automattic/calypso-security-alerts
Provide advisory guidance for scanning Automattic/wp-calypso Dependabot alerts and Dependabot remediation PRs using the public dependency security alerts playbook.
npx skills add https://github.com/Automattic/wp-calypso --skill calypso-security-alerts
Use this skill to guide a dependency-security scan for Automattic/wp-calypso.
This is an advisory workflow. Do not run shell commands from this skill. Read the playbook, explain the scan steps, and report the exact commands an operator should run.
Accept any of these:
Run from the repository root.
docs/dependency-security-alerts.md.gh commands to run.gh pr checks, not only statusCheckRollup, when deciding whether Calypso CI is ready.Scan complete.
- Open Dependabot alerts: <count>
- Open Dependabot PRs: <count>
Action needed:
- <item>
No action needed:
- <proof>
If there is nothing to do, say that first.
Take automattic/calypso-security-alerts from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.