Connect Apps with Composio
ComposioHQ/awesome-claude-skills
Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.
Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action
$ npx skills add aeonfun/aeon --skill inbox-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aeonfun/aeon inbox-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/inbox-triage .claude/skills/inbox-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "inbox-triage" agent skill from https://github.com/aeonfun/aeon/tree/main/skills/inbox-triage into .claude/skills/inbox-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "inbox-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aeonfun/aeon/tree/main/skills/inbox-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aeonfun/aeon --skill inbox-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aeonfun/aeon inbox-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/inbox-triage .agents/skills/inbox-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "inbox-triage" agent skill from https://github.com/aeonfun/aeon/tree/main/skills/inbox-triage into .agents/skills/inbox-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "inbox-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aeonfun/aeon --skill inbox-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aeonfun/aeon inbox-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/inbox-triage .cursor/skills/inbox-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "inbox-triage" agent skill from https://github.com/aeonfun/aeon/tree/main/skills/inbox-triage into .cursor/skills/inbox-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "inbox-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aeonfun/aeon.git --path skills/inbox-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aeonfun/aeon --skill inbox-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aeonfun/aeon inbox-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/inbox-triage .gemini/skills/inbox-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "inbox-triage" agent skill from https://github.com/aeonfun/aeon/tree/main/skills/inbox-triage into .gemini/skills/inbox-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "inbox-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aeonfun/aeon inbox-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aeonfun/aeon --skill inbox-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/inbox-triage .github/skills/inbox-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "inbox-triage" agent skill from https://github.com/aeonfun/aeon/tree/main/skills/inbox-triage into .github/skills/inbox-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "inbox-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aeonfun/aeon --skill inbox-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aeonfun/aeon inbox-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aeonfun/aeon.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/inbox-triage .opencode/skills/inbox-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "inbox-triage" agent skill from https://github.com/aeonfun/aeon/tree/main/skills/inbox-triage into .opencode/skills/inbox-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "inbox-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
inbox-triageDaily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action
Inbox Triage is an agent skill from aeonfun/aeon. Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Productivity & Automation, covering Email management. It works with GitHub. The repository describes itself as: The most autonomous AI agent framework: runs unattended on GitHub Actions, self-healing skills, drives Claude Code, Grok, Codex & more. No approval loops. Configure once, forget… The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c0cb7c4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comapi.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Inbox Triage loads about 1.8k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 675 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aeonfun/aeon at commit c0cb7c4, republished under its MIT licence (© aeonfun). 675 words, ~1,833 tokens.
.claude/skills/inbox-triage/SKILL.md (or your agent's skills folder).Today is ${today}. Read memory/MEMORY.md before starting.
Hand-tracked follow-ups live in MEMORY.md. vuln-tracker tracks the operator's vuln PRs by scanning branch names and ages the memory/pending-disclosures/ queue. Neither reads from the actual GitHub notification inbox. When a maintainer replies to a vuln PR — or a security advisory opens on a watched repo — it sits unread until someone manually checks GitHub. This skill reads the inbox and routes what needs action.
vuln-tracker covers PR and disclosure lifecycle by branch and draft state. This skill covers the notification layer — inbound responses, review requests, security alerts, mentions.
Run:
gh api /notifications --paginate 2>&1Parse the JSON array. If the command errors or returns an empty array [], log INBOX_TRIAGE_SKIP: no notifications and stop.
Limit to the first 100 notifications if --paginate returns more (GitHub caps at 50 per page; two pages is enough).
For each notification record:
idreason — why you're being notified (mention, review_requested, author, state_change, security_alert, assign, etc.)subject.titlesubject.type — PullRequest, Issue, Release, etc.subject.url — API URL for the subjectrepository.full_nameupdated_at — ISO timestampKeep notifications where unread: true AND updated_at is within the last 14 days. Discard older or read ones.
If zero remain after filtering: log INBOX_TRIAGE_SKIP: no actionable notifications within 14 days and stop.
Assign each notification to exactly one category (first match wins):
| Category | Match criteria |
|---|---|
SECURITY | reason == "security_alert" OR title contains any of: vulnerability, vuln, CVE, advisory, security |
VULN_REPLY | subject.type == "PullRequest" AND reason is one of: author, state_change, comment AND repository.full_name is NOT under the operator's own account/org (derive the operator's GitHub handle from soul/SOUL.md or the workflow's GITHUB_ACTOR — these are PRs filed on third-party repos by the vuln-scanner) |
REVIEW_NEEDED | reason == "review_requested" |
MENTION | reason == "mention" OR reason == "team_mention" |
GENERAL | everything else |
For each VULN_REPLY notification, compute age_days = today minus updated_at date (integer days).
Flag urgency:
CRITICAL — age_days > 7 (maintainer likely hasn't responded)AGING — age_days 3–7FRESH — age_days < 3Cross-reference with memory/topics/vuln-followup.md if it exists: look for the PR title in that file and pull any tracked notes (e.g. "approved", "NEEDS-ANSWER", merge status).
For each notification in SECURITY, VULN_REPLY (CRITICAL or AGING), REVIEW_NEEDED, and MENTION categories:
Try to get the HTML URL via:
gh api {subject.url} --jq '.html_url' 2>/dev/nullIf that fails, construct the URL manually:
https://github.com/{repository.full_name}/pulls/{number} for PRs
https://github.com/{repository.full_name}/issues/{number} for issues
(Extract the number from the tail of subject.url.)
Overwrite memory/topics/inbox-triage.md:
# GitHub Inbox Triage
Last run: {today}
Scanned: {N} unread notifications ({N} within 14 days)
## Action Required
### Security ({count})
{for each SECURITY item, sorted by age:}
- **{repo}**: {title} ({age_days}d) — {html_url}
{if none:}
None.
### Vuln PR Replies ({count_critical} critical, {count_aging} aging)
{for each VULN_REPLY sorted by age desc:}
- **[{CRITICAL|AGING|FRESH}]** `{repo}` ({age_days}d): {title} — {html_url}
{if vuln-followup note found:} _{tracked note}_
{if none:}
None.
### Review Requested ({count})
{for each REVIEW_NEEDED item:}
- **{repo}**: {title} — {html_url}
{if none:}
None.
### Mentions ({count})
{for each MENTION item:}
- **{repo}**: {title} — {html_url}
{if none:}
None.
## No Action Needed
{count_general} general notifications (subscriptions, automated state changes).Read memory/MEMORY.md. Find the ## Known Follow-ups section.
Add any VULN_REPLY CRITICAL item not already tracked there — append:
- **{repo} #{number} NEEDS-ANSWER** — {age_days}d since maintainer activity ({url})Update any existing NEEDS-ANSWER item for a PR that now appears as FRESH in VULN_REPLY (maintainer responded recently) — change its note to RESPONDED — verify resolution.
Do NOT add GENERAL, REVIEW_NEEDED, MENTION, or SECURITY items to MEMORY.md Known Follow-ups (too noisy; security items warrant a separate issue if severe).
Only send if at least one of:
Write to .pending-notify-temp/inbox-triage-${today}.md:
inbox — {today}
{if SECURITY:}
security alert: {repo} — {title}
{if VULN_REPLY CRITICAL:}
vuln PRs aging: {comma-separated list of "repo (Nd)"}
{if REVIEW_NEEDED:}
review needed: {comma-separated repo list}
{if 3+ MENTION:}
{N} mentions
read it: memory/topics/inbox-triage.mdThen:
./notify -f .pending-notify-temp/inbox-triage-${today}.mdIf nothing meets the threshold: skip notification. Log that no notification was sent.
Append to memory/logs/${today}.md:
### inbox-triage
- **Scanned:** {N} notifications
- **Security:** {N}
- **Vuln replies:** {N total} ({N_critical} critical, {N_aging} aging, {N_fresh} fresh)
- **Review needed:** {N}
- **Mentions:** {N}
- **MEMORY.md follow-ups updated:** {yes/no — what changed}
- **Notification sent:** {yes/no}
- INBOX_TRIAGE_OKIf skipped:
### inbox-triage
- INBOX_TRIAGE_SKIP: {reason}None beyond GITHUB_TOKEN, which GitHub Actions sets automatically and gh uses internally.
Uses gh api for all GitHub calls — it handles auth internally, so no $SECRET ever appears on the command line for the Bash permission layer to refuse. gh api works in a GitHub Actions run. If gh api /notifications fails (rate limit, auth error), log the error and exit with INBOX_TRIAGE_SKIP: api error. Use WebFetch as a fallback only if gh is unavailable — the endpoint is https://api.github.com/notifications with Authorization: Bearer $GITHUB_TOKEN, but WebFetch can't carry that auth header; prefer gh.
vuln-tracker — vuln-tracker tracks lifecycle by branch name. This catches inbound maintainer replies via notifications.vuln-tracker's disclosure-queue aging - that manages memory/pending-disclosures/ advisory drafts. This reads GitHub security alerts and PR responses.© aeonfun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/inbox-triage of aeonfun/aeon.
Open the folder on GitHubat commit c0cb7c4
Inbox Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Inbox Triage this skillaeonfun/aeon | 767 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Connect Apps with ComposioComposioHQ/awesome-claude-skills | 77k | 3 repos | ~557 | Automated safety check: Pass | None | |
| Composio Cloud Toolsquarqlabs/argus | 279 | — | ~543 | Automated safety check: Pass | Apache-2.0 | |
| ClawdiClawdi-AI/clawdi | 103 | — | ~4.8k | Automated safety check: Notes | MIT | |
| ClawdiClawdi-AI/clawdi | 103 | — | ~4k | Automated safety check: Notes | MIT | |
| ConnectComposioHQ/awesome-claude-skills | 77k | 3 repos | ~987 | Automated safety check: Pass | None |
ComposioHQ/awesome-claude-skills
Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.
quarqlabs/argus
Routes requests to external SaaS apps such as GitHub, Gmail, Google Calendar, Slack, Notion and Linear through cloud tools, with safeguards on irreversible actions.
Clawdi-AI/clawdi
API keys, tokens, memory, sessions, Projects, integrations. An agent skill from Clawdi-AI/clawdi.
Clawdi-AI/clawdi
API keys, tokens, memory, sessions, Projects, integrations. An agent skill from Clawdi-AI/clawdi.
ComposioHQ/awesome-claude-skills
Connect Claude to any app. An agent skill from ComposioHQ/awesome-claude-skills.
vellum-ai/vellum-assistant
Create and manage polling watchers that monitor external services (Gmail, Google Calendar, GitHub, Linear, Outlook) for events and process them with custom action prompts
aeonfun/aeon
Browses open tasks on the TaskMarket agent-worker market and, with explicit operator approval, creates tasks, tracks submissions and submits finished work.
aeonfun/aeon
Sets up and manages an Aeon agent instance that runs skills on a schedule through GitHub Actions: starting, rescheduling, debugging, editing skills and mining chat history.
aeonfun/aeon
Reads a Base Account's address, portfolio and transaction history through the Base MCP server, and stays strictly read-only in unattended Aeon runs, reporting only changes.
aeonfun/aeon
Audits every page of a site each day from its sitemap, scores on-page and technical SEO, checks duplicates across pages and reports what changed since the last run.
aeonfun/aeon
5 concrete real-life actions, leverage-scored against open loops with specificity and anti-fluff gates
aeonfun/aeon
Static linter for an Aeon instance's configuration that catches silent failures such as unquoted schedules, duplicate keys, unconfigured skills and broken MCP references.
Works with
Categories
Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action. Inbox Triage is an agent skill from aeonfun/aeon.
Inbox Triage fits situations like: tasks that involve Email management.
Run `npx skills add aeonfun/aeon --skill inbox-triage -a claude-code`. Or copy the skill folder (skills/inbox-triage in aeonfun/aeon) into .claude/skills/inbox-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aeonfun/aeon --skill inbox-triage -a codex`. Or copy the skill folder (skills/inbox-triage in aeonfun/aeon) into .agents/skills/inbox-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aeonfun/aeon --skill inbox-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/inbox-triage, .gemini/skills/inbox-triage, .github/skills/inbox-triage and .opencode/skills/inbox-triage in your project.
Going by SKILL.md and its folder, Inbox Triage needs the command-line tools its instructions call (gh) and credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.
SKILL.md names 2 domains. In commands or code: github.com and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Inbox Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Inbox Triage: Connect Apps with Composio (ComposioHQ/awesome-claude-skills, 77k stars), Composio Cloud Tools (quarqlabs/argus, 279 stars), Clawdi (Clawdi-AI/clawdi, 103 stars) and Clawdi (Clawdi-AI/clawdi, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aeonfun (a GitHub organization) maintains it in aeonfun/aeon, which has 767 GitHub stars. The repository holds 82 skills in this directory. The repository was last updated on October 8, 2026.
Source: aeonfun/aeon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.