skills/dependabot-resolve/SKILL.md
Comprehensive dependency update workflow for resolving Dependabot alerts and PRs. Use when: (1) User wants to update dependencies, (2) User mentions 'dependabot', 'security vulnerabilities', or 'dependency updates', (3) User asks to run security audit, (4) User wants to create a deps-update PR. Analyzes Dependabot issues, runs pnpm audit, applies updates, runs quality checks (typecheck, lint, test, build), handles Playwright Docker image sync, creates PR with changelog.
npx skillsauth add takazudo/claude-resources dependabot-resolveInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Execute a comprehensive dependency update workflow:
gh issue list --label "dependencies" --state open --json number,title,url,body to list all open Dependabot issuespnpm audit to check for security vulnerabilitiesIf there are updates to apply:
deps-update-MMDD from the current branchpnpm update <package-name> or pnpm add <package-name>@<version> as appropriatepnpm install to ensure lockfile is updatedSome packages require coordinated updates across multiple files. Check for these patterns:
When updating @playwright/test or playwright in package.json:
package.json: Look for @playwright/test and playwright versions.github/workflows/*.yml: Search for mcr.microsoft.com/playwright:v Docker image tagsUpdate Docker image tag to match the npm package version:
# In workflow files using Playwright Docker container
container:
image: mcr.microsoft.com/playwright:v<NEW_VERSION>-noble
Verify image exists at https://mcr.microsoft.com/v2/playwright/tags/list or check Microsoft's Playwright Docker documentation
Example: If updating @playwright/test from 1.57.0 to 1.58.0:
"@playwright/test": "^1.58.0"image: mcr.microsoft.com/playwright:v1.58.0-noblenext, eslint-config-next, etc.Run all quality checks in sequence:
pnpm typecheckpnpm lint (or pnpm lint:fix if auto-fixable)pnpm format (or pnpm format:fix if needed)pnpm test:unitpnpm build (to ensure the project builds successfully)pnpm test:e2e:critical or pnpm test:e2e:full-prod for comprehensive testingOnce all checks pass:
git add .git commit -m "chore: Update dependencies (MMDD)"git push -u origin deps-update-MMDDgh pr create with:
List of updated packages and versions
Summary of security fixes (if any)
Links to Dependabot issues being resolved using list format:
- 関連Issue
- https://github.com/<owner>/<repo>/issues/<issue-1>
- https://github.com/<owner>/<repo>/issues/<issue-2>
Note that all quality checks passed
--force flagspnpm serve and manual testing if needed)tools
Acceptance gate for a branch produced by an OpenAI Codex CLI run — usually Codex implementing a /big-plan epic that was handed off to it. Codex reports the work 'done' (or the user flags it WIP with corrections); this skill confirms the branch actually fulfils the original spec, fixes what falls short, and routes larger discoveries into GitHub issues. Use when: (1) User says '/finalize-codex-work', 'finalize codex work', 'confirm the codex work', 'check the codex branch', or 'codex said it's done', (2) A branch is the result of a Codex CLI session and needs verification against its spec issue/PR, (3) After assigning a /big-plan epic to Codex CLI. Pass -m/--merge to run /pr-complete -c at the end.
tools
Read a Figma design node directly from a share URL via the Figma REST API — no Dev Mode subscription, no MCP, no desktop app. Renders the node to PNG and dumps its full style/layout JSON so the design can be described, compared, or implemented. Use whenever the user gives a Figma design URL (figma.com/design/... or /file/...) and wants to see, read, inspect, reference, or implement that node — including `/fig-url-refer <url>`. This is the URL-based counterpart to `/figrefer` (which needs a Dev-plan desktop MCP); prefer this one when the input is a URL rather than a live desktop selection.
tools
Sync the user's Claude Code workflow skills into the OpenAI Codex CLI settings repo ($HOME/.codex) as Codex-native ports, fix the Codex .gitignore for new local state, then commit and push. Use when: (1) user says '/dev-codex-sync-settings-from-claude', 'sync codex settings', 'sync claude skills to codex', 'port skills to codex', or 'update codex from claude'; (2) after updating ~/.claude workflow skills (big-plan, x, x-as-pr, x-wt-teams) and Codex should catch up; (3) the $HOME/.codex repo has drifted behind $HOME/.claude. The ports are condensed Codex-native REWRITES, never file copies.
development
Analyze a video file (mov, mp4, webm, etc.) or a YouTube video by extracting still frames with ffmpeg and reading them chronologically with vision — Claude cannot ingest video files directly. Use whenever the user provides a video file path or YouTube URL and wants to know what happens in it: "read this video", "watch this video", "check this recording", "what happens in this .mov/.mp4", analyzing a screen recording of a UI bug, or verifying UI behavior captured in a video, even if they don't name this skill.