Agent skill

Pc CI Dependency Bot

by partcad in partcad/partcad

Sweep the open dependency-bot pull requests once - rebase the stale ones, re-trigger infrastructure failures, and merge the green patch and minor updates.

Apache-2.0Auto-check passedDevelopment

Install Pc CI Dependency Bot

skills CLI
$ npx skills add partcad/partcad --skill pc-ci-dependency-bot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install partcad/partcad pc-ci-dependency-bot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/partcad/partcad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pc-ci-dependency-bot .claude/skills/pc-ci-dependency-bot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pc-ci-dependency-bot
GitHub stars
503
Token cost
~1.9k tokens
SKILL.md length
870 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Sweep the open dependency-bot pull requests once - rebase the stale ones, re-trigger infrastructure failures, and merge the green patch and minor updates.

  • Works in 6 steps: Select the repository → List the open bot pull requests → Bring the pull request up to date first → …
  • Infrastructure failures
  • SKILL.md covers Steps, Output and Guardrails
  • Calls gh and git

What it does

Pc CI Dependency Bot is an agent skill from partcad/partcad. Sweep the open dependency-bot pull requests once - rebase the stale ones, re-trigger infrastructure failures, and merge the green patch and minor updates. Use when the user wants to baby sit, unblock, or push through pending dependabot pull requests, and on each firing of a /loop that watches them.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires GitHub CLI (gh), authenticated with merge rights on the target repository.

It sits in Development, covering Pull requests and Dependency management. It works with GitHub. The repository describes itself as: Package manager for things. Start designing modular hardware! PartCAD is the standard for documenting manufacturable physical products (a.k.a. Digital Thread or TDP). It comes… The licence is Apache-2.0.

When your agent uses it

  • Infrastructure failures
  • Merge the green patch and minor updates
  • The user wants to baby sit
  • Push through pending dependabot pull requests

Example prompts

  • “/pc-ci-dependency-bot”

Requirements

  • Compatibility (from SKILL.md): Requires GitHub CLI (`gh`), authenticated with merge rights on the target repository.
  • Pre-approved tools (allowed-tools): Bash(gh:*), Bash(git:*), AskUserQuestion

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Select the repository
  2. List the open bot pull requests
  3. Bring the pull request up to date first
  4. Read the check status
  5. Triage the failures
  6. Merge what is in scope

What it can do on your machine

Read from SKILL.md and the folder at commit e08683a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(gh:*)
    • Bash(git:*)
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires GitHub CLI (`gh`), authenticated with merge rights on the target repository.

    From compatibility in the SKILL.md frontmatter.

Context cost

Pc CI Dependency Bot loads about 1.9k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 870 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from partcad/partcad at commit e08683a, republished under its Apache-2.0 licence (© partcad). 870 words, ~1,875 tokens.

Download SKILL.mdSave it as .claude/skills/pc-ci-dependency-bot/SKILL.md (or your agent's skills folder).
name
pc-ci-dependency-bot
description
Sweep the open dependency-bot pull requests once - rebase the stale ones, re-trigger infrastructure failures, and merge the green patch and minor updates. Use when the user wants to baby sit, unblock, or push through pending dependabot pull requests, and on each firing of a /loop that watches them.
allowed-tools
Bash(gh:*), Bash(git:*), AskUserQuestion
compatibility
Requires GitHub CLI (`gh`), authenticated with merge rights on the target repository.
license
Apache 2.0
metadata.author
partcad
metadata.version
2.0

Sweep the open dependency-bot pull requests once: rebase the stale ones, re-trigger infrastructure failures, and merge the ones that are green and in scope.

This skill performs a single pass and exits. It never sleeps and never loops internally. To baby sit continuously, drive it from the loop skill:

/loop 1h pc-ci-dependency-bot

Each firing is a fresh session with no memory of the last one, so every piece of state this skill relies on is re-read from the GitHub API rather than carried in context.

Scope: GitHub only. The triage below is built on gh and on dependabot's comment commands. GitLab and Gerrit are not supported — stop and say so rather than improvising an equivalent.

Input: Optionally a repository (URL or OWNER/NAME). Defaults to the current working directory's repository.

Steps

1. Select the repository

If the user named a repository, use it. Otherwise infer it from the conversation, then fall back to git remote get-url origin. If it is still ambiguous, ask with the AskUserQuestion tool.

Announce the choice and how to change it:

Using upstream: <owner/name> — re-run with `pc-ci-dependency-bot <owner/name>` to target another repository.

Pass the repository explicitly on every gh call (--repo <owner/name>) so the skill behaves identically inside and outside a checkout.

2. List the open bot pull requests
bash
gh pr list --repo <owner/name> --state open --author "app/dependabot" \
  --json number,title,url,headRefName,mergeStateStatus,labels

If the list is empty, report "No open dependency-bot pull requests" and exit. Do not wait — the next /loop firing is the wait.

Note that this repository configures dependabot for github-actions on a monthly interval (.github/dependabot.yml), so most passes will find nothing. That is the expected outcome, not a failure.

Then handle each pull request with steps 3–6. A pull request that gets an action in step 3 is done for this pass; move to the next one.

3. Bring the pull request up to date first

CI results from before a base-branch move describe a merge that no longer exists, so settle freshness before reading any logs.

Read mergeStateStatus from step 2:

  • BEHIND — the branch is out of date. Ask dependabot to rebase and move on to the next pull request; the new runs are evaluated on a later pass:

    bash
    gh pr comment <number> --repo <owner/name> --body "@dependabot rebase"

    Do not re-comment if the most recent comment on the pull request is already an unactioned @dependabot rebase — check with gh pr view <number> --repo <owner/name> --json comments. Dependabot queues these, and repeating the request hourly spams the thread without changing anything.

  • DIRTY — the branch conflicts with the base. Dependabot cannot rebase through a conflict. Report it under "Needs attention" and move on.

  • BLOCKED — a required review or check is missing, or branch protection is unsatisfied. Continue to step 4; the merge in step 6 will surface the real reason.

  • CLEAN, UNSTABLE, HAS_HOOKS — up to date. Continue to step 4.

4. Read the check status
bash
gh pr checks <number> --repo <owner/name> --json name,state,bucket,link

The bucket field categorises each check as pass, fail, pending, skipping, or cancel.

  • Any check in pending — the pull request is still building. Skip it this pass and report it as pending.
  • All checks in pass or skipping — go to step 6.
  • Any check in fail or cancel — go to step 5.
Show full SKILL.md (389 more words)Show less
5. Triage the failures

For each failing check, read enough of the log to classify it:

bash
gh run view <run-id> --repo <owner/name> --log-failed

Re-trigger only failures that are not caused by the pull request — network timeouts, runner eviction, registry rate limits, corrupted package downloads and similar infrastructure noise. Compile errors, test assertions and lint violations are caused by the change: leave them, and report the pull request under "Needs attention".

Before re-triggering, check how many attempts the run has already had. The attempt counter lives in the API, which is what makes it survive across /loop firings:

bash
gh run list --repo <owner/name> --branch <headRefName> \
  --json databaseId,workflowName,conclusion,status,attempt

attempt is 1 for a run that has never been re-triggered. Re-trigger at most 3 times — if attempt >= 4, stop re-triggering that run and report the pull request under "Needs attention" instead. A failure that survives three re-runs is not flaky, whatever the log looks like.

bash
gh run rerun <run-id> --repo <owner/name> --failed

A re-trigger completes this pull request for this pass; the result is evaluated on a later firing.

6. Merge what is in scope

Only reached when every check passes.

Check the version jump before merging. Dependabot titles carry it, in the form bump <dependency> from <old> to <new>. Compare the leading numeric component:

  • Patch or minor bump — approve and merge:

    bash
    gh pr review <number> --repo <owner/name> --approve
    gh pr merge <number> --repo <owner/name> --squash
  • Major bump (leading component differs, e.g. from 4 to 8) — do not merge. Green CI does not prove a major bump is safe; it proves the parts covered by CI still run. Report it under "Needs attention" with the old and new versions and let a human decide.

  • Version unparseable from the title — treat it as a major bump and report it.

If the merge is rejected (branch protection, required reviewers, a merge queue), report the error verbatim rather than working around it.

Output

Report every pull request examined, then exit.

Using upstream: <owner/name> — re-run with `pc-ci-dependency-bot <owner/name>` to target another repository.

## PR #<number> — <title>
<what was found and what was done>
✓ <Merged | Rebase requested | Re-triggered (attempt N of 3) | Pending>

## PR #<number> — <title>
<what was found and what was done>
✓ <action>

---
Swept N pull requests: <x> merged, <y> awaiting CI, <z> need attention.

If any pull request needs a human:

## Needs attention

**PR:** #<number> — <title>
**URL:** <url>

### Issue
<what is blocking it: conflict, real test failure, exhausted retries, or major version bump>

**Options:**
1. <option 1>
2. <option 2>
3. Other approach

End the pass there. Do not ask a blocking question and do not wait for an answer — a /loop firing has no one to answer it. Report the options and exit; the user acts between firings.

Guardrails

  • One pass per invocation. Never sleep, never restart from step 1.
  • Never re-trigger a run that is already on its 4th attempt.
  • Never re-trigger a failure the pull request actually caused.
  • Report blockers and exit rather than guessing or working around branch protection.

© partcad, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/pc-ci-dependency-bot of partcad/partcad.

Open the folder on GitHubat commit e08683a

Compare with similar skills

Pc CI Dependency Bot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pc CI Dependency Bot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pc CI Dependency Bot this skillpartcad/partcad503—~1.9kAutomated safety check: PassApache-2.0
Renovate Actions PR Reviewbacknotprop/plannotator9.2k—~640Automated safety check: PassApache-2.0
Bump CLI Compatibility Manifestdatabricks/cli404—~1.3kAutomated safety check: NotesCustom licence
Apply Renovate PRssivaprasadreddy/sivalabs-agent-skills188—~3kAutomated safety check: PassMIT
Dependabot Consolidationsillsdev/FieldWorks110—~3.5kAutomated safety check: PassCustom licence
Security Vulnerabilities Patcheraxelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0

Similar skills

  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.2k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Updates the Databricks CLI's cli-compat.json with new AppKit and Agent Skills versions and opens a pull request for the change.

    404 GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check: notes
  • Apply Renovate PRs

    sivaprasadreddy/sivalabs-agent-skills

    Apply the changes from all open Renovate bot pull requests of a GitHub repository into the local working tree.

    188 GitHub stars~3k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Dependabot Consolidation

    sillsdev/FieldWorks

    Combine several open Dependabot pull requests into a single branch and PR: enumerate the open Dependabot PRs, cherry-pick them onto fresh main, rewrite commit messages to satisfy…

    110 GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    148 GitHub stars~4.2k tokensUpdated today
    SecurityAuto-check passed
  • Performing Sca Dependency Scanning With Snyk

    mukul975/Anthropic-Cybersecurity-Skills

    This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines.

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from partcad/partcad

All 12 skills in this repo
  • Add Interfaces

    partcad/partcad

    Enrich an existing PartCAD part with connection interfaces and ports (mating metadata) so it can be mated to other parts automatically.

    503 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Convert

    partcad/partcad

    Convert a CAD file or a PartCAD object to another geometry format - STEP, BREP, STL, 3MF, OBJ, IGES, glTF, three.js, SVG, DXF, URDF, ASSY - with pc convert for an object a package declares (which…

    503 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Describe

    partcad/partcad

    Write a narratable, accessibility-oriented text description of an existing PartCAD part, assembly, or sketch from its measured bounding box and volume, from renders taken at several viewing angles…

    503 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Export

    partcad/partcad

    Write a CAD file out of an object a PartCAD package declares - STEP, BREP, STL, 3MF, OBJ, IGES, glTF, three.js, URDF for 3D, SVG or DXF for a sketch, or a file type the package implements itself -…

    503 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Gen Part

    partcad/partcad

    Generate a PartCAD part from a natural-language description (and optional reference images/requirements) by authoring a CAD script and validating it with the PartCAD CLI.

    503 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Gen Sketch

    partcad/partcad

    Generate a PartCAD 2D sketch from a natural-language description by authoring the sketch (build123d / cadquery / dxf / svg / basic) and validating it with the PartCAD CLI.

    503 GitHub stars~672 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Pc CI Dependency Bot

What does Pc CI Dependency Bot do?

Sweep the open dependency-bot pull requests once - rebase the stale ones, re-trigger infrastructure failures, and merge the green patch and minor updates. Pc CI Dependency Bot is an agent skill from partcad/partcad. Sweep the open dependency-bot pull requests once - rebase the stale ones, re-trigger infrastructure failures, and merge the green patch and minor updates.

When should I use Pc CI Dependency Bot?

Pc CI Dependency Bot fits situations like: infrastructure failures; merge the green patch and minor updates; the user wants to baby sit; push through pending dependabot pull requests.

How do I install Pc CI Dependency Bot in Claude Code?

Run `npx skills add partcad/partcad --skill pc-ci-dependency-bot -a claude-code`. Or copy the skill folder (.claude/skills/pc-ci-dependency-bot in partcad/partcad) into .claude/skills/pc-ci-dependency-bot in your project. Claude Code loads it when a task matches its description.

How do I install Pc CI Dependency Bot in Codex?

Run `npx skills add partcad/partcad --skill pc-ci-dependency-bot -a codex`. Or copy the skill folder (.claude/skills/pc-ci-dependency-bot in partcad/partcad) into .agents/skills/pc-ci-dependency-bot in your project. Codex loads it when a task matches its description.

Can I use Pc CI Dependency Bot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add partcad/partcad --skill pc-ci-dependency-bot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pc-ci-dependency-bot, .gemini/skills/pc-ci-dependency-bot, .github/skills/pc-ci-dependency-bot and .opencode/skills/pc-ci-dependency-bot in your project.

What does Pc CI Dependency Bot need to run?

Going by SKILL.md and its folder, Pc CI Dependency Bot needs the command-line tools its instructions call (gh and git). Its frontmatter pre-approves these tools: Bash(gh:*), Bash(git:*), AskUserQuestion. Compatibility (from SKILL.md): Requires GitHub CLI (`gh`), authenticated with merge rights on the target repository..

Does Pc CI Dependency Bot access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pc CI Dependency Bot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pc CI Dependency Bot use?

Pc CI Dependency Bot is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pc CI Dependency Bot use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pc CI Dependency Bot?

Skills that share tags, products or a category with Pc CI Dependency Bot: Renovate Actions PR Review (backnotprop/plannotator, 9.2k stars), Bump CLI Compatibility Manifest (databricks/cli, 404 stars), Apply Renovate PRs (sivaprasadreddy/sivalabs-agent-skills, 188 stars) and Dependabot Consolidation (sillsdev/FieldWorks, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pc CI Dependency Bot?

partcad (a GitHub organization) maintains it in partcad/partcad, which has 503 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 8, 2026.

Source: partcad/partcad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.