Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Review and manage Dependabot PRs. Categorizes by risk, checks CI status, auto-merges safe updates, and reports issues. Use when the user says "review dependabot", "merge dependabot", "dependabot PRs", or "update dependencies".
.claude/skills/davila7-dependabot-review/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-08 | ✗→✓ | ▲ Improved | 102% | 0% |
| case-10 | ✗→✓ | ▲ Improved | -5% | 0% |
| case-12 | ✗→✓ | ▲ Improved | 33% | 0% |
| case-13 | ✗→✓ | ▲ Improved | -22% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 80% | 0% |
You are a dependency management specialist. Your job is to review all open Dependabot PRs, assess risk, and take action.
List all open Dependabot PRs:
bashgh pr list --author "dependabot[bot]" --state open --json number,title,labels,createdAt,headRefName --limit 50
If no PRs are found, inform the user and stop.
For each PR, classify it into a risk tier based on the branch name and title:
| Tier | Criteria | Action | |------|----------|--------| | Safe | GitHub Actions updates (dependabot/github_actions/), patch bumps (1.2.3 -> 1.2.4) | Auto-merge | | Low Risk | Minor bumps (1.2.0 -> 1.3.0) for well-known libraries | Auto-merge after CI check | | Review Required | Major bumps (1.x -> 2.x), unknown libraries, security-tagged PRs | Report to user |
To determine bump type, parse the PR title. Dependabot titles follow patterns like:
Bump X from 1.2.3 to 1.2.4 (patch)Bump X from 1.2.0 to 1.3.0 (minor)Bump X from 1.0.0 to 2.0.0 (major)For each PR you plan to merge, check CI status:
bashgh pr checks <number> --json name,state,bucket
For PRs classified as Safe or Low Risk with passing CI:
bashgh pr merge <number> --merge --delete-branch
Important rules:
After processing, present a summary table to the user:
## Dependabot Review Summary
### Merged (X PRs)
| PR | Update | Type |
|----|--------|------|
| #123 | actions/checkout v4 -> v6 | GitHub Actions |
### Needs Review (X PRs)
| PR | Update | Risk | Reason |
|----|--------|------|--------|
| #456 | jest 29 -> 30 | Major | Breaking changes possible |
### Skipped (X PRs)
| PR | Update | Reason |
|----|--------|--------|
| #789 | chalk 5.5 -> 5.6 | CI failing |security label or mentions a CVE, always flag it to the user even if it's a patch, so they are awaregh pr list --author "dependabot[bot]" again after each batch to see updated statusQuick safe merge (GitHub Actions only): The user says "merge the actions PRs" — filter to dependabot/github_actions/ branches only.
Full review: The user says "review dependabot" — run the complete workflow above.
Dry run: The user says "check dependabot" or "show dependabot PRs" — run Steps 1-2 only, report classification without merging.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 8,404 | 4,599 | -45% | 1 | 1 | 0% | 1,493 | 1,232 | -17% | 0 | 0 | — |
case-02 | fail→fail | 13,884 | 5,520 | -60% | 1 | 1 | 0% | 2,253 | 1,202 | -47% | 0 | 0 | — |
case-03 | fail→fail | 13,216 | 4,605 | -65% | 1 | 1 | 0% | 2,348 | 1,151 | -51% | 0 | 0 | — |
case-04 | pass→fail | 7,485 | 5,571 | -26% | 1 | 1 | 0% | 1,401 | 1,248 | -11% | 0 | 0 | — |
case-05 | pass→pass | 9,589 | 5,807 | -39% | 1 | 1 | 0% | 1,668 | 1,844 | +11% | 0 | 0 | — |
case-06 | fail→fail | 7,845 | 6,051 | -23% | 1 | 1 | 0% | 1,356 | 1,302 | -4% | 0 | 0 | — |
case-07 | fail→fail | 7,534 | 5,637 | -25% | 1 | 1 | 0% | 1,200 | 1,158 | -4% | 0 | 0 | — |
case-08 | fail→pass | 4,205 | 3,826 | -9% | 1 | 1 | 0% | 719 | 1,453 | +102% | 0 | 0 | — |
case-09 | pass→pass | 7,865 | 2,939 | -63% | 1 | 1 | 0% | 1,281 | 1,372 | +7% | 0 | 0 | — |
case-10 | fail→pass | 9,514 | 3,819 | -60% | 1 | 1 | 0% | 1,508 | 1,435 | -5% | 0 | 0 | — |
case-11 | pass→pass | 8,767 | 5,460 | -38% | 1 | 1 | 0% | 1,392 | 1,776 | +28% | 0 | 0 | — |
case-12 | fail→pass | 6,651 | 2,959 | -56% | 1 | 1 | 0% | 1,085 | 1,448 | +33% | 0 | 0 | — |
case-13 | fail→pass | 9,639 | 1,986 | -79% | 1 | 1 | 0% | 1,527 | 1,197 | -22% | 0 | 0 | — |
case-14 | pass→pass | 6,717 | 5,488 | -18% | 1 | 1 | 0% | 936 | 1,853 | +98% | 0 | 0 | — |
case-15 | fail→pass | 5,453 | 2,049 | -62% | 1 | 1 | 0% | 694 | 1,247 | +80% | 0 | 0 | — |
case-16 | fail→pass | 7,842 | 5,512 | -30% | 1 | 1 | 0% | 1,409 | 1,861 | +32% | 0 | 0 | — |
case-17 | fail→pass | 10,046 | 3,897 | -61% | 1 | 1 | 0% | 1,493 | 1,541 | +3% | 0 | 0 | — |
case-18 | pass→fail | 3,087 | 2,501 | -19% | 1 | 1 | 0% | 346 | 1,301 | +276% | 0 | 0 | — |
case-19 | pass→pass | 11,681 | 2,777 | -76% | 1 | 1 | 0% | 2,004 | 1,376 | -31% | 0 | 0 | — |
case-20 | pass→pass | 12,587 | 4,173 | -67% | 1 | 1 | 0% | 1,888 | 1,612 | -15% | 0 | 0 | — |
case-21 | fail→pass | 9,581 | 2,591 | -73% | 1 | 1 | 0% | 1,823 | 1,345 | -26% | 0 | 0 | — |
case-22 | fail→pass | 9,550 | 3,374 | -65% | 1 | 1 | 0% | 1,462 | 1,437 | -2% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 16 counted toward the lift figure. The other 6 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +32 percentage points is the difference between those two pass rates over the 16 comparable cases. 4 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.