Dependabot PR Bulk Processor
Audit, comment, and merge open dependabot PRs. Each PR gets a security review via the review-dependency skill, a comment with findings, and — if safe — a squash merge.
Argument: $ARGUMENTS — optional filter (e.g., golang, docker, npm). Empty = process all open dependabot PRs.
Prerequisites
ghsudoinstalled for write operations (pip install ghsudo)- GitHub MCP tools available (
mcp__plugin_claudius_github__*) review-dependencyskill available
Workflow
1. Discover Open Dependabot PRs
gh pr list --repo <owner>/<repo> --author 'app/dependabot' \
--json number,title,statusCheckRollup,mergeable --limit 50
Extract per PR: number, title, CI status (which checks passed/failed), mergeable state. If $ARGUMENTS is set, keep only PRs whose title contains it.
2. Check for Unpushed Commits
Before spawning worktree agents:
git log @{upstream}..HEAD --oneline
If unpushed commits exist, alert the user and stop — worktree agents fork from remote state and would miss them. If no upstream is configured, fall back to git log origin/$(git branch --show-current)..HEAD.
3. Classify PRs
| Group | Condition | Action |
|---|---|---|
| Green | All CI checks passed + MERGEABLE | Audit, Comment, Merge |
| Red | CI failures + MERGEABLE | Audit, Comment, @dependabot rebase |
| Conflicting | CONFLICTING mergeable state | Comment conflict notice, @dependabot rebase |
Present the classification table to the user and ask for confirmation before proceeding.
4. Spawn Review Agents
For each PR, the coordinator pre-creates an isolated worktree (see grand-admiral § Worktree Isolation — the isolation flag is unreliable for run_in_background spawns) and spawns a background agent that cds into it as its FIRST action:
Agent(
mode: "bypassPermissions",
run_in_background: true,
prompt: "cd <pre-created worktree abs-path> first, then review the dependabot PR ..."
)
Set model per spawn: opus for every dependency bump — a bump pulls in third-party code and is security-sensitive by default; a passing vulnerability scan (e.g. govulncheck) is NOT evidence of low risk. ALWAYS fully investigate the bump, including the updated dependency's changed code; never downgrade to Sonnet.
Agent prompt must include ALL of:
- PR number, title, repo
<owner>/<repo> - CI status — green or red, which checks failed
- Mergeable state
- Instruction to invoke
review-dependencyskill with the PR number as argument - Instruction to post a comment with findings via
mcp__plugin_claudius_github__add_issue_comment(include attribution footer), and to report back either "confirmed posted:<comment URL>" or "NOT posted:<reason>" — never a bare "published"/"done", which has been observed meaning only "returned the text to you" - If Green: merge via
ghsudo gh pr merge <number> --repo <owner>/<repo> --squash - If Red or Conflicting: do NOT merge; post
@dependabot rebase, then enter Rebase Watch Loop (step 5a)
Spawn all agents in a single message for maximum parallelism.
5. Collect Results and Handle Write Blocks
As agents complete, check results. Never trust a "posted"/"published" self-report at face value — confirmed case: an agent reported the comment published when the PR actually had zero comments, and separately stated unverified claims (signature checks, release immutability) as confirmed fact. Verify independently before moving on: gh pr view <number> --json comments (or the MCP equivalent) for an actual comment matching this run, and re-read the agent's own reasoning for anything phrased as fact that it did not actually check.
Agents may be blocked from GitHub write operations by hooks. For blocked agents, or where verification above fails:
- Post the review comment yourself using GitHub MCP
- Execute the merge, rebase request, or watch loop yourself
5a. Rebase Watch Loop
After posting @dependabot rebase, poll until the rebase lands and CI completes (or timeout).
- Record the current HEAD SHA before requesting rebase
- Poll every 60s (max 15 minutes):
gh pr view --repo <owner>/<repo> <number> --json headRefOid,statusCheckRollup,mergeable - Exit conditions:
| Condition | Action |
|---|---|
headRefOid changed + all checks SUCCESS + mergeable == MERGEABLE |
Squash merge via ghsudo gh pr merge |
headRefOid changed + any check FAILURE |
Report as CI Red after rebase — do NOT re-rebase |
| 15 min elapsed, HEAD unchanged | Report as Rebase Timeout |
| Merge attempt fails (race, new conflict) | Report as Merge Failed after rebase |
On successful merge, report as Merged after rebase.
6. Handle Cascading Merge Failures
After earlier PRs merge, later PRs may become unmergeable (conflicting go.sum, lock files, etc.). When a merge fails with "not mergeable":
- Post
@dependabot rebaseon the PR - Enter Rebase Watch Loop (step 5a) — same timeout and CI check logic
7. Final Report
| PR | Dependency | Audit | Action | Result |
|---|---|---|---|---|
| #NNN | pkg old->new |
Safe/Risk | Merged/Rebase/Skipped | OK/MERGED_AFTER_REBASE/CI_RED/TIMEOUT/MERGE_FAILED/WARN |
Include:
- Total merged count (direct + after rebase)
- Rebase outcomes: merged after rebase, CI red after rebase, rebase timeout, merge failed after rebase
- Any PRs with security concerns (not merged)
- Note flaky tests if multiple PRs failed the same test
8. Lessons Learned
After all PRs, invoke claudius:lessons-learned skill if notable patterns emerged (flaky tests blocking merges, recurring merge conflicts, security concerns).
Attribution Footer
Every GitHub comment MUST end with:
<sub>🤖 Co-authored by [Claudius the Magnificent](https://github.com/lklimek/claudius) AI Agent</sub>
Safety Rules
- Never merge a PR with security concerns — comment only
- Never merge a PR with failing CI — request rebase instead
- Always get user confirmation before starting the bulk operation
- Use
ghsudofor all write operations (merge, comment) whenghalone fails with 403/404 - If
ghsudoexits with code 2 (user denied), skip that PR and move on - If
ghsudoexits with code 4 (no token), inform user to runghsudo --setup <org>