Validator Dependency Upgrade
express-validator/express-validator
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
Reviews Dependabot gem upgrade PRs for breaking changes, codebase impact, and merge readiness.
$ npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ThibautBaissac/rails_ai_agents dependabot-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependabot-review .claude/skills/dependabot-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependabot-review" agent skill from https://github.com/ThibautBaissac/rails_ai_agents/tree/main/.agents/skills/dependabot-review into .claude/skills/dependabot-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ThibautBaissac/rails_ai_agents/tree/main/.agents/skills/dependabot-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ThibautBaissac/rails_ai_agents dependabot-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dependabot-review .agents/skills/dependabot-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependabot-review" agent skill from https://github.com/ThibautBaissac/rails_ai_agents/tree/main/.agents/skills/dependabot-review into .agents/skills/dependabot-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ThibautBaissac/rails_ai_agents dependabot-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dependabot-review .cursor/skills/dependabot-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependabot-review" agent skill from https://github.com/ThibautBaissac/rails_ai_agents/tree/main/.agents/skills/dependabot-review into .cursor/skills/dependabot-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ThibautBaissac/rails_ai_agents.git --path .agents/skills/dependabot-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ThibautBaissac/rails_ai_agents dependabot-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dependabot-review .gemini/skills/dependabot-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependabot-review" agent skill from https://github.com/ThibautBaissac/rails_ai_agents/tree/main/.agents/skills/dependabot-review into .gemini/skills/dependabot-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ThibautBaissac/rails_ai_agents dependabot-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dependabot-review .github/skills/dependabot-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-review" agent skill from https://github.com/ThibautBaissac/rails_ai_agents/tree/main/.agents/skills/dependabot-review into .github/skills/dependabot-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ThibautBaissac/rails_ai_agents dependabot-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dependabot-review .opencode/skills/dependabot-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependabot-review" agent skill from https://github.com/ThibautBaissac/rails_ai_agents/tree/main/.agents/skills/dependabot-review into .opencode/skills/dependabot-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependabot-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependabot-reviewReviews Dependabot gem upgrade PRs for breaking changes, codebase impact, and merge readiness.
Dependabot Review is an agent skill from ThibautBaissac/rails_ai_agents. Reviews Dependabot gem upgrade PRs for breaking changes, codebase impact, and merge readiness. Use when user pastes a Dependabot PR URL, asks about a gem version bump, or wants to audit open dependency PRs ("which dep PRs are safe to merge", "audit our deps", "check dependabot"). WHEN NOT: Non-Dependabot PRs, npm/yarn upgrades, or general code review.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management. It works with npm. The repository describes itself as: Specialized AI skills, agents, rules and hooks for modern Rails AI driven-development + Spec-Driven-Development kit + MCP. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 03622f2. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashWebFetchGrepGlobFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comrubygems.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependabot Review loads about 3.9k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 1,945 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Bash, WebFetch, Grep, GlobAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ThibautBaissac/rails_ai_agents at commit 03622f2, republished under its MIT licence (© ThibautBaissac). 1,945 words, ~3,881 tokens.
.claude/skills/dependabot-review/SKILL.md (or your agent's skills folder).Current repo: !gh repo view --json nameWithOwner -q .nameWithOwner 2>/dev/null || echo "(unknown — run from inside the repo)"
Review Dependabot PRs and give the developer a concise, scannable verdict: what changed upstream, what could break (and how to fix it), what each gem touches in the codebase, and whether to merge.
Trigger phrases for audit mode: "review all open dependabot PRs", "which dependabot PRs are ready to merge", "audit our dep upgrades", "go through the open dep PRs", "check dependabot", any request for a status/report on pending dependency updates. Trigger single-PR mode on any GitHub PR URL related to dependabot, gem upgrades, or "bump" in the title. If the intent is ambiguous, default to audit mode.
Pick the mode based on what the user asked for:
gh.If the intent is ambiguous (e.g., "review dependabot"), default to audit mode since it's the superset and shows what's available.
Determine the repo from the current working directory (gh repo view --json nameWithOwner -q .nameWithOwner). Then list open Dependabot PRs:
gh pr list --author "app/dependabot" --state open \
--json number,title,url,createdAt,headRefName,labels \
--limit 50The app/ prefix in the author filter is required — Dependabot authors as the bot account app/dependabot. If gh returns an empty list, tell the user "No open Dependabot PRs in <repo>." and stop.
Before diving into analysis, surface the scope to the user in one line: "Found N open Dependabot PRs. Analyzing each now…" — this sets expectations when there are many to crunch through.
For every PR returned, run the single-PR workflow (Steps 1-3 below) to gather bump type, changelog highlights, and codebase impact. Keep each analysis tight — you'll be producing per-PR sections for a combined report, not standalone documents.
You can fetch independent PRs in parallel where the tool call structure allows it.
Emit the report in this order:
<repo>."After the consolidated report, follow the shared "Posting findings to PRs" section below. For audit mode, the opt-in prompt covers the whole batch ("yes / no / selective"), and the comment body for each PR is drawn from that PR's per-PR detail section in Step A3.
The summary table is the first thing the dev reads — its job is to let them triage the whole batch in under a minute. Render it as a GitHub-flavored markdown table with these exact columns, in this order:
| Column | Contents |
|---|---|
# | PR number, linked as [#9170](url) |
Gem | Gem name. For multi-gem PRs, comma-separate (e.g., rspec-core, rspec-expectations) |
Bump | old → new (e.g., 7.2.4 → 8.0.10) |
Type | patch, minor, or major. Prefix with 🔒 if the PR addresses a security advisory |
Age | Days since createdAt (e.g., 3d, 21d) |
Verdict | Abbreviated: Merge, Verify, Investigate, Hold |
Why | One short clause (≤ 10 words). Concrete, not generic — e.g., "dev-only, no breaking changes" beats "looks safe" |
Sort order: primary key is verdict in the order Merge → Verify → Investigate → Hold (worklist-style — easy wins first, stop when you hit "Investigate"). Within each verdict bucket, sort by Age descending so the stalest PRs rise to the top of their bucket — PRs that have been rotting in the queue often hide the real merge friction.
Security exception: any row with the 🔒 marker jumps to the top of the entire table regardless of verdict bucket, because security urgency overrides the triage-by-ease ordering.
Verdict abbreviations (use these exact strings so the column stays narrow and scannable):
Merge — safe, low riskVerify — safe pending specific checks (detail lives in the per-PR section)Investigate — needs human judgmentHold — breaking changes require code work firstDo not add extra columns (branch name, author, CI status, labels). Seven is already the comfortable ceiling for terminal width, and every extra column dilutes the signal. If something doesn't fit the table, it belongs in the per-PR detail section, not here.
Parse the PR URL to extract the owner, repo, and PR number. When invoked via audit mode, these come from the gh pr list output — no parsing needed.
gh pr view <NUMBER> --repo <OWNER/REPO> --json title,body,url,files,headRefName
gh pr diff <NUMBER> --repo <OWNER/REPO>From the diff, extract for each gem being updated:
If the PR updates multiple gems, analyze them together in a combined summary with one section per gem.
This is the most important step. Developers need to know what changed and whether anything will break.
Fetch the changelog between old and new versions. Try these sources:
gh to fetch the raw changelog file from the gem's repo (usually CHANGELOG.md, Changes.md, or HISTORY.md at the repo root)https://github.com/<gem-source-repo>/releaseshttps://rubygems.org/gems/<gem-name> links to the sourcePatch/minor bumps: read the relevant version sections in full — they're short.
Major bumps: do not read the full changelog or migration guide. Large gems (Rails, Sidekiq, Devise, ActiveRecord) have thousands of lines of changelog prose that will exhaust context before you reach the codebase-impact step. Instead:
grep to extract only sections matching the version range (e.g., grep -n "^## \[" CHANGELOG.md to find section line numbers, then read only that range).The goal is a targeted list of breaking changes and deprecations, not a comprehensive retelling of everything that changed.
Organize findings by importance:
If you cannot find a changelog, say so explicitly.
Search the codebase to understand what this gem touches and what's at stake if it breaks.
:development, :test, or production).app/, lib/, config/, and spec/. Check config/initializers/ for configuration.sentry-sidekiq depends on sidekiq). Verify their version constraints are compatible by checking the Gemfile.lock diff — if Bundler resolved successfully, note that.For dev/test-only gems, note the lower risk profile (broken dev workflow vs broken customer experience).
Keep this section concise: a grouped list of affected areas, not an exhaustive file listing.
Deliver a clear, concise verdict. Consider:
| Factor | Lower Risk | Higher Risk |
|---|---|---|
| Bump type | Patch | Major |
| Usage scope | 1-2 files, dev/test only | Widespread, production |
| Feature area | Admin, dev tooling | Payments, auth, orders |
| Changelog | No breaking changes | API changes, deprecations |
| Security fix | No | Yes (merge sooner) |
Verdicts:
Do not recommend running the test suite — CI handles that. Instead, call out specific things a human should verify that tests might not catch (e.g., production Redis version, runtime behavior changes, new deprecation warnings in logs).
After presenting the review in chat, follow the shared "Posting findings to PRs" section below. In single-PR mode the prompt is a simple yes/no ("Want me to post this review as a comment on the PR?"), and the comment body is drawn from the review you just produced.
The output should be concise and scannable. Use this structure:
## Dependabot Review: `gem_name` (old_version -> new_version)
### Bump Type
[patch/minor/major] — [one line: what this means for risk]
### What Changed
[Changelog highlights organized by importance: breaking changes first (with fix suggestions), then deprecations, security fixes, and notable changes. Skip noise. If nothing notable, say "No breaking changes or deprecations."]
### Breaking Changes in This Codebase
[Only if there ARE breaking changes: list each one with the affected file and a concrete fix suggestion. If no breaking changes affect the codebase, omit this section entirely.]
### Codebase Impact
[Concise grouped list of what this gem touches: "Payments: captures charges via checkoutcom jobs", "Notifications: 12 push/email notification jobs", etc. One line per area.]
### Recommendation
[Verdict + 1-3 sentences explaining why and what to verify]For multi-gem PRs, use one top-level heading and a section per gem, then a single combined recommendation at the end.
In audit mode, each per-PR subsection uses the same structure but condensed (aim for 15-25 lines). The top-level summary table and Overall recommendation (defined in the audit workflow) replace the single-PR verdict block.
This section applies to both single-PR mode (Step 5) and audit mode (Step A4). Always run it — producing a review without offering to post it back to the PR means the work lives only in the chat transcript, which isn't where a team actually reviews code.
Posting is a visible, public-facing action, so always ask before posting — never post automatically. Ask once, and keep the prompt short:
<number>? (yes / no)"If the user answers "no", stop there. If "yes" or "selective", proceed to the idempotency check and then posting.
gh pr comment <NUMBER> --repo <OWNER/REPO> --body-file <path-to-tempfile>Use --body-file rather than --body so newlines, backticks, and markdown tables survive the shell without escaping headaches. Write each comment to a temp file first (e.g., /tmp/dep-review-<pr-number>.md), then pass the path.
Use this exact structure per PR:
## Dependabot review
**Verdict:** <Merge / Verify / Investigate / Hold>
<one-line reason — the core of why this verdict>
<details>
<summary>Full review</summary>
<the full review output: Bump Type, What Changed, Breaking Changes in This Codebase (if any), Codebase Impact, Recommendation>
</details>
<!-- dependabot-audit:v1 -->Rationale for each element:
<details> block keeps the long analysis collapsed — PR comments that dump 40 lines of unrequested content are noisy and get ignored.<!-- dependabot-audit:v1 --> HTML comment is invisible in the rendered view but lets a future run detect its own prior comment and decide whether to skip or update instead of duplicating.Before posting to any PR, run:
gh api repos/<OWNER>/<REPO>/issues/<NUMBER>/comments --paginate \
--jq '.[].body' | grep -q 'dependabot-audit:v1'If the marker is found, a prior review comment already exists. Mention it in the confirmation prompt ("PR #9170 already has a prior review comment — re-post anyway?") so the user can choose to skip, replace (delete the old comment via gh api --method DELETE /repos/<owner>/<repo>/issues/comments/<id> and post new), or leave it alone. Default to skipping if the user doesn't specify.
If gh pr comment fails for one PR (permissions, locked PR, rate limit), report the failure inline and continue. In audit mode, do not abort the whole batch because one comment failed.
After posting, show a short line:
<number>."© ThibautBaissac, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/dependabot-review of ThibautBaissac/rails_ai_agents.
Open the folder on GitHubat commit 03622f2
Dependabot Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependabot Review this skillThibautBaissac/rails_ai_agents | 665 | — | ~3.9k | Automated safety check: Notes | MIT | |
| Validator Dependency Upgradeexpress-validator/express-validator | 6.2k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Claude Code Version Checkykdojo/claude-code-tips | 10k | — | ~1.8k | Automated safety check: Pass | Custom licence | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| RStudio Electron Version Updaterstudio/rstudio | 5.1k | — | ~964 | Automated safety check: Pass | Custom licence | |
| Aube Package Manager Helperaubepkg/aube | 2k | — | ~1.1k | Automated safety check: Warn | MIT |
express-validator/express-validator
Walks maintainers through bumping the pinned validator package in express-validator and syncing chain types, implementations and options with the new release.
ykdojo/claude-code-tips
Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
rstudio/rstudio
Bumps the pinned Electron version across the RStudio repository, updating NEWS.md, package.json, the lockfile and the allowScripts entry.
aubepkg/aube
Manages Node.js dependencies, scripts and installs with aube, aubr and aubx, choosing the right command by its effect and preserving the project's existing lockfile and workspace format.
livesession/xyd
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
ThibautBaissac/rails_ai_agents
Audits Rails application accessibility against WCAG 2.2 Level AA, detects violations with axe-core / Lighthouse / Pa11y, and reports remediation guidance for ERB views, ViewComponents, Stimulus…
ThibautBaissac/rails_ai_agents
Implements real-time features with Action Cable and WebSockets.
ThibautBaissac/rails_ai_agents
Configures Active Storage for file uploads with variants and direct uploads.
ThibautBaissac/rails_ai_agents
Implements authentication using Rails 8 built-in generator. An agent skill from ThibautBaissac/rails_ai_agents.
ThibautBaissac/rails_ai_agents
Implements Rails caching patterns for performance optimization.
ThibautBaissac/rails_ai_agents
Implements internationalization with Rails I18n for multi-language support.
Works with
Categories
Reviews Dependabot gem upgrade PRs for breaking changes, codebase impact, and merge readiness. Dependabot Review is an agent skill from ThibautBaissac/rails_ai_agents. Reviews Dependabot gem upgrade PRs for breaking changes, codebase impact, and merge readiness.
Dependabot Review fits situations like: user pastes a Dependabot PR URL; asks about a gem version bump; wants to audit open dependency PRs (which dep PRs are safe to merge; check dependabot).
Run `npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a claude-code`. Or copy the skill folder (.agents/skills/dependabot-review in ThibautBaissac/rails_ai_agents) into .claude/skills/dependabot-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a codex`. Or copy the skill folder (.agents/skills/dependabot-review in ThibautBaissac/rails_ai_agents) into .agents/skills/dependabot-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ThibautBaissac/rails_ai_agents --skill dependabot-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-review, .gemini/skills/dependabot-review, .github/skills/dependabot-review and .opencode/skills/dependabot-review in your project.
Going by SKILL.md and its folder, Dependabot Review needs the command-line tools its instructions call (gh). Its frontmatter pre-approves these tools: Read, Bash, WebFetch, Grep, Glob.
SKILL.md names 2 domains. In commands or code: github.com and rubygems.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Dependabot Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dependabot Review: Validator Dependency Upgrade (express-validator/express-validator, 6.2k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and RStudio Electron Version Update (rstudio/rstudio, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ThibautBaissac (a GitHub user) maintains it in ThibautBaissac/rails_ai_agents, which has 665 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on June 1, 2026.
Source: ThibautBaissac/rails_ai_agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.