Agent skill

Hunter 22

by aeonfun in aeonfun/aeon

Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw…

MITAuto-check passedSecurity

Install Hunter 22

skills CLI
$ npx skills add aeonfun/aeon --skill hunter-22 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aeonfun/aeon hunter-22 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunter-22 .claude/skills/hunter-22 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunter-22
GitHub stars
767
Token cost
~1.7k tokens
SKILL.md length
766 words
Files
1
Skills in repo
82
Repo updated
First seen
Licence
MIT

At a glance

Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw…

  • Works in 8 steps: Read memory/topics/hunter-22-seen.json… → Call POST… → Triage the gate output the same way as… → …
  • Tasks that involve Security review
  • SKILL.md covers What this is, What to do and Guardrails
  • Calls curl and node; reaches clawhunter.fun

What it does

Hunter 22 is an agent skill from aeonfun/aeon. Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw unfiltered dump. When a match is real audit-shaped work with a linked GitHub repo, the notification carries a one-tap button to dispatch vuln-scanner at it directly.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with GitHub. The repository describes itself as: The most autonomous AI agent framework: runs unattended on GitHub Actions, self-healing skills, drives Claude Code, Grok, Codex & more. No approval loops. Configure once, forget… The licence is MIT.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/hunter-22”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Read memory/topics/hunter-22-seen.json if it exists (dedup log — bounty IDs already surfaced, with the timestamp last seen). Create it…
  2. Call POST https://clawhunter.fun/api/v1/match with this agent's real, demonstrated capabilities, then pipe its response directly through…
  3. Triage the gate output the same way as any other discovery skill - be honest, not generous
  4. Flag audit-shaped candidates. For each candidate that survives step 3, check whether it's actually a code-security audit: requires…
  5. Diff against memory/topics/hunter-22-seen.json - only report bounties not already seen in the last 14 days.
  6. Update memory/topics/hunter-22-seen.json: append {id, title, reward, seen_at} from every entry in gate.seen, so candidates rejected by the…
  7. If there are new, genuinely-good matches: ./notify with a short, decision-grade list - title, reward, venue, one-line why-it-matches…
  8. Commit memory/topics/hunter-22-seen.json with an updated timestamp:.

What it can do on your machine

Read from SKILL.md and the folder at commit f252074. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • clawhunter.fun

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunter 22 loads about 1.7k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 766 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aeonfun/aeon at commit f252074, republished under its MIT licence (© aeonfun). 766 words, ~1,666 tokens.

Download SKILL.mdSave it as .claude/skills/hunter-22/SKILL.md (or your agent's skills folder).
name
hunter-22
description
Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw unfiltered dump. When a match is real audit-shaped work with a linked GitHub repo, the notification carries a one-tap button to dispatch vuln-scanner at it directly.
metadata.title
Hunter 22
metadata.mode
write
metadata.category
productivity
metadata.tags
bounties, income, discovery, security

${var} — optional filter. Empty → default capability match (see below). types:<a,b> → restrict to bounty types (e.g. types:code,research). min:<usd> → minimum reward floor.

Today is ${today}.

What this is

ClawHunter is a paid API that indexes crypto/social bounty venues and ranks opportunities. This skill calls its free discovery tier only — no API key, no wallet, no payment. Read docs/ClawHunter-API.md in this repo for the endpoint reference (base URL, auth, rate limits).

This is discovery only for anything requiring human judgment or funds — it never claims, submits, or executes a bounty, and never touches a wallet. It surfaces candidates for the operator to act on manually, with one exception: when a match is real audit-shaped work (code/security, with a linked GitHub repo), the notification carries a button that dispatches vuln-scanner at that repo — the operator still taps to trigger it, this skill never dispatches on its own. Do not call any $ (paid, x402) endpoint in this skill; those require a funded wallet this fork does not have configured.

What to do

  1. Read memory/topics/hunter-22-seen.json if it exists (dedup log — bounty IDs already surfaced, with the timestamp last seen). Create it empty ([]) if missing.
  2. Call POST https://clawhunter.fun/api/v1/match with this agent's real, demonstrated capabilities, then pipe its response directly through the mandatory expiration gate before reading or triaging it:
    bash
    curl -fsS -X POST https://clawhunter.fun/api/v1/match \
      -H 'content-type: application/json' \
      --data '{"capabilities":["code","security-research","research","writing","dependency-analysis"],"canDoRealWorld":false,"minReward":20,"limit":25}' \
      | node scripts/hunter-22-filter.mjs
    Run that command as written when ${var} is empty. When ${var} sets types:<a,b>, add "types":["a","b"] to the --data body before running it (types filters the bounty types field). When it sets min:<usd>, set minReward to that number before running it. Apply both edits when both are set. Do not save, inspect, or triage the raw response. If the gate exits non-zero, treat the API as unavailable and stop. The gate removes expired and malformed deadlines deterministically. Its gate.seen list retains minimal dedup fields for all input candidates, including rejected ones. Use these real capabilities, not aspirational ones:
    json
    {
      "capabilities": ["code", "security-research", "research", "writing", "dependency-analysis"],
      "canDoRealWorld": false,
      "minReward": 20,
      "limit": 25
    }
    canDoRealWorld: false — this agent has no wallet/payment rails configured, so exclude bounties requiring on-chain execution or payment. Do NOT set canDoRealWorld: true unless a wallet has actually been funded and documented in memory/topics/ — check first.
  3. Triage the gate output the same way as any other discovery skill - be honest, not generous:
    • Drop anything that's really a content/social-growth task in disguise (tweet threads, engagement farming, influencer voice-cloning, "get a streamer/creator to post X" outreach). A requires array that's only engage/outreach/video/image with no code/onchain is the tell — this agent has no content-generation or social-outreach tooling wired up and can't credibly deliver those.
    • Keep bounties that map to real work: code fixes, dependency/security review, technical writing, structured research with citable sources — the kind of work already demonstrated in output/articles/vuln-scan-*.md.
    • For each kept candidate, sanity-check the reward is real (not vaporware) and that a remaining deadline is reachable.
  4. Flag audit-shaped candidates. For each candidate that survives step 3, check whether it's actually a code-security audit: requires includes code or onchain, and the bounty's body/url contains a GitHub repo link (github\.com/[\w.-]+/[\w.-]+). If both hold, extract owner/repo - this is exactly the Veilo-bounty shape (a Superteam listing naming a specific on-chain program's source repo). Not every kept candidate will have one; most won't.
  5. Diff against memory/topics/hunter-22-seen.json - only report bounties not already seen in the last 14 days.
  6. Update memory/topics/hunter-22-seen.json: append {id, title, reward, seen_at} from every entry in gate.seen, so candidates rejected by the hard gate still enter the dedup window. Prune entries older than 30 days.
  7. If there are new, genuinely-good matches: ./notify with a short, decision-grade list - title, reward, venue, one-line why-it-matches, link. Lead with the count and the best one. For any match flagged audit-shaped in step 4, add an inline button so the operator can dispatch the audit in one tap:
    bash
    ./notify -f /tmp/hunter22-notify.md --buttons '[[
      {"text":"Audit owner/repo","callback_data":"run:vuln-scanner:owner/repo"},
      {"text":"Open bounty","url":"<bounty url>"}
    ]]'
    callback_data has a hard 64-byte limit (see docs/telegram-commands.md) — run:vuln-scanner:owner/repo fits comfortably for any realistic repo path. If more than one candidate this run is audit-shaped, send one notify per candidate (each with its own button row) rather than merging them, so a tap is unambiguous about which repo it targets. If nothing new or nothing real survived triage, do not notify (see CLAUDE.md: "notify only on signal").
  8. Commit memory/topics/hunter-22-seen.json with an updated timestamp:.
Show full SKILL.md (78 more words)Show less

Guardrails

  • Never call a paid ($) endpoint. Never touch /tools/*, /chat/completions, or anything billed via x402 in this skill.
  • Never claim or submit a bounty on the operator's behalf - this skill only surfaces candidates, and the audit-dispatch button in step 7 still requires a human tap, not an automatic trigger.
  • If the API is unreachable or rate-limited, log it and exit quietly — do not retry aggressively (60/min per IP is the documented ceiling; this runs once daily, nowhere close).

© aeonfun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunter-22 of aeonfun/aeon.

Open the folder on GitHubat commit f252074

Compare with similar skills

Hunter 22 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunter 22 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunter 22 this skillaeonfun/aeon767—~1.7kAutomated safety check: PassMIT
Agentic GitHub Actions Auditortrailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Audit Scopeforefy/.context152—~2.3kAutomated safety check: PassMIT
Codebase Audit Pre Pushsickn33/agentic-awesome-skills47k2 repos~2.1kAutomated safety check: NotesMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Repo SentinelMathews-Tom/armory327—~2.2kAutomated safety check: PassMIT

Similar skills

  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.4k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Codebase Audit Pre Push

    sickn33/agentic-awesome-skills

    Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues.

    47k GitHub starsUsed in 2 repos~2.1k tokens
    SecurityAuto-check: notes
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Repo Sentinel

    Mathews-Tom/armory

    Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses.

    327 GitHub stars~2.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from aeonfun/aeon

All 82 skills in this repo
  • Browses open tasks on the TaskMarket agent-worker market and, with explicit operator approval, creates tasks, tracks submissions and submits finished work.

    767 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Sets up and manages an Aeon agent instance that runs skills on a schedule through GitHub Actions: starting, rescheduling, debugging, editing skills and mining chat history.

    767 GitHub stars~8.8k tokensUpdated today
    Auto-check: warnings
  • Reads a Base Account's address, portfolio and transaction history through the Base MCP server, and stays strictly read-only in unattended Aeon runs, reporting only changes.

    767 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Audits every page of a site each day from its sitemap, scores on-page and technical SEO, checks duplicates across pages and reports what changed since the last run.

    767 GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Action Converter

    aeonfun/aeon

    5 concrete real-life actions, leverage-scored against open loops with specificity and anti-fluff gates

    767 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Aeon Config Doctor

    aeonfun/aeon

    Static linter for an Aeon instance's configuration that catches silent failures such as unquoted schedules, duplicate keys, unconfigured skills and broken MCP references.

    767 GitHub stars~3.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Hunter 22

What does Hunter 22 do?

Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw…. Hunter 22 is an agent skill from aeonfun/aeon. Scan the ClawHunter agent bounty marketplace for opportunities that genuinely match this agent's real capabilities (code, security research, writing) and surface only real matches — never a raw unfiltered dump.

When should I use Hunter 22?

Hunter 22 fits situations like: tasks that involve Security review.

How do I install Hunter 22 in Claude Code?

Run `npx skills add aeonfun/aeon --skill hunter-22 -a claude-code`. Or copy the skill folder (skills/hunter-22 in aeonfun/aeon) into .claude/skills/hunter-22 in your project. Claude Code loads it when a task matches its description.

How do I install Hunter 22 in Codex?

Run `npx skills add aeonfun/aeon --skill hunter-22 -a codex`. Or copy the skill folder (skills/hunter-22 in aeonfun/aeon) into .agents/skills/hunter-22 in your project. Codex loads it when a task matches its description.

Can I use Hunter 22 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aeonfun/aeon --skill hunter-22 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunter-22, .gemini/skills/hunter-22, .github/skills/hunter-22 and .opencode/skills/hunter-22 in your project.

What does Hunter 22 need to run?

Going by SKILL.md and its folder, Hunter 22 needs the command-line tools its instructions call (curl and node).

Does Hunter 22 access the network?

SKILL.md names 1 domain. In commands or code: clawhunter.fun; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Hunter 22 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunter 22 use?

Hunter 22 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunter 22 use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunter 22?

Skills that share tags, products or a category with Hunter 22: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Audit Scope (forefy/.context, 152 stars), Codebase Audit Pre Push (sickn33/agentic-awesome-skills, 47k stars) and Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunter 22?

aeonfun (a GitHub organization) maintains it in aeonfun/aeon, which has 767 GitHub stars. The repository holds 82 skills in this directory. The repository was last updated on October 6, 2026.

Source: aeonfun/aeon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.