Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
Install the "fix-security-pr" agent skill from https://github.com/unional/typescript-blackbook/tree/main/.agents/skills/fix-security-pr into .claude/skills/fix-security-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-pr", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add unional/typescript-blackbook --skill fix-security-pr -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "fix-security-pr" agent skill from https://github.com/unional/typescript-blackbook/tree/main/.agents/skills/fix-security-pr into .agents/skills/fix-security-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-pr", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add unional/typescript-blackbook --skill fix-security-pr -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "fix-security-pr" agent skill from https://github.com/unional/typescript-blackbook/tree/main/.agents/skills/fix-security-pr into .cursor/skills/fix-security-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-pr", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add unional/typescript-blackbook --skill fix-security-pr -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "fix-security-pr" agent skill from https://github.com/unional/typescript-blackbook/tree/main/.agents/skills/fix-security-pr into .gemini/skills/fix-security-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-pr", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add unional/typescript-blackbook --skill fix-security-pr -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "fix-security-pr" agent skill from https://github.com/unional/typescript-blackbook/tree/main/.agents/skills/fix-security-pr into .github/skills/fix-security-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-pr", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add unional/typescript-blackbook --skill fix-security-pr -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "fix-security-pr" agent skill from https://github.com/unional/typescript-blackbook/tree/main/.agents/skills/fix-security-pr into .opencode/skills/fix-security-pr/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fix-security-pr", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
fix-security-pr
GitHub stars
133
Token cost
~1.4k tokens
SKILL.md length
574 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT
At a glance
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
Works in 7 steps: Identify the PR and failure → Understand the vulnerability → Detect package manager and repo type → …
Asked to fix the security PR
SKILL.md covers Step 1 — Identify the PR and…, Step 2 — Understand the…, Step 3 — Detect package… and Step 4 — Apply the fix, plus 4 more sections
Calls git, gh and pnpm
What it does
Fix Security PR is an agent skill from unional/typescript-blackbook. Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Use when asked to 'fix the security PR', 'resolve the vulnerability failure', or 'unblock the Dependabot PR'.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Dependency management, Git workflow and Vulnerability scanning. It works with npm, pnpm, Snyk and GitHub. The repository describes itself as: The TypeScript Blackbook. The licence is MIT.
When your agent uses it
Asked to fix the security PR
Resolve the vulnerability failure
Unblock the Dependabot PR
Example prompts
“fix the security PR”
“resolve the vulnerability failure”
“unblock the Dependabot PR”
“/fix-security-pr”
Requirements
Node.js
Workflow steps
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 154d0ea. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
git
gh
pnpm
npm
yarn
bun
jq
npx
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use git, gh, pnpm, npm, yarn and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Fix Security PR loads about 1.4k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 574 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~79
When it runs· the whole SKILL.md, loaded when a task matches
~1.4k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: warnings
The automated check found patterns that need a careful read before installing.
WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:190
fails to reach the registry, check for `.npmrc` or `.pnpmrc` with a private registry URL. The fix process is the same; j
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/fix-security-pr/SKILL.md (or your agent's skills folder).
name
fix-security-pr
description
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Use when asked to 'fix the security PR', 'resolve the vulnerability failure', or 'unblock the Dependabot PR'.
Fix Security PR
Diagnose and remediate security/vulnerability failures in a pull request so CI passes.
Step 1 — Identify the PR and failure
Detect the PR:
If a PR URL or number is provided, use it directly
If on a branch: gh pr view --json number,url,headRefName,baseRefName
If unspecified: list recent failing PRs: gh pr list --state open --json number,title,url | grep -i -E "security|vuln|cve|dependabot|snyk|audit"
Read the failure:
bash
gh run list --repo <owner>/<repo> --branch <branch> --limit 5 --json databaseId,conclusion,name
gh run view <run-id> --log-failed 2>&1 | head -100
Look for these patterns in the logs:
Pattern
Source
Meaning
npm audit / pnpm audit / yarn audit exit non-zero
Audit step
Vulnerable dep in tree
High / Critical severity advisory
Audit output
Specific CVE needs fixing
merge conflict / conflict in PR
Git
Dependabot PR is stale; needs rebase
Snyk found / snyk test failure
Snyk
Vulnerable dep detected by Snyk
GHSA-* advisory ID
GitHub Advisory
Specific advisory blocking
Step 2 — Understand the vulnerability
Extract from the failure log:
Package name (e.g. lodash)
Vulnerable version range (e.g. <4.17.21)
Safe version (e.g. >=4.17.21)
Severity (critical / high / moderate / low)
Advisory ID (CVE or GHSA number)
Whether it's a direct or transitive dependency
For Dependabot PRs, also check:
bash
gh pr view <number> --json body,title,commits
Step 3 — Detect package manager and repo type
File
Package manager
pnpm-lock.yaml
pnpm
bun.lock / bun.lockb
bun
yarn.lock
yarn
package-lock.json
npm
Check for monorepo: pnpm-workspace.yaml, workspaces in root package.json, or bun.workspace.ts.
Step 4 — Apply the fix
Choose the approach based on whether the dependency is direct or transitive:
Direct dependency
Update the version in package.json to the safe version, then reinstall:
bash
# pnpm
pnpm update <package>@<safe-version>
# npm
npm install <package>@<safe-version>
# yarn
yarn upgrade <package>@<safe-version>
# bun
bun update <package>
Transitive dependency (you don't control the version directly)
Add an override to force the safe version across the entire tree:
If the vulnerable dep is a transitive dep of a workspace, add the override to the rootpackage.json (not the workspace's).
Show full SKILL.md (238 more words)Show less
Step 5 — Verify the fix locally
bash
# Confirm no remaining vulnerabilities at the severity level that was failing
<pm> audit --audit-level=high # or: critical / moderate
# If Snyk is used
npx snyk test
If the audit still fails after fixing one package, check for additional advisories in the output and repeat Step 4 for each.
For Dependabot PRs where you rebased with --force-with-lease, the push is already done in Step 4.
Step 7 — Re-trigger CI and verify
bash
# Watch the new run
gh run list --branch <branch> --limit 3
gh run watch <new-run-id>
If CI passes, the PR is unblocked. If another security failure appears, return to Step 2 for the next advisory.
Edge cases
Audit level mismatch: CI may fail on moderate while you're checking high. Check the CI command's --audit-level flag and match it when verifying locally.
No safe version exists yet: If the advisory has no fix available, options are:
Remove the package entirely if it's not truly needed
Add the package to an audit ignore list (.nsprc, auditignore, or --ignore flag) and leave a comment explaining why — inform the user before doing this
Wait for upstream to release a fix; inform the user
Private registry: If npm audit / pnpm audit fails to reach the registry, check for .npmrc or .pnpmrc with a private registry URL. The fix process is the same; just ensure the registry is reachable in CI.
Dependabot already auto-merged: Check if the PR is still open before starting. If it merged and CI still fails on main, the vulnerability is in the base branch — treat it as a direct fix to main, not a PR fix.
Fix Security PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Fix Security PR compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Fix Security PR this skillunional/typescript-blackbook
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.
Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…
Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.
Cut and publish a new tellux release — bump version, curate a changelog summary from recent commits, pause for the user to manually pnpm publish (browser 2FA), then push the tag and create the…
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Fix Security PR is an agent skill from unional/typescript-blackbook. Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.
When should I use Fix Security PR?
Fix Security PR fits situations like: asked to fix the security PR; resolve the vulnerability failure; unblock the Dependabot PR.
How do I install Fix Security PR in Claude Code?
Run `npx skills add unional/typescript-blackbook --skill fix-security-pr -a claude-code`. Or copy the skill folder (.agents/skills/fix-security-pr in unional/typescript-blackbook) into .claude/skills/fix-security-pr in your project. Claude Code loads it when a task matches its description.
How do I install Fix Security PR in Codex?
Run `npx skills add unional/typescript-blackbook --skill fix-security-pr -a codex`. Or copy the skill folder (.agents/skills/fix-security-pr in unional/typescript-blackbook) into .agents/skills/fix-security-pr in your project. Codex loads it when a task matches its description.
Can I use Fix Security PR in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add unional/typescript-blackbook --skill fix-security-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-security-pr, .gemini/skills/fix-security-pr, .github/skills/fix-security-pr and .opencode/skills/fix-security-pr in your project.
What does Fix Security PR need to run?
Going by SKILL.md and its folder, Fix Security PR needs the command-line tools its instructions call (git, gh, pnpm, npm, yarn and bun). Our summary lists: Node.js.
Does Fix Security PR access the network?
SKILL.md contains no URLs. Its commands use git, gh, npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Is Fix Security PR safe to install?
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
What licence does Fix Security PR use?
Fix Security PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Fix Security PR use?
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Fix Security PR?
Skills that share tags, products or a category with Fix Security PR: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Release (seasonedcc/remix-forms, 514 stars) and Dependabot Alerts Update (livesession/xyd, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Fix Security PR?
unional (a GitHub user) maintains it in unional/typescript-blackbook, which has 133 GitHub stars. The repository was last updated on October 7, 2026.
Source: unional/typescript-blackbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.