Agent skill

Inbox Triage

by aeonfun in aeonfun/aeon

Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action

MITAuto-check passedProductivity & Automation

Install Inbox Triage

skills CLI
$ npx skills add aeonfun/aeon --skill inbox-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aeonfun/aeon inbox-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/inbox-triage .claude/skills/inbox-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
inbox-triage
GitHub stars
767
Token cost
~1.8k tokens
SKILL.md length
675 words
Files
1
Skills in repo
82
Repo updated
First seen
Licence
MIT

At a glance

Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action

  • Works in 9 steps: Fetch GitHub notifications → Filter → Categorize → …
  • Tasks that involve Email management
  • SKILL.md covers Why this skill exists, Steps, Required Env Vars and Network Note, plus 1 more section
  • Calls gh; reaches github.com and api.github.com; needs GITHUB_TOKEN

What it does

Inbox Triage is an agent skill from aeonfun/aeon. Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Email management. It works with GitHub. The repository describes itself as: The most autonomous AI agent framework: runs unattended on GitHub Actions, self-healing skills, drives Claude Code, Grok, Codex & more. No approval loops. Configure once, forget… The licence is MIT.

When your agent uses it

  • Tasks that involve Email management

Example prompts

  • “/inbox-triage”

Requirements

  • A credential in GITHUB_TOKEN

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Fetch GitHub notifications
  2. Filter
  3. Categorize
  4. Age vuln PR replies
  5. Resolve HTML URLs for action items
  6. Write triage summary
  7. Update MEMORY.md known follow-ups
  8. Send notification
  9. Log

What it can do on your machine

Read from SKILL.md and the folder at commit c0cb7c4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Inbox Triage loads about 1.8k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 675 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aeonfun/aeon at commit c0cb7c4, republished under its MIT licence (© aeonfun). 675 words, ~1,833 tokens.

Download SKILL.mdSave it as .claude/skills/inbox-triage/SKILL.md (or your agent's skills folder).
name
inbox-triage
description
Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action
metadata.title
Inbox Triage
metadata.category
dev
metadata.tags
github, security, meta

Today is ${today}. Read memory/MEMORY.md before starting.

Why this skill exists

Hand-tracked follow-ups live in MEMORY.md. vuln-tracker tracks the operator's vuln PRs by scanning branch names and ages the memory/pending-disclosures/ queue. Neither reads from the actual GitHub notification inbox. When a maintainer replies to a vuln PR — or a security advisory opens on a watched repo — it sits unread until someone manually checks GitHub. This skill reads the inbox and routes what needs action.

vuln-tracker covers PR and disclosure lifecycle by branch and draft state. This skill covers the notification layer — inbound responses, review requests, security alerts, mentions.

Steps

1. Fetch GitHub notifications

Run:

bash
gh api /notifications --paginate 2>&1

Parse the JSON array. If the command errors or returns an empty array [], log INBOX_TRIAGE_SKIP: no notifications and stop.

Limit to the first 100 notifications if --paginate returns more (GitHub caps at 50 per page; two pages is enough).

For each notification record:

  • id
  • reason — why you're being notified (mention, review_requested, author, state_change, security_alert, assign, etc.)
  • subject.title
  • subject.type — PullRequest, Issue, Release, etc.
  • subject.url — API URL for the subject
  • repository.full_name
  • updated_at — ISO timestamp
2. Filter

Keep notifications where unread: true AND updated_at is within the last 14 days. Discard older or read ones.

If zero remain after filtering: log INBOX_TRIAGE_SKIP: no actionable notifications within 14 days and stop.

3. Categorize

Assign each notification to exactly one category (first match wins):

CategoryMatch criteria
SECURITYreason == "security_alert" OR title contains any of: vulnerability, vuln, CVE, advisory, security
VULN_REPLYsubject.type == "PullRequest" AND reason is one of: author, state_change, comment AND repository.full_name is NOT under the operator's own account/org (derive the operator's GitHub handle from soul/SOUL.md or the workflow's GITHUB_ACTOR — these are PRs filed on third-party repos by the vuln-scanner)
REVIEW_NEEDEDreason == "review_requested"
MENTIONreason == "mention" OR reason == "team_mention"
GENERALeverything else
4. Age vuln PR replies

For each VULN_REPLY notification, compute age_days = today minus updated_at date (integer days).

Flag urgency:

  • CRITICAL — age_days > 7 (maintainer likely hasn't responded)
  • AGING — age_days 3–7
  • FRESH — age_days < 3

Cross-reference with memory/topics/vuln-followup.md if it exists: look for the PR title in that file and pull any tracked notes (e.g. "approved", "NEEDS-ANSWER", merge status).

5. Resolve HTML URLs for action items

For each notification in SECURITY, VULN_REPLY (CRITICAL or AGING), REVIEW_NEEDED, and MENTION categories:

Try to get the HTML URL via:

bash
gh api {subject.url} --jq '.html_url' 2>/dev/null

If that fails, construct the URL manually: https://github.com/{repository.full_name}/pulls/{number} for PRs https://github.com/{repository.full_name}/issues/{number} for issues

(Extract the number from the tail of subject.url.)

6. Write triage summary

Overwrite memory/topics/inbox-triage.md:

markdown
# GitHub Inbox Triage

Last run: {today}
Scanned: {N} unread notifications ({N} within 14 days)

## Action Required

### Security ({count})
{for each SECURITY item, sorted by age:}
- **{repo}**: {title} ({age_days}d) — {html_url}

{if none:}
None.

### Vuln PR Replies ({count_critical} critical, {count_aging} aging)
{for each VULN_REPLY sorted by age desc:}
- **[{CRITICAL|AGING|FRESH}]** `{repo}` ({age_days}d): {title} — {html_url}
  {if vuln-followup note found:} _{tracked note}_

{if none:}
None.

### Review Requested ({count})
{for each REVIEW_NEEDED item:}
- **{repo}**: {title} — {html_url}

{if none:}
None.

### Mentions ({count})
{for each MENTION item:}
- **{repo}**: {title} — {html_url}

{if none:}
None.

## No Action Needed
{count_general} general notifications (subscriptions, automated state changes).
Show full SKILL.md (273 more words)Show less
7. Update MEMORY.md known follow-ups

Read memory/MEMORY.md. Find the ## Known Follow-ups section.

Add any VULN_REPLY CRITICAL item not already tracked there — append:

- **{repo} #{number} NEEDS-ANSWER** — {age_days}d since maintainer activity ({url})

Update any existing NEEDS-ANSWER item for a PR that now appears as FRESH in VULN_REPLY (maintainer responded recently) — change its note to RESPONDED — verify resolution.

Do NOT add GENERAL, REVIEW_NEEDED, MENTION, or SECURITY items to MEMORY.md Known Follow-ups (too noisy; security items warrant a separate issue if severe).

8. Send notification

Only send if at least one of:

  • Any SECURITY item
  • Any VULN_REPLY where urgency == CRITICAL
  • Any REVIEW_NEEDED item
  • Three or more MENTION items

Write to .pending-notify-temp/inbox-triage-${today}.md:

inbox — {today}

{if SECURITY:}
security alert: {repo} — {title}

{if VULN_REPLY CRITICAL:}
vuln PRs aging: {comma-separated list of "repo (Nd)"}

{if REVIEW_NEEDED:}
review needed: {comma-separated repo list}

{if 3+ MENTION:}
{N} mentions

read it: memory/topics/inbox-triage.md

Then:

bash
./notify -f .pending-notify-temp/inbox-triage-${today}.md

If nothing meets the threshold: skip notification. Log that no notification was sent.

9. Log

Append to memory/logs/${today}.md:

markdown
### inbox-triage
- **Scanned:** {N} notifications
- **Security:** {N}
- **Vuln replies:** {N total} ({N_critical} critical, {N_aging} aging, {N_fresh} fresh)
- **Review needed:** {N}
- **Mentions:** {N}
- **MEMORY.md follow-ups updated:** {yes/no — what changed}
- **Notification sent:** {yes/no}
- INBOX_TRIAGE_OK

If skipped:

markdown
### inbox-triage
- INBOX_TRIAGE_SKIP: {reason}

Required Env Vars

None beyond GITHUB_TOKEN, which GitHub Actions sets automatically and gh uses internally.

Network Note

Uses gh api for all GitHub calls — it handles auth internally, so no $SECRET ever appears on the command line for the Bash permission layer to refuse. gh api works in a GitHub Actions run. If gh api /notifications fails (rate limit, auth error), log the error and exit with INBOX_TRIAGE_SKIP: api error. Use WebFetch as a fallback only if gh is unavailable — the endpoint is https://api.github.com/notifications with Authorization: Bearer $GITHUB_TOKEN, but WebFetch can't carry that auth header; prefer gh.

What this is NOT

  • Not a replacement for hand-tracked follow-ups in MEMORY.md. This reads the raw GitHub inbox.
  • Not a duplicate of vuln-tracker — vuln-tracker tracks lifecycle by branch name. This catches inbound maintainer replies via notifications.
  • Not a duplicate of vuln-tracker's disclosure-queue aging - that manages memory/pending-disclosures/ advisory drafts. This reads GitHub security alerts and PR responses.

© aeonfun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/inbox-triage of aeonfun/aeon.

Open the folder on GitHubat commit c0cb7c4

Compare with similar skills

Inbox Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Inbox Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Inbox Triage this skillaeonfun/aeon767—~1.8kAutomated safety check: PassMIT
Connect Apps with ComposioComposioHQ/awesome-claude-skills77k3 repos~557Automated safety check: PassNone
Composio Cloud Toolsquarqlabs/argus279—~543Automated safety check: PassApache-2.0
ClawdiClawdi-AI/clawdi103—~4.8kAutomated safety check: NotesMIT
ClawdiClawdi-AI/clawdi103—~4kAutomated safety check: NotesMIT
ConnectComposioHQ/awesome-claude-skills77k3 repos~987Automated safety check: PassNone

Similar skills

  • Connect Apps with Composio

    ComposioHQ/awesome-claude-skills

    Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.

    77k GitHub starsUsed in 3 repos~557 tokens
    Productivity & AutomationAuto-check passed
  • Composio Cloud Tools

    quarqlabs/argus

    Routes requests to external SaaS apps such as GitHub, Gmail, Google Calendar, Slack, Notion and Linear through cloud tools, with safeguards on irreversible actions.

    279 GitHub stars~543 tokensUpdated 4 mo ago
    Productivity & AutomationAuto-check passed
  • Clawdi

    Clawdi-AI/clawdi

    API keys, tokens, memory, sessions, Projects, integrations. An agent skill from Clawdi-AI/clawdi.

    103 GitHub stars~4.8k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Clawdi

    Clawdi-AI/clawdi

    API keys, tokens, memory, sessions, Projects, integrations. An agent skill from Clawdi-AI/clawdi.

    103 GitHub stars~4k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Connect

    ComposioHQ/awesome-claude-skills

    Connect Claude to any app. An agent skill from ComposioHQ/awesome-claude-skills.

    77k GitHub starsUsed in 3 repos~987 tokens
    Productivity & AutomationAuto-check passed
  • Watcher

    vellum-ai/vellum-assistant

    Create and manage polling watchers that monitor external services (Gmail, Google Calendar, GitHub, Linear, Outlook) for events and process them with custom action prompts

    1.4k GitHub stars~1.7k tokensUpdated yesterday
    Productivity & AutomationAuto-check passed

More from aeonfun/aeon

All 82 skills in this repo
  • Browses open tasks on the TaskMarket agent-worker market and, with explicit operator approval, creates tasks, tracks submissions and submits finished work.

    767 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Sets up and manages an Aeon agent instance that runs skills on a schedule through GitHub Actions: starting, rescheduling, debugging, editing skills and mining chat history.

    767 GitHub stars~9k tokensUpdated 2 days ago
    Auto-check: warnings
  • Reads a Base Account's address, portfolio and transaction history through the Base MCP server, and stays strictly read-only in unattended Aeon runs, reporting only changes.

    767 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Audits every page of a site each day from its sitemap, scores on-page and technical SEO, checks duplicates across pages and reports what changed since the last run.

    767 GitHub stars~5.1k tokensUpdated 2 days ago
    Auto-check passed
  • Action Converter

    aeonfun/aeon

    5 concrete real-life actions, leverage-scored against open loops with specificity and anti-fluff gates

    767 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Aeon Config Doctor

    aeonfun/aeon

    Static linter for an Aeon instance's configuration that catches silent failures such as unquoted schedules, duplicate keys, unconfigured skills and broken MCP references.

    767 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Inbox Triage

What does Inbox Triage do?

Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action. Inbox Triage is an agent skill from aeonfun/aeon.

When should I use Inbox Triage?

Inbox Triage fits situations like: tasks that involve Email management.

How do I install Inbox Triage in Claude Code?

Run `npx skills add aeonfun/aeon --skill inbox-triage -a claude-code`. Or copy the skill folder (skills/inbox-triage in aeonfun/aeon) into .claude/skills/inbox-triage in your project. Claude Code loads it when a task matches its description.

How do I install Inbox Triage in Codex?

Run `npx skills add aeonfun/aeon --skill inbox-triage -a codex`. Or copy the skill folder (skills/inbox-triage in aeonfun/aeon) into .agents/skills/inbox-triage in your project. Codex loads it when a task matches its description.

Can I use Inbox Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aeonfun/aeon --skill inbox-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/inbox-triage, .gemini/skills/inbox-triage, .github/skills/inbox-triage and .opencode/skills/inbox-triage in your project.

What does Inbox Triage need to run?

Going by SKILL.md and its folder, Inbox Triage needs the command-line tools its instructions call (gh) and credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.

Does Inbox Triage access the network?

SKILL.md names 2 domains. In commands or code: github.com and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Inbox Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Inbox Triage use?

Inbox Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Inbox Triage use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Inbox Triage?

Skills that share tags, products or a category with Inbox Triage: Connect Apps with Composio (ComposioHQ/awesome-claude-skills, 77k stars), Composio Cloud Tools (quarqlabs/argus, 279 stars), Clawdi (Clawdi-AI/clawdi, 103 stars) and Clawdi (Clawdi-AI/clawdi, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Inbox Triage?

aeonfun (a GitHub organization) maintains it in aeonfun/aeon, which has 767 GitHub stars. The repository holds 82 skills in this directory. The repository was last updated on October 8, 2026.

Source: aeonfun/aeon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.