Agent skill

Fix Security PR

by unional in unional/typescript-blackbook

Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

MITAuto-check: warningsDevelopment

Install Fix Security PR

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add unional/typescript-blackbook --skill fix-security-pr -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install unional/typescript-blackbook fix-security-pr --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/unional/typescript-blackbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fix-security-pr .claude/skills/fix-security-pr && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-security-pr
GitHub stars
133
Token cost
~1.4k tokens
SKILL.md length
574 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

  • Works in 7 steps: Identify the PR and failure → Understand the vulnerability → Detect package manager and repo type → …
  • Asked to fix the security PR
  • SKILL.md covers Step 1 — Identify the PR and…, Step 2 — Understand the…, Step 3 — Detect package… and Step 4 — Apply the fix, plus 4 more sections
  • Calls git, gh and pnpm

What it does

Fix Security PR is an agent skill from unional/typescript-blackbook. Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Use when asked to 'fix the security PR', 'resolve the vulnerability failure', or 'unblock the Dependabot PR'.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management, Git workflow and Vulnerability scanning. It works with npm, pnpm, Snyk and GitHub. The repository describes itself as: The TypeScript Blackbook. The licence is MIT.

When your agent uses it

  • Asked to fix the security PR
  • Resolve the vulnerability failure
  • Unblock the Dependabot PR

Example prompts

  • “fix the security PR”
  • “resolve the vulnerability failure”
  • “unblock the Dependabot PR”
  • “/fix-security-pr”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Identify the PR and failure
  2. Understand the vulnerability
  3. Detect package manager and repo type
  4. Apply the fix
  5. Verify the fix locally
  6. Commit and push
  7. Re-trigger CI and verify

What it can do on your machine

Read from SKILL.md and the folder at commit 154d0ea. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • pnpm
    • npm
    • yarn
    • bun
    • jq
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, gh, pnpm, npm, yarn and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Security PR loads about 1.4k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:190
    fails to reach the registry, check for `.npmrc` or `.pnpmrc` with a private registry URL. The fix process is the same; j

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from unional/typescript-blackbook at commit 154d0ea, republished under its MIT licence (© unional). 574 words, ~1,444 tokens.

Download SKILL.mdSave it as .claude/skills/fix-security-pr/SKILL.md (or your agent's skills folder).
name
fix-security-pr
description
Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Use when asked to 'fix the security PR', 'resolve the vulnerability failure', or 'unblock the Dependabot PR'.

Fix Security PR

Diagnose and remediate security/vulnerability failures in a pull request so CI passes.

Step 1 — Identify the PR and failure

Detect the PR:

  • If a PR URL or number is provided, use it directly
  • If on a branch: gh pr view --json number,url,headRefName,baseRefName
  • If unspecified: list recent failing PRs: gh pr list --state open --json number,title,url | grep -i -E "security|vuln|cve|dependabot|snyk|audit"

Read the failure:

bash
gh run list --repo <owner>/<repo> --branch <branch> --limit 5 --json databaseId,conclusion,name
gh run view <run-id> --log-failed 2>&1 | head -100

Look for these patterns in the logs:

PatternSourceMeaning
npm audit / pnpm audit / yarn audit exit non-zeroAudit stepVulnerable dep in tree
High / Critical severity advisoryAudit outputSpecific CVE needs fixing
merge conflict / conflict in PRGitDependabot PR is stale; needs rebase
Snyk found / snyk test failureSnykVulnerable dep detected by Snyk
GHSA-* advisory IDGitHub AdvisorySpecific advisory blocking

Step 2 — Understand the vulnerability

Extract from the failure log:

  • Package name (e.g. lodash)
  • Vulnerable version range (e.g. <4.17.21)
  • Safe version (e.g. >=4.17.21)
  • Severity (critical / high / moderate / low)
  • Advisory ID (CVE or GHSA number)
  • Whether it's a direct or transitive dependency

For Dependabot PRs, also check:

bash
gh pr view <number> --json body,title,commits

Step 3 — Detect package manager and repo type

FilePackage manager
pnpm-lock.yamlpnpm
bun.lock / bun.lockbbun
yarn.lockyarn
package-lock.jsonnpm

Check for monorepo: pnpm-workspace.yaml, workspaces in root package.json, or bun.workspace.ts.

Step 4 — Apply the fix

Choose the approach based on whether the dependency is direct or transitive:

Direct dependency

Update the version in package.json to the safe version, then reinstall:

bash
# pnpm
pnpm update <package>@<safe-version>

# npm
npm install <package>@<safe-version>

# yarn
yarn upgrade <package>@<safe-version>

# bun
bun update <package>
Transitive dependency (you don't control the version directly)

Add an override to force the safe version across the entire tree:

pnpm (package.json):

json
{
  "pnpm": {
    "overrides": {
      "<package>": ">=<safe-version>"
    }
  }
}

npm (package.json):

json
{
  "overrides": {
    "<package>": ">=<safe-version>"
  }
}

yarn (package.json):

json
{
  "resolutions": {
    "<package>": ">=<safe-version>"
  }
}

After adding the override, reinstall to regenerate the lockfile:

bash
<pm> install
Dependabot PR with merge conflicts

The PR branch is stale. Rebase it onto the base branch:

bash
git fetch origin
git checkout <dependabot-branch>
git rebase origin/<base-branch>
# resolve any conflicts
git push --force-with-lease origin <dependabot-branch>

If the conflict is in the lockfile, delete it and reinstall after resolving package.json conflicts:

bash
rm <lockfile>
<pm> install
git add <lockfile>
git rebase --continue
Monorepo: vulnerability in a workspace package

Check which workspace contains the vulnerable dep:

bash
<pm> audit --json 2>/dev/null | jq '.vulnerabilities | to_entries[] | {pkg: .key, via: .value.via}'

If the vulnerable dep is a transitive dep of a workspace, add the override to the root package.json (not the workspace's).

Show full SKILL.md (238 more words)Show less

Step 5 — Verify the fix locally

bash
# Confirm no remaining vulnerabilities at the severity level that was failing
<pm> audit --audit-level=high   # or: critical / moderate

# If Snyk is used
npx snyk test

If the audit still fails after fixing one package, check for additional advisories in the output and repeat Step 4 for each.

Step 6 — Commit and push

bash
git add package.json <lockfile>
git commit -m "fix: patch <package> vulnerability (<CVE-or-GHSA>)"
git push origin <branch>

For Dependabot PRs where you rebased with --force-with-lease, the push is already done in Step 4.

Step 7 — Re-trigger CI and verify

bash
# Watch the new run
gh run list --branch <branch> --limit 3
gh run watch <new-run-id>

If CI passes, the PR is unblocked. If another security failure appears, return to Step 2 for the next advisory.

Edge cases

Audit level mismatch: CI may fail on moderate while you're checking high. Check the CI command's --audit-level flag and match it when verifying locally.

No safe version exists yet: If the advisory has no fix available, options are:

  1. Remove the package entirely if it's not truly needed
  2. Add the package to an audit ignore list (.nsprc, auditignore, or --ignore flag) and leave a comment explaining why — inform the user before doing this
  3. Wait for upstream to release a fix; inform the user

Private registry: If npm audit / pnpm audit fails to reach the registry, check for .npmrc or .pnpmrc with a private registry URL. The fix process is the same; just ensure the registry is reachable in CI.

Dependabot already auto-merged: Check if the PR is still open before starting. If it merged and CI still fails on main, the vulnerability is in the base branch — treat it as a direct fix to main, not a PR fix.

© unional, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/fix-security-pr of unional/typescript-blackbook.

Open the folder on GitHubat commit 154d0ea

Compare with similar skills

Fix Security PR next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Security PR compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Security PR this skillunional/typescript-blackbook133—~1.4kAutomated safety check: WarnMIT
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
ZCF Release AutomationUfoMiao/zcf6.1k—~3.4kAutomated safety check: PassMIT
Releaseseasonedcc/remix-forms514—~1.3kAutomated safety check: PassMIT
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Monorepo Tooling and Dependenciespierrecomputer/pierre6.3k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Automates a version release with changesets: analyzes code changes, writes a bilingual CHANGELOG, bumps the version and commits through a release branch and pull request.

    6.1k GitHub stars~3.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Release

    seasonedcc/remix-forms

    Release a new version of the remix-forms npm package. An agent skill from seasonedcc/remix-forms.

    514 GitHub stars~1.3k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.3k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Release

    cyanfish-x/tellux

    Cut and publish a new tellux release — bump version, curate a changelog summary from recent commits, pause for the user to manually pnpm publish (browser 2FA), then push the tag and create the…

    207 GitHub stars~1.3k tokensUpdated 18 days ago
    DevelopmentAuto-check passed

Categories

Questions about Fix Security PR

What does Fix Security PR do?

Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Fix Security PR is an agent skill from unional/typescript-blackbook. Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks.

When should I use Fix Security PR?

Fix Security PR fits situations like: asked to fix the security PR; resolve the vulnerability failure; unblock the Dependabot PR.

How do I install Fix Security PR in Claude Code?

Run `npx skills add unional/typescript-blackbook --skill fix-security-pr -a claude-code`. Or copy the skill folder (.agents/skills/fix-security-pr in unional/typescript-blackbook) into .claude/skills/fix-security-pr in your project. Claude Code loads it when a task matches its description.

How do I install Fix Security PR in Codex?

Run `npx skills add unional/typescript-blackbook --skill fix-security-pr -a codex`. Or copy the skill folder (.agents/skills/fix-security-pr in unional/typescript-blackbook) into .agents/skills/fix-security-pr in your project. Codex loads it when a task matches its description.

Can I use Fix Security PR in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add unional/typescript-blackbook --skill fix-security-pr -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-security-pr, .gemini/skills/fix-security-pr, .github/skills/fix-security-pr and .opencode/skills/fix-security-pr in your project.

What does Fix Security PR need to run?

Going by SKILL.md and its folder, Fix Security PR needs the command-line tools its instructions call (git, gh, pnpm, npm, yarn and bun). Our summary lists: Node.js.

Does Fix Security PR access the network?

SKILL.md contains no URLs. Its commands use git, gh, npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Fix Security PR safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Fix Security PR use?

Fix Security PR is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fix Security PR use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Security PR?

Skills that share tags, products or a category with Fix Security PR: Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), ZCF Release Automation (UfoMiao/zcf, 6.1k stars), Release (seasonedcc/remix-forms, 514 stars) and Dependabot Alerts Update (livesession/xyd, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Security PR?

unional (a GitHub user) maintains it in unional/typescript-blackbook, which has 133 GitHub stars. The repository was last updated on October 7, 2026.

Source: unional/typescript-blackbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.