review-dependabot-config
v1.0.0Review a repository's Dependabot setup (dependabot.yml coverage and validity, grouping, labels, commit messages, and the repository settings and secrets Dependabot depends on), then apply the fixes the user selects.
By Christopher BooneLicense: MIT2 GitHub starsUpdated last week
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 1 skill or MCP entry
- Source updated
- Sep 16, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install review-dependabot-config for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install review-dependabot-config-2@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/cboone/agent-harness-pluginsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/review-dependabot-config/.
Plugin files
├── .claude-plugin/plugin.json└── skills/review-dependabot-config/SKILL.md
Included Skills1
Review a repository's Dependabot setup: whether dependabot.yml covers every ecosystem and directory present, whether it is valid against current GitHub behavior, how it groups and paces PRs, labels, commit messages, and ignore rules, plus the repository settings and secrets Dependabot depends on (alerts, security updates, Dependabot secrets, rulesets). Reports findings by severity, then applies the fixes the user selects. Use when the user says "review dependabot config", "review dependabot settings", "audit dependabot.yml", "check the Dependabot configuration", "is Dependabot set up correctly", "do we have Dependabot checks on everything", "why isn't Dependabot opening PRs", "stop Dependabot from updating a directory", or any variant involving reviewing Dependabot configuration. Requires the gh CLI to be installed and authenticated, and jq.
Plugin manifests1
{
"author": {
"name": "Christopher Boone"
},
"description": "Review a repository's Dependabot setup (dependabot.yml coverage and validity, grouping, labels, commit messages, and the repository settings and secrets Dependabot depends on), then apply the fixes the user selects.",
"homepage": "https://github.com/cboone/agent-harness-plugins",
"keywords": [
"configuration",
"dependabot",
"dependencies",
"github",
"security"
],
"license": "MIT",
"name": "review-dependabot-config",
"repository": "https://github.com/cboone/agent-harness-plugins",
"skills": "./skills",
"version": "1.0.0"
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[review-dependabot-config on Agent Plugins Marketplace](https://pluginsmp.com/plugins/review-dependabot-config-2)