Borrowing it
Nothing to install: this file belongs to c9r-io/orchestrator. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/c9r-io/orchestrator/main/.claude/skills/dependabot-governance/SKILL.mdgit clone --depth 1 https://github.com/c9r-io/orchestratorWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/c9r-io/orchestrator/dependabot-governance)<a href="https://agentmods.dev/skills/c9r-io/orchestrator/dependabot-governance"><img src="https://agentmods.dev/badge/skills/c9r-io/orchestrator/dependabot-governance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/c9r-io/orchestrator/dependabot-governance"><img src="https://agentmods.dev/badge/skills/c9r-io/orchestrator/dependabot-governance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00061 | $0.01143 |
| Opus 5 | $0.00030 | $0.00571 |
| Sonnet 5 | $0.00012 | $0.00229 |
| Haiku 4.5 | $0.00006 | $0.00114 |
Grade A, and why
dependabot-governance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 105 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Dependabot PR Governance
Audit, remediate, and merge all open Dependabot PRs in one pass.
Phase 1: Audit
- List open Dependabot PRs:
gh pr list --state open --author 'app/dependabot' - For each PR, fetch CI and mergeability:
gh pr view <N> --json title,mergeable,mergeStateStatus,statusCheckRollup,headRefName - Record: PR number, package, ecosystem (npm/rust), version bump, CI pass/fail per job, mergeable state.
Phase 2: Classify
| Category | Criteria | Action |
|---|---|---|
| green | All CI pass, mergeable | Merge in Phase 4 |
| rebase-needed | CI fails on fmt/lint only (pre-existing on main), or has merge conflict | @dependabot rebase |
| breaking-combo | CI fails on build/test — shared backend requires combined upgrade | Create combined branch in Phase 3 |
Shared-backend detection
Dependabot upgrades crates independently, but some must be upgraded together because they share a transitive dependency with breaking trait changes. Common Rust groups:
sha2+hmac+pbkdf2→digestbackendaes+ctr→cipherbackendnotify+notify-debouncer-full→notify-typesbackend
Detection method:
- If a PR's CI shows trait-mismatch or version-conflict compile errors, inspect
Cargo.tomlfor the shared transitive dep - Check if another open Dependabot PR bumps the counterpart crate
- If so, classify both as breaking-combo
Phase 3: Remediate breaking-combo PRs
- Investigate CI failure logs:
gh run list --branch <branch> --limit 1 --json databaseId -q '.[0].databaseId' gh run view <run-id> --log-failed 2>&1 | head -200 - Find affected source files:
grep -r "use <crate>" --include="*.rs" -l - Create combined branch from main:
deps/<combined-name> - Apply all version bumps, fix compile errors
- Common migration patterns:
hmac0.13: adduse hmac::KeyInit(no longer re-exported viaMac)sha20.11:Digest::OutputdropsLowerHex— usehash.iter().map(|b| format!("{b:02x}")).collect()
- Verify:
cargo check && cargo fmt --check && cargo clippy && cargo test - Commit, push, create PR referencing superseded Dependabot PRs
- Close individual Dependabot PRs:
gh pr close <N> --comment "Superseded by #<combined>."
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 105 lines · 61 tokens per session scan A f6cf0f97f819
dependabot-governance is a skill published in the GitHub repository c9r-io/orchestrator (21 stars, last pushed 11d ago), licensed MIT. It adds 61 tokens to every session and 1,143 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
refactor
Safely restructure code in an isolated git worktree with test-preserved, incremental transformations.
cw-gates
Use before claiming any Codewhale change is done, green, or ready to land: the focused-to-broad verification ladder, the budget checks CI enforces, and the rules for what counts as a passing test.
cw-land
Use when turning verified Codewhale work into commits, branches, or a merge: choosing direct-main vs. worktree vs. integration branch, preserving contributor credit, and honoring the gate artifact before merging.
cw-orient
Use at the start of any Codewhale work session, or when unsure which checkout, branch, or worktree is authoritative: establish live repo truth before reading a plan or editing a file.
contributor-onboarding
Help a new contributor get productive on this checkout - inspect sync state against main, build, run the repository's exact verification gate, and produce a local what's-new digest. Never fetches, pulls, or modifies a dirty tree on its own. Explicit-only.
codew-release-qa-sweep
Use before claiming Codewhale release work is done: run the full gate sweep and list the manual QA targets.