dependabot-pnpm
Dependabot pnpm Resolver
Autonomously resolve Dependabot security alerts in pnpm projects by analyzing dependency chains, applying appropriate fixes, and documenting decisions.
Workflow Overview
1. Check setup → First run? Configure the repo
2. Fetch alerts → Get open alerts via gh api
3. Plan → Group by fix, prioritize by severity
4. Baseline → Run install, build, typecheck, lint, test
5. Execute fixes → Apply fixes, validate each with install
6. Final validate → Confirm baseline still passes
7. Log & report → Document decisions, report issues
First-Run Setup
On first use in a repo, check if setup exists by looking for a dependabot workflow include in CLAUDE.md or AGENTS.md.
More from jvgomg/skills
grill-me
Interview the user relentlessly about a plan or design until reaching shared understanding, resolving each branch of the decision tree. Use when user wants to stress-test a plan, get grilled on their design, or mentions "grill me".
10team-lead
Orchestrates large bodies of work (features, refactors, milestones, backlog tasks) using sub-agents as a team. Use this skill when the user explicitly asks you to "take responsibility", "orchestrate", "lead", or "team-lead" a set of tasks or a milestone. This is a manual-trigger skill — only activate when the user clearly invokes it.
5prd-to-tasks
Break a PRD into independently-grabbable Backlog tasks using tracer-bullet vertical slices. Use when user wants to convert a PRD to tasks, create implementation tickets, or break down a PRD into work items.
4write-a-prd
Create a PRD through user interview, codebase exploration, and module design, then store as a Backlog document. Use when user wants to write a PRD, create a product requirements document, or plan a new feature.
4skill-creator
Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.
1split-expenses
>
1