Agent skill

Dependabot Review

by try-works in try-works/role-model

Analyzes a Dependabot PR to determine what actually changed in each bumped package and whether those changes affect this repo.

Custom licenceAuto-check passedDevelopment

Install Dependabot Review

skills CLI
$ npx skills add try-works/role-model --skill dependabot-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install try-works/role-model dependabot-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/try-works/role-model.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependabot-review .claude/skills/dependabot-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dependabot-review
GitHub stars
118
Token cost
~1.5k tokens
SKILL.md length
583 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Custom licence

At a glance

Analyzes a Dependabot PR to determine what actually changed in each bumped package and whether those changes affect this repo.

  • Works in 6 steps: Identify the packages being bumped → Fetch the changelog / release notes for… → Extract what changed → …
  • Tasks that involve Dependency management
  • SKILL.md covers Goal, Process, Output format and Special cases
  • Calls gh, npm and node

What it does

Dependabot Review is an agent skill from try-works/role-model. Analyzes a Dependabot PR to determine what actually changed in each bumped package and whether those changes affect this repo. Reports changed APIs/methods, which doc pages use them, and the realistic probability of any visible impact on the docs site.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Static sites and blogs and Changelog and release notes. The repository describes itself as: role-model is a protocol for assigning the right model for the right job. Use local and cloud AI together, or route between several cloud providers.

When your agent uses it

  • Tasks that involve Dependency management
  • Tasks that involve Static sites and blogs
  • Tasks that involve Changelog and release notes

Example prompts

  • “Use the dependabot-review skill to analyz a Dependabot PR to determine what actually changed in each bumped package and whether those changes affect…”
  • “/dependabot-review”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify the packages being bumped
  2. Fetch the changelog / release notes for each package
  3. Extract what changed
  4. Determine how this repo uses the package
  5. Map usage to doc pages
  6. Assess impact

What it can do on your machine

Read from SKILL.md and the folder at commit de1c04a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dependabot Review loads about 1.5k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 583 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 583 words (~1,488 tokens).

“Load this skill when asked to review, analyze, assess, or verify a Dependabot PR.”

— opening of SKILL.md by try-works, Custom licence
name
dependabot-review

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/dependabot-review of try-works/role-model.

Open the folder on GitHubat commit de1c04a

Compare with similar skills

Dependabot Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dependabot Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dependabot Review this skilltry-works/role-model118—~1.5kAutomated safety check: PassCustom licence
Changesetwithastro/astro63k—~1.1kAutomated safety check: PassCustom licence
Fern Navigationai-dynamo/dynamo8.3k—~2.2kAutomated safety check: PassApache-2.0
Claude Code Version Checkykdojo/claude-code-tips10k—~1.8kAutomated safety check: PassCustom licence
Create Manifestmindfold-ai/Trellis15k—~2.5kAutomated safety check: PassAGPL-3.0
Releasehyhmrright/brooks-lint1.5k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Changeset

    withastro/astro

    Official

    Create a changeset for the Astro monorepo. An agent skill from withastro/astro.

    63k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Fern Navigation

    ai-dynamo/dynamo

    Knowledge of Fern's site-level navigation and structure configuration — how a docs site is organized in docs.yml (and product/version .yml files) using sections, pages, folders, tabs, tab variants…

    8.3k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Claude Code Version Check

    ykdojo/claude-code-tips

    Recommends whether to stay on the installed Claude Code version, update, or pin another one by comparing npm tags, release timing and the changelog.

    10k GitHub stars~1.8k tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • Create Manifest

    mindfold-ai/Trellis

    Create a Trellis migration manifest and matching docs-site changelogs for a target release by analyzing commits since the previous release.

    15k GitHub stars~2.5k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Release

    hyhmrright/brooks-lint

    Cut a brooks-lint release: set the version in package.json, propagate it across all four plugin manifests and every version-bearing text file (README badges, docs site metadata), write the CHANGELOG…

    1.5k GitHub stars~1.2k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Bestie Features

    JuliaBesties/BestieTemplate.jl

    Add BestieTemplate features (AGENTS.md, changelog, dependabot, pre-commit, lint workflow, testitem runner) to a Julia package with the bestie CLI — no Julia needed.

    128 GitHub stars~2.5k tokensUpdated 21 days ago
    DevelopmentAuto-check passed

More from try-works/role-model

All 19 skills in this repo
  • E2E Testing Patterns

    try-works/role-model

    Master end-to-end testing with Playwright and Cypress to build reliable test suites that catch bugs, improve confidence, and enable fast deployment.

    118 GitHub starsUsed in 14 repos~990 tokens
    Auto-check passed
  • UI Design System

    try-works/role-model

    React UI component systems with TailwindCSS + Radix + shadcn/ui.

    118 GitHub stars~5k tokensUpdated 2 days ago
    Auto-check passed
  • Swiss Design

    try-works/role-model

    Apply a Swiss International Style design system using Tailwind CSS.

    118 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Contributing

    try-works/role-model

    A skill your agent uses when contributing to the Cloudflare Docs repository — writing or editing documentation pages, choosing content types or components, adding changelog entries, reviewing docs…

    118 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Effect V3 To V4

    try-works/role-model

    A skill your agent uses when migrating a codebase from Effect v3 to Effect v4, upgrading effect or any @effect/ package across the v3/v4 boundary.

    118 GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Turnstile Spin

    try-works/role-model

    Set up Cloudflare Turnstile end-to-end in a project — scan the codebase, create the widget via the Cloudflare API, deploy the managed siteverify Worker, write the frontend snippets, validate, and…

    118 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Dependabot Review

What does Dependabot Review do?

Analyzes a Dependabot PR to determine what actually changed in each bumped package and whether those changes affect this repo. Dependabot Review is an agent skill from try-works/role-model. Analyzes a Dependabot PR to determine what actually changed in each bumped package and whether those changes affect this repo.

When should I use Dependabot Review?

Dependabot Review fits situations like: tasks that involve Dependency management; tasks that involve Static sites and blogs; tasks that involve Changelog and release notes.

How do I install Dependabot Review in Claude Code?

Run `npx skills add try-works/role-model --skill dependabot-review -a claude-code`. Or copy the skill folder (.agents/skills/dependabot-review in try-works/role-model) into .claude/skills/dependabot-review in your project. Claude Code loads it when a task matches its description.

How do I install Dependabot Review in Codex?

Run `npx skills add try-works/role-model --skill dependabot-review -a codex`. Or copy the skill folder (.agents/skills/dependabot-review in try-works/role-model) into .agents/skills/dependabot-review in your project. Codex loads it when a task matches its description.

Can I use Dependabot Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add try-works/role-model --skill dependabot-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependabot-review, .gemini/skills/dependabot-review, .github/skills/dependabot-review and .opencode/skills/dependabot-review in your project.

What does Dependabot Review need to run?

Going by SKILL.md and its folder, Dependabot Review needs the command-line tools its instructions call (gh, npm and node).

Does Dependabot Review access the network?

SKILL.md contains no URLs. Its commands use gh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dependabot Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dependabot Review use?

Dependabot Review has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Dependabot Review use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dependabot Review?

Skills that share tags, products or a category with Dependabot Review: Changeset (withastro/astro, 63k stars), Fern Navigation (ai-dynamo/dynamo, 8.3k stars), Claude Code Version Check (ykdojo/claude-code-tips, 10k stars) and Create Manifest (mindfold-ai/Trellis, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dependabot Review?

try-works (a GitHub user) maintains it in try-works/role-model, which has 118 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: try-works/role-model on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.