge-dependabot-prs .claude/skills/merge-dependabot-prs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
merge-dependabot-prs
GitHub stars
32k
Used in
1 other repo
Token cost
~2.2k tokens
SKILL.md length
1,029 words
Files
2 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…

  • Works in 9 steps: Discover the batch → Triage into buckets, confirm the plan → Green: audit, approve, enqueue → …
  • The user asks to merge
  • SKILL.md covers How Onyx gates merges, 1. Discover the batch, 2. Triage into buckets,… and 3. Green: audit, approve,…, plus 6 more sections
  • Calls gh, bun and jest

What it does

Merge Dependabot PRs is an agent skill from onyx-dot-app/onyx. Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes mechanical CI failures (stale backend/requirements exports, stale bun.lock), tells real regressions apart from pre-existing breakage and flakes, and tracks every PR through to merge. Use when the user asks to merge, clean up, clear out, or land Dependabot (or similar bot-authored) PRs.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/graphql-queries.md`). Compatibility notes: Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx.

It sits in Development, covering Dependency management. It works with GitHub, Python and Playwright. The repository describes itself as: Open Source AI Platform - AI Chat with advanced features that works with every LLM. The licence is MIT.

When your agent uses it

  • The user asks to merge
  • Land Dependabot (or similar bot-authored) PRs

Example prompts

  • “Use the merge-dependabot-prs skill to triage and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's…”
  • “/merge-dependabot-prs”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx.
  • Pre-approved tools (allowed-tools): Bash(gh:*), Bash(git:*), Bash(pre-commit:*), Bash(bun install:*), Bash(ods audit:*)

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Discover the batch
  2. Triage into buckets, confirm the plan
  3. Green: audit, approve, enqueue
  4. Superseded: comment which PR supersedes it, then gh pr close
  5. Mechanical: fix in an isolated worktree
  6. Needs diagnosis: read the failing job's log, then classify
  7. Conflicts
  8. Track to completion
  9. Report

What it can do on your machine

Read from SKILL.md and the folder at commit ab2e6bb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(gh:*)
    • Bash(git:*)
    • Bash(pre-commit:*)
    • Bash(bun install:*)
    • Bash(ods audit:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • bun
    • jest
    • uv
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, uv and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx.

    From compatibility in the SKILL.md frontmatter.

Context cost

Merge Dependabot PRs loads about 2.2k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 1,029 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~125
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from onyx-dot-app/onyx at commit ab2e6bb, republished under its MIT licence (© onyx-dot-app). 1,029 words, ~2,176 tokens.

Download SKILL.mdSave it as .claude/skills/merge-dependabot-prs/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
merge-dependabot-prs
description
Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes mechanical CI failures (stale backend/requirements exports, stale bun.lock), tells real regressions apart from pre-existing breakage and flakes, and tracks every PR through to merge. Use when the user asks to merge, clean up, clear out, or land Dependabot (or similar bot-authored) PRs.
allowed-tools
Bash(gh:*), Bash(git:*), Bash(pre-commit:*), Bash(bun install:*), Bash(ods audit:*)
compatibility
Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx.
license
MIT
metadata.author
jmelahman
metadata.version
1.1

Merge Dependabot PRs

Treat each blocked PR as its own small diagnosis, not one "just merge it" action.

Confirm before anything consequential. Approving, closing, pushing to a PR branch, merging main into someone's branch, and rerunning CI all touch shared state. Triage everything into buckets first, then confirm the plan per bucket with AskUserQuestion — not per PR, and not after the fact. Re-confirm if a genuinely new kind of problem appears mid-flight (e.g. a real regression where a mechanical fix was expected).

How Onyx gates merges

  • main merges exclusively through the merge queue ("Main Protection" ruleset). Enqueue with gh pr merge <pr> --auto — no strategy flag; the queue picks the method. --squash/--merge/--rebase will be rejected.
  • Required checks: quality-checks, playwright-required, database-tests, backend-check, mypy-check, Jest Tests, required.
  • required (in pr-integration-tests.yml) and playwright-required (in pr-playwright-tests.yml) are aggregate needs: [...] + if: always() jobs over the slow integration/playwright matrices. If either is absent from gh pr checks, its matrix is still running — the PR isn't blocked. (merge-group.yml provides fast same-named jobs inside the queue itself; they only check that the PR run's verdict used a base that landed, and skip that check for Dependabot PRs, which cannot record it.)
  • mergeStateStatus/autoMergeRequest are unreliable for "is it actually queued" — query the queue directly: references/graphql-queries.md.

1. Discover the batch

bash
gh pr list --search "is:open author:app/dependabot assignee:<user>" \
  --json number,title,headRefName,mergeable,mergeStateStatus,reviewDecision,statusCheckRollup

PRs are labeled by ecosystem (dependabot:python, dependabot:javascript, dependabot:docker, dependabot:actions, plus dependabot:sandbox) and assigned per .github/dependabot.yml. Flag duplicates: two PRs bumping the same package, or a manual bump PR overlapping a bot one.

2. Triage into buckets, confirm the plan

These PRs aren't in a rush. Wait for every check to complete — required and advisory alike — and treat any red check as a failure to classify, never as noise to skip. Two advisory checks matter here even though the queue ignores them:

  • storybook-build (pr-storybook-build.yml) on web/** changes — never gates the queue, but pages Slack if broken post-merge.

  • audit (audit.yml) — runs on every lockfile, pyproject.toml, .github/workflows/**, and tools/ods/** change, so it runs on almost every Dependabot PR. Treat it as required for this skill: a Dependabot PR does not get enqueued while audit is red. A red audit means the bump either pulled in a vulnerable version or landed next to one, and merging it ships the finding.

  • Green & ready — every check completed and passing, advisory included.

  • Failing — mechanical — only a generated/lock file wasn't regenerated after the bump (see step 5 for the Onyx cases).

  • Failing — needs diagnosis — anything else; requires reading the failing job's log first, never just the check name.

  • Conflicting — real merge conflict against main.

  • Superseded — a newer PR in the batch covers it.

Independent of bucket, assess compatibility: note each PR's semver jump and whether the package is production or dev-only. Major bumps (and 0.x minors, which semver allows to break) are never covered by a blanket "enqueue the green ones" — green CI proves the build, not the behavior. Surface each one individually in the confirmation with a one-line breaking-changes summary from the release notes Dependabot embeds in the PR body, and let the user opt in per PR.

Summarize buckets and proposed actions, confirm with AskUserQuestion, then act.

3. Green: audit, approve, enqueue

Run ods audit on the PR's code before you enqueue it. CI's audit job covers this, but it is skipped when the PR touches no audited path, and it is advisory in the queue — so confirm it yourself for every Dependabot PR.

bash
gh pr checkout <pr>
source .venv/bin/activate   # ods ships in the repo venv
ods audit --fail-on=critical

ods audit scans bun.lock and uv.lock plus open Dependabot alerts, and exits non-zero on an unignored finding at or above --fail-on (tools/ods/README.md). It reads the working tree, so the PR branch must be checked out — a run on main says nothing about the bump.

If it exits non-zero, STOP. Don't enqueue and don't try to work out whether the finding came from this bump or was already on main. Report the advisory ids and let the user say how to proceed.

Then, once clean:

bash
gh pr review <pr> --approve
gh pr merge <pr> --auto

If a PR falls out of the queue (e.g. head_ref_force_pushed after a Dependabot rebase), re-running gh pr merge <pr> --auto is routine, not a failure.

Show full SKILL.md (369 more words)Show less

4. Superseded: comment which PR supersedes it, then gh pr close

5. Mechanical: fix in an isolated worktree

Once the bucket is approved, individual stale-generated-file fixes don't need per-PR confirmation. Known Onyx cases:

  • uv bumps (dependabot:python): the exported backend/requirements/*.txt files go stale when only pyproject.toml/uv.lock were bumped. Regenerate via the same pre-commit hooks CI uses:
    bash
    pre-commit run --files pyproject.toml uv.lock backend/requirements/*.txt
  • bun bumps (dependabot:javascript): stale bun.lock — run bun install in the bumped directory (repo root or web/).

Getting the branch: prefer the harness's isolated-worktree feature if it has one (Claude Code: EnterWorktree). Otherwise, if the current checkout is clean, work in place — gh pr checkout <pr>, fix, push, and return to the previous branch. If neither applies (e.g. dirty checkout), ask the user where to resolve (AskUserQuestion) rather than picking a spot — and steer away from tmpfs paths like /tmp, which can hit "Disk quota exceeded" mid-post-checkout hook (uv sync/bun install) even when they look roomy.

6. Needs diagnosis: read the failing job's log, then classify

  • Pre-existing — the same job also fails on main's current HEAD (references/graphql-queries.md). Not this PR's problem; leave it and say so.
  • External flake (rate limit, transient network, shared infra) — confirm from the log, rerun once (gh run rerun <runId> --failed). If the same failure recurs, stop and ask — a persisting "flake" may not be one.
  • Real regression from the bump — diagnose the root cause, then ask whether to fix or leave it. Never patch unrelated source just to force CI green.

7. Conflicts

  • Untouched Dependabot branch: comment @dependabot rebase (or recreate) — Dependabot owns the branch and will redo it properly.
  • Branch we already pushed fixes to: @dependabot rebase discards non-Dependabot commits. Instead rebase onto origin/main yourself, rerun the step 5 regeneration if lockfiles conflicted, push with --force-with-lease, and verify git diff origin/main...HEAD --stat still shows only the intended bump. If a pre-push hook trips on a stale local cache (e.g. dev type-gen referencing a file deleted upstream), clear the cache and retry — don't skip the hook.

8. Track to completion

Prefer one polling loop (e.g. Monitor) over repeated manual checks: watch both queue state and PR state (MERGED/CLOSED), and surface new failures as they appear rather than staying silent until success.

9. Report

Merged (N): #A, #B, #C
Closed as superseded (N): #D (superseded by #E)
Left for you (N): #F — <specific unresolved reason>

© onyx-dot-app, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/merge-dependabot-prs of onyx-dot-app/onyx.

  • SKILL.md
  • references/graphql-queries.md

Open the folder on GitHubat commit ab2e6bb

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in onyx-dot-app/onyx, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Merge Dependabot PRs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Merge Dependabot PRs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Merge Dependabot PRs this skillonyx-dot-app/onyx32k1 repos~2.2kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0
OpenROAD Issue TriageThe-OpenROAD-Project/OpenROAD3.2k—~842Automated safety check: PassBSD-3-Clause
LangBot Environment Setuplangbot-app/LangBot18k—~496Automated safety check: NotesApache-2.0
Deps Bumplkmeta/txtify135—~585Automated safety check: PassApache-2.0
Debug Sessionai-dynamo/dynamo8.3k—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • OpenROAD Issue Triage

    The-OpenROAD-Project/OpenROAD

    Reproduces an OpenROAD GitHub bug from an attached tarball and shrinks the failing design with whittle.py so maintainers get a minimal test case.

    3.2k GitHub stars~842 tokensUpdated today
    DevelopmentAuto-check passed
  • LangBot Environment Setup

    langbot-app/LangBot

    Prepares a LangBot development and testing environment for an agent, covering service startup, proxy settings and browser access through Computer Use or Playwright MCP.

    18k GitHub stars~496 tokensUpdated today
    DevelopmentAuto-check: notes
  • Deps Bump

    lkmeta/txtify

    Safely update Txtify dependencies or resolve Dependabot alerts.

    135 GitHub stars~585 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Debug Session

    ai-dynamo/dynamo

    Sets up a structured debugging session for a Dynamo bug — pull the report from a Linear ticket, GitHub issue, or pasted text, capture the environment, create a persistent worklog markdown file, and…

    8.3k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Clawsec Scanner

    LeoYeAI/openclaw-master-skills

    Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from onyx-dot-app/onyx

All 9 skills in this repo
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    Auto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Image Generation

    onyx-dot-app/onyx

    Generate or edit raster images (photos, illustrations, textures, sprites, mockups, logos, infographics) using the workspace's configured image-generation provider via onyx-cli image.

    32k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • Onyx CLI

    onyx-dot-app/onyx

    Query the Onyx knowledge base using the onyx-cli command. An agent skill from onyx-dot-app/onyx.

    32k GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Playwright E2E Tests

    onyx-dot-app/onyx

    Write and maintain Playwright end-to-end tests for the Onyx application.

    32k GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check: notes
  • Browser

    onyx-dot-app/onyx

    Core browser usage guide. An agent skill from onyx-dot-app/onyx.

    32k GitHub starsUsed in 1 repo~21k tokens
    Auto-check: warnings

Questions about Merge Dependabot PRs

What does Merge Dependabot PRs do?

Triages and lands a batch of open Dependabot PRs in the Onyx repo, where main is gated exclusively by GitHub's merge queue: approves and enqueues green PRs, closes superseded duplicates, fixes…. Merge Dependabot PRs is an agent skill from onyx-dot-app/onyx.lock), tells real regressions apart from pre-existing breakage and flakes, and tracks every PR through to merge.

When should I use Merge Dependabot PRs?

Merge Dependabot PRs fits situations like: the user asks to merge; land Dependabot (or similar bot-authored) PRs.

How do I install Merge Dependabot PRs in Claude Code?

Run `npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a claude-code`. Or copy the skill folder (.agents/skills/merge-dependabot-prs in onyx-dot-app/onyx) into .claude/skills/merge-dependabot-prs in your project. Claude Code loads it when a task matches its description.

How do I install Merge Dependabot PRs in Codex?

Run `npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a codex`. Or copy the skill folder (.agents/skills/merge-dependabot-prs in onyx-dot-app/onyx) into .agents/skills/merge-dependabot-prs in your project. Codex loads it when a task matches its description.

Can I use Merge Dependabot PRs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add onyx-dot-app/onyx --skill merge-dependabot-prs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/merge-dependabot-prs, .gemini/skills/merge-dependabot-prs, .github/skills/merge-dependabot-prs and .opencode/skills/merge-dependabot-prs in your project.

What does Merge Dependabot PRs need to run?

Going by SKILL.md and its folder, Merge Dependabot PRs needs the command-line tools its instructions call (gh, bun, jest, uv and git). Our summary lists: Docker. Its frontmatter pre-approves these tools: Bash(gh:*), Bash(git:*), Bash(pre-commit:*), Bash(bun install:*), Bash(ods audit:*). Compatibility (from SKILL.md): Requires git, pre-commit, uv, bun, ods (the repo venv's devtools script), and gh (GitHub CLI) authenticated with write access to onyx-dot-app/onyx..

Does Merge Dependabot PRs access the network?

SKILL.md contains no URLs. Its commands use gh, uv and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Merge Dependabot PRs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Merge Dependabot PRs use?

Merge Dependabot PRs is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Merge Dependabot PRs use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 317 tokens, read only when the agent opens those files.

What are the alternatives to Merge Dependabot PRs?

Skills that share tags, products or a category with Merge Dependabot PRs: Update V8 Version (openinterpreter/openinterpreter, 69k stars), OpenROAD Issue Triage (The-OpenROAD-Project/OpenROAD, 3.2k stars), LangBot Environment Setup (langbot-app/LangBot, 18k stars) and Deps Bump (lkmeta/txtify, 135 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Merge Dependabot PRs?

onyx-dot-app (a GitHub organization) maintains it in onyx-dot-app/onyx, which has 32,381 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.

Source: onyx-dot-app/onyx on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.