Official agent skill

Fix Dependabot

by remotion-dev in remotion-dev/remotion

Fix a Dependabot PR by updating all monorepo instances of the dependency, running bun install, and pushing

OfficialCustom licenceAuto-check passedDevelopment

Install Fix Dependabot

skills CLI
$ npx skills add remotion-dev/remotion --skill fix-dependabot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install remotion-dev/remotion fix-dependabot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/remotion-dev/remotion.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fix-dependabot .claude/skills/fix-dependabot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-dependabot
GitHub stars
62k
Token cost
~509 tokens
SKILL.md length
245 words
Files
1
Skills in repo
71
Repo updated
First seen
Licence
Custom licence

At a glance

Fix a Dependabot PR by updating all monorepo instances of the dependency, running bun install, and pushing

  • Works in 3 steps: Get PR info — Use gh pr view --json… → Checkout the branch → Update all monorepo instances —…
  • Tasks that involve Dependency management
  • SKILL.md covers Steps and Notes
  • Calls git, bun and rg

What it does

Fix Dependabot is an agent skill from remotion-dev/remotion, published by the product's own GitHub organization. Fix a Dependabot PR by updating all monorepo instances of the dependency, running bun install, and pushing

Its SKILL.md is about 510 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management and Monorepo tooling. It works with Bun and npm. The repository describes itself as: 🎥 Make videos programmatically with React.

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Monorepo tooling

Example prompts

  • “/fix-dependabot”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Get PR info — Use gh pr view --json headRefName,files,title,body to identify the branch name, which dependency was bumped, and the old/new…
  2. Checkout the branch
  3. Update all monorepo instances — Dependabot only touches one package. Search for all other package.json files that reference the same…

What it can do on your machine

Read from SKILL.md and the folder at commit 1e4c5de. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • bun
    • rg
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Dependabot loads about 509 tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 245 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~509

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 245 words (~509 tokens).

“Dependabot PRs only update one package.json and never run bun install, so the bun.lock file is out of date and other packages in the monorepo still reference the old version. This skill fixes both problems.”

— opening of SKILL.md by remotion-dev, Custom licence
name
fix-dependabot

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/fix-dependabot of remotion-dev/remotion.

Open the folder on GitHubat commit 1e4c5de

Compare with similar skills

Fix Dependabot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Dependabot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Dependabot this skillremotion-dev/remotion62k—~509Automated safety check: PassCustom licence
Monorepo Tooling and Dependenciespierrecomputer/pierre6.2k—~1.1kAutomated safety check: PassApache-2.0
Bun Runtimespinspire/pocketbase-sveltekit-starter5115 repos~653Automated safety check: NotesMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Bun 1.4 Builtins Guidecode-yeongyu/senpi470—~1.3kAutomated safety check: PassMIT

Similar skills

  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.2k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Bun Runtime

    spinspire/pocketbase-sveltekit-starter

    Bun as runtime, package manager, bundler, and test runner. An agent skill from spinspire/pocketbase-sveltekit-starter.

    511 GitHub starsUsed in 5 repos~653 tokens
    DevelopmentAuto-check: notes
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • Bun 1.4 Builtins Guide

    code-yeongyu/senpi

    Points the agent at Bun 1.4 built-in APIs before it installs an npm package, so image, browser, markdown, cron, PTY and test work uses what Bun already ships.

    470 GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Bun Runtime and Toolkit

    mweinbach/agent-coworker

    Quick reference for using Bun to run TypeScript and JavaScript, install packages, bundle code, run tests and serve HTTP, with the key files and commands.

    156 GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check: notes

More from remotion-dev/remotion

All 71 skills in this repo
  • Gh Stack

    remotion-dev/remotion

    Official

    Manages stacked PRs and splits multi-part work into reviewable branches with gh-stack.

    62k GitHub starsUsed in 6 repos~2.4k tokens
    Auto-check passed
  • Canvas Capture Extension

    remotion-dev/remotion

    Official

    Rebuild, install, and reload the private Remotion Canvas Capture unpacked Chrome extension.

    62k GitHub stars~868 tokensUpdated today
    Auto-check passed
  • Nullable New Params

    remotion-dev/remotion

    Official

    Fix newly added optional parameters, optional React props, and optional type/interface members in Remotion monorepo diffs by converting internal APIs to required nullable values and updating call…

    62k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Vercel

    remotion-dev/remotion

    Official

    Set up a Codex monitor for Vercel deployments and preview URLs.

    62k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Writing Docs

    remotion-dev/remotion

    Official

    Guides for writing and editing Remotion documentation. An agent skill from remotion-dev/remotion.

    62k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Find Unplanned Issues

    remotion-dev/remotion

    Official

    Audit and clean the Remotion GitHub masterplan hierarchy. An agent skill from remotion-dev/remotion.

    62k GitHub stars~673 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Fix Dependabot

What does Fix Dependabot do?

Fix a Dependabot PR by updating all monorepo instances of the dependency, running bun install, and pushing. Fix Dependabot is an agent skill from remotion-dev/remotion, published by the product's own GitHub organization.

When should I use Fix Dependabot?

Fix Dependabot fits situations like: tasks that involve Dependency management; tasks that involve Monorepo tooling.

How do I install Fix Dependabot in Claude Code?

Run `npx skills add remotion-dev/remotion --skill fix-dependabot -a claude-code`. Or copy the skill folder (.agents/skills/fix-dependabot in remotion-dev/remotion) into .claude/skills/fix-dependabot in your project. Claude Code loads it when a task matches its description.

How do I install Fix Dependabot in Codex?

Run `npx skills add remotion-dev/remotion --skill fix-dependabot -a codex`. Or copy the skill folder (.agents/skills/fix-dependabot in remotion-dev/remotion) into .agents/skills/fix-dependabot in your project. Codex loads it when a task matches its description.

Can I use Fix Dependabot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add remotion-dev/remotion --skill fix-dependabot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-dependabot, .gemini/skills/fix-dependabot, .github/skills/fix-dependabot and .opencode/skills/fix-dependabot in your project.

What does Fix Dependabot need to run?

Going by SKILL.md and its folder, Fix Dependabot needs the command-line tools its instructions call (git, bun, rg and gh).

Does Fix Dependabot access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Fix Dependabot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fix Dependabot use?

Fix Dependabot has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Fix Dependabot use?

About 509 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Dependabot?

Skills that share tags, products or a category with Fix Dependabot: Monorepo Tooling and Dependencies (pierrecomputer/pierre, 6.2k stars), Bun Runtime (spinspire/pocketbase-sveltekit-starter, 511 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Dependabot Alerts Update (livesession/xyd, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Dependabot?

remotion-dev (a GitHub organization, an official publisher) maintains it in remotion-dev/remotion, which has 62,235 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on October 7, 2026.

Source: remotion-dev/remotion on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.