Agent skill

Dependabot Consolidation

by sillsdev in sillsdev/FieldWorks

Combine several open Dependabot pull requests into a single branch and PR: enumerate the open Dependabot PRs, cherry-pick them onto fresh main, rewrite commit messages to satisfy…

Custom licenceAuto-check passedDevelopment

Install Dependabot Consolidation

skills CLI
$ npx skills add sillsdev/FieldWorks --skill dependabot-consolidation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sillsdev/FieldWorks dependabot-consolidation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sillsdev/FieldWorks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dependabot-consolidation .claude/skills/dependabot-consolidation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot-consolidation
GitHub stars
110
Token cost
~3.5k tokens
SKILL.md length
1,684 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
Custom licence

At a glance

Combine several open Dependabot pull requests into a single branch and PR: enumerate the open Dependabot PRs, cherry-pick them onto fresh main, rewrite commit messages to satisfy…

  • Works in 7 steps: Enumerate → Gate 1: the plan → Construct the branch → …
  • Asked to combine
  • SKILL.md covers Three gates, Step 1 - Enumerate, Step 2 - Gate 1: the plan and Step 3 - Construct the branch, plus 5 more sections
  • Calls git and gh; needs CODECOV_TOKEN

What it does

Dependabot Consolidation is an agent skill from sillsdev/FieldWorks. Combine several open Dependabot pull requests into a single branch and PR: enumerate the open Dependabot PRs, cherry-pick them onto fresh main, rewrite commit messages to satisfy .github/commit-guidelines.md, verify locally, push, open the combined PR, wait for CI, and close the superseded PRs once it is green. Use when asked to combine, consolidate, batch, roll up, or squash together existing Dependabot PRs.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management and Pull requests. It works with GitHub and Git. The repository describes itself as: FieldWorks is a suite of software tools for language and cultural data, with support for complex scripts.

When your agent uses it

  • Asked to combine
  • Squash together existing Dependabot PRs

Example prompts

  • “/dependabot-consolidation”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Enumerate
  2. Gate 1: the plan
  3. Construct the branch
  4. Verify locally
  5. Gate 2: push and open
  6. Wait for CI
  7. Gate 3: close the superseded PRs

What it can do on your machine

Read from SKILL.md and the folder at commit 489ed1b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CODECOV_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot Consolidation loads about 3.5k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 1,684 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,684 words (~3,518 tokens).

“Turn several open Dependabot pull requests into one reviewable pull request, so the repository pays for one CI cycle instead of one per bump. In scope: open PRs authored by app/dependabot against one base. Out of scope: human-authored dependency PRs…”

— opening of SKILL.md by sillsdev, Custom licence
name
dependabot-consolidation
argument-hint
Optional PR numbers to combine, e.g. 1035 1036 1037

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/dependabot-consolidation of sillsdev/FieldWorks.

Open the folder on GitHubat commit 489ed1b

Compare with similar skills

Dependabot Consolidation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot Consolidation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot Consolidation this skillsillsdev/FieldWorks110—~3.5kAutomated safety check: PassCustom licence
Apply Renovate PRssivaprasadreddy/sivalabs-agent-skills188—~3kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Pull Request Title and Body Writeropeninterpreter/openinterpreter69k2 repos~1.1kAutomated safety check: PassApache-2.0
PR Review State Fetchprisma/orm48k—~767Automated safety check: PassApache-2.0

Similar skills

  • Apply Renovate PRs

    sivaprasadreddy/sivalabs-agent-skills

    Apply the changes from all open Renovate bot pull requests of a GitHub repository into the local working tree.

    188 GitHub stars~3k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Fetches a pull request's canonical review state as JSON, validates it, and renders markdown, a text summary and triage target files from it using bundled scripts.

    48k GitHub stars~767 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Official

    Generate a clear, concise GitHub PR title and description from the diff between two local git branches, and save it to prDescription.md in the repo root.

    12k GitHub stars~838 tokensUpdated yesterday
    DevelopmentAuto-check passed

More from sillsdev/FieldWorks

All 29 skills in this repo
  • Atlassian Readonly Skills

    sillsdev/FieldWorks

    Read-only Python utilities for Jira (SIL Data Center): fetch an issue, search with JQL, read transitions, links, worklogs, agile boards and projects.

    110 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Atlassian Skills

    sillsdev/FieldWorks

    Python utilities for Jira (SIL Data Center) covering issue management, JQL search, workflows and transitions, links, agile boards, worklogs and projects.

    110 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Fieldworks Winapp

    sillsdev/FieldWorks

    Control and document the FieldWorks desktop application with WinForms MCP or WinApp MCP.

    110 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Convert Slice

    sillsdev/FieldWorks

    Drive the conversion of one legacy slice type to the Avalonia detail view through analysis, developer alignment, integration-test planning, route/exemplar mapping, design, and scaffold/implement.

    110 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Capture or review FieldWorks parity evidence: semantic snapshots, render/visual baselines, layout parity, failure artifacts, XML view definitions, and the Avalonia presentation IR.

    110 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Design or review FieldWorks UI automation and accessibility tests: UIA2, FlaUI, Appium, WinAppDriver, Avalonia.Headless, keyboard, focus, IME, and automation-id strategy.

    110 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Dependabot Consolidation

What does Dependabot Consolidation do?

Combine several open Dependabot pull requests into a single branch and PR: enumerate the open Dependabot PRs, cherry-pick them onto fresh main, rewrite commit messages to satisfy…. Dependabot Consolidation is an agent skill from sillsdev/FieldWorks.md, verify locally, push, open the combined PR, wait for CI, and close the superseded PRs once it is green.

When should I use Dependabot Consolidation?

Dependabot Consolidation fits situations like: asked to combine; squash together existing Dependabot PRs.

How do I install Dependabot Consolidation in Claude Code?

Run `npx skills add sillsdev/FieldWorks --skill dependabot-consolidation -a claude-code`. Or copy the skill folder (.claude/skills/dependabot-consolidation in sillsdev/FieldWorks) into .claude/skills/dependabot-consolidation in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot Consolidation in Codex?

Run `npx skills add sillsdev/FieldWorks --skill dependabot-consolidation -a codex`. Or copy the skill folder (.claude/skills/dependabot-consolidation in sillsdev/FieldWorks) into .agents/skills/dependabot-consolidation in your project. Codex loads it when a task matches its description.

Can I use Dependabot Consolidation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sillsdev/FieldWorks --skill dependabot-consolidation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-consolidation, .gemini/skills/dependabot-consolidation, .github/skills/dependabot-consolidation and .opencode/skills/dependabot-consolidation in your project.

What does Dependabot Consolidation need to run?

Going by SKILL.md and its folder, Dependabot Consolidation needs the command-line tools its instructions call (git and gh) and credentials named CODECOV_TOKEN.

Does Dependabot Consolidation access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependabot Consolidation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependabot Consolidation use?

Dependabot Consolidation has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Dependabot Consolidation use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot Consolidation?

Skills that share tags, products or a category with Dependabot Consolidation: Apply Renovate PRs (sivaprasadreddy/sivalabs-agent-skills, 188 stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Create Pull Request (cline/cline, 70k stars) and Pull Request Title and Body Writer (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot Consolidation?

sillsdev (a GitHub organization) maintains it in sillsdev/FieldWorks, which has 110 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 7, 2026.

Source: sillsdev/FieldWorks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.