Addresses GitHub Dependabot security alerts by listing open alerts, identifying affected Python/uv, frontend npm, and Titus Go projects, upgrading vulnerable dependencies, running verification, and committing fixes. Use when the user wants to fix Dependabot alerts, upgrade vulnerable packages, or address security vulnerabilities found by Dependabot.
91
88%
Does it follow best practices?
Impact
98%
1.13xAverage score across 3 eval scenarios
Passed
No known issues
Python multi-project vulnerability scan and fix
Scans unflagged project
100%
100%
Reads pyproject.toml
100%
100%
Uses uv add for direct deps
100%
100%
Correct version constraint
100%
100%
Quoted package spec
100%
100%
Per-project cd
100%
100%
Skips unaffected projects
50%
100%
Derives project directory
100%
100%
Uses alert fixed_in
100%
100%
Commit message format
40%
100%
npm transitive vulnerability fix via overrides
Uses overrides for transitive
100%
100%
Override uses >= constraint
100%
100%
Runs npm install
100%
100%
Verifies installed version
100%
100%
Build and audit verification
33%
66%
Preserves existing overrides
100%
100%
Correct commit files
100%
100%
Commit message format
40%
80%
Go multi-alert version format and combined fix
v prefix on versions
100%
100%
Single go get command
0%
100%
Runs go mod tidy
100%
100%
Verifies with go list -m
100%
100%
go binary PATH fallback
100%
100%
Runs go tests
100%
100%
Correct commit files
100%
100%
Commit message format
50%
100%
432d081
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.