Agent skill

Aeon Vuln Scanner

by BankrBot in BankrBot/skills

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

No licenceAuto-check passedSecurity

Install Aeon Vuln Scanner

skills CLI
$ npx skills add BankrBot/skills --skill aeon-vuln-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BankrBot/skills aeon-vuln-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BankrBot/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/aeon-vuln-scanner .claude/skills/aeon-vuln-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aeon-vuln-scanner
GitHub stars
1.2k
Token cost
~858 tokens
SKILL.md length
296 words
Files
2
Skills in repo
106
Repo updated
First seen
Licence
None found

At a glance

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

  • Works in 4 steps: Open the file at the reported line. Read… → Write one sentence: what attacker… → Check the call path — reachable from… → …
  • Tasks that involve Vulnerability scanning
  • SKILL.md covers Inputs, Target selection, Scanners and Triage (per candidate), plus 3 more sections
  • Calls semgrep and gh; needs GH_TOKEN

What it does

Aeon Vuln Scanner is an agent skill from BankrBot/skills. Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed dependency CVEs. Semgrep + TruffleHog + osv-scanner + Slither with reachability triage. Skips targets that have no safe disclosure channel. Triggers: "vuln scan owner/repo", "audit this repo", "responsible-disclosure scan", "check for secret leaks", "scan dependencies for CVEs".

Its SKILL.md is about 860 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `catalog.json`).

It sits in Security, covering Vulnerability scanning, Secrets management and Static analysis and SAST. It works with Semgrep. The repository describes itself as: Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

When your agent uses it

  • Tasks that involve Vulnerability scanning
  • Tasks that involve Secrets management
  • Tasks that involve Static analysis and SAST

Example prompts

  • “vuln scan owner/repo”
  • “audit this repo”
  • “responsible-disclosure scan”
  • “/aeon-vuln-scanner”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Open the file at the reported line. Read 30-50 lines of context.
  2. Write one sentence: what attacker controls, what they achieve. Can't? Discard.
  3. Check the call path — reachable from external input in production code?
  4. Drop if in tests, fixtures, examples, behind a feature flag, or requires attacker privs ≥ what's gained.

What it can do on your machine

Read from SKILL.md and the folder at commit dc47eed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aeon Vuln Scanner loads about 858 tokens when it runs. Until then it costs about 122 tokens; SKILL.md has 296 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~858

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 296 words (~858 tokens).

“A scanner that dumps zero-days into public PRs isn't a helper — it's a publisher. This skill triages every finding by reading the code and routes to the right disclosure channel.”

— opening of SKILL.md by BankrBot
name
aeon-vuln-scanner

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in aeon-vuln-scanner of BankrBot/skills.

  • SKILL.md
  • catalog.json

Open the folder on GitHubat commit dc47eed

Compare with similar skills

Aeon Vuln Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aeon Vuln Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aeon Vuln Scanner this skillBankrBot/skills1.2k—~858Automated safety check: PassNone
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Building Devsecops Pipeline With GitLab CImukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Warden Scanjeremylongshore/tons-of-skills-marketplace2.8k—~750Automated safety check: NotesMIT
Detection Breadthdeonmenezes/mantishack503—~510Automated safety check: PassApache-2.0
Semgrep Rule Creatorskrun-dev/skrun210—~1.3kAutomated safety check: PassMIT

Similar skills

  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Building Devsecops Pipeline With GitLab CI

    mukul975/Anthropic-Cybersecurity-Skills

    Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Warden Scan

    jeremylongshore/tons-of-skills-marketplace

    Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~750 tokensUpdated yesterday
    SecurityAuto-check: notes
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    503 GitHub stars~510 tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Semgrep Rule Creator

    skrun-dev/skrun

    Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

    210 GitHub stars~1.3k tokensUpdated 18 days ago
    SecurityAuto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check: notes

More from BankrBot/skills

All 106 skills in this repo
  • OnchainKit App Builder

    BankrBot/skills

    Builds onchain apps with Coinbase's OnchainKit React components and TypeScript utilities: wallet connection, identity, token swaps, transactions and checkout flows.

    1.2k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Lists AgenticBets prediction markets on Base, shows odds, places UP or DOWN bets on token prices in USDC and claims winnings through the Bankr wallet API.

    1.2k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • AI2Human Task Router

    BankrBot/skills

    Creates AI2Human tasks for steps that need a real person, such as manual QA or local checks, and returns a task URL the agent can track.

    1.2k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Lets an agent inspect and operate AZZLE V2 tasks on Base through Bankr, from posting and claiming to funding, delivery, release and disputes, behind verified deployment pins.

    1.2k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • B20 Console

    BankrBot/skills

    Inspect B20 token contract addresses on Base through B20 Console.

    1.2k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Capacitr

    BankrBot/skills

    Paste a URL or free text and get matched Polymarket / Hyperliquid / Deribit markets with Quotient edge scores.

    1.2k GitHub stars~3k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Aeon Vuln Scanner

What does Aeon Vuln Scanner do?

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…. Aeon Vuln Scanner is an agent skill from BankrBot/skills. Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed dependency CVEs.

When should I use Aeon Vuln Scanner?

Aeon Vuln Scanner fits situations like: tasks that involve Vulnerability scanning; tasks that involve Secrets management; tasks that involve Static analysis and SAST.

How do I install Aeon Vuln Scanner in Claude Code?

Run `npx skills add BankrBot/skills --skill aeon-vuln-scanner -a claude-code`. Or copy the skill folder (aeon-vuln-scanner in BankrBot/skills) into .claude/skills/aeon-vuln-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Aeon Vuln Scanner in Codex?

Run `npx skills add BankrBot/skills --skill aeon-vuln-scanner -a codex`. Or copy the skill folder (aeon-vuln-scanner in BankrBot/skills) into .agents/skills/aeon-vuln-scanner in your project. Codex loads it when a task matches its description.

Can I use Aeon Vuln Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BankrBot/skills --skill aeon-vuln-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aeon-vuln-scanner, .gemini/skills/aeon-vuln-scanner, .github/skills/aeon-vuln-scanner and .opencode/skills/aeon-vuln-scanner in your project.

What does Aeon Vuln Scanner need to run?

Going by SKILL.md and its folder, Aeon Vuln Scanner needs the command-line tools its instructions call (semgrep and gh) and credentials named GH_TOKEN.

Does Aeon Vuln Scanner access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Aeon Vuln Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aeon Vuln Scanner use?

No licence was found for Aeon Vuln Scanner or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Aeon Vuln Scanner use?

About 858 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aeon Vuln Scanner?

Skills that share tags, products or a category with Aeon Vuln Scanner: Security Reviewer (Jeffallan/claude-skills, 12k stars), Building Devsecops Pipeline With GitLab CI (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Warden Scan (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Detection Breadth (deonmenezes/mantishack, 503 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aeon Vuln Scanner?

BankrBot (a GitHub organization) maintains it in BankrBot/skills, which has 1,202 GitHub stars. The repository holds 106 skills in this directory. The repository was last updated on October 10, 2026.

Source: BankrBot/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.