
Aeon Skill Security Scan
- 14 installs
- 1.2k repo stars
- Updated August 1, 2026
- bankrbot/skills
aeon-skill-security-scan is a Claude skill that audits installed skills' SKILL.md and scripts for shell injection, secret exfiltration, prompt-override payloads, and obfuscation before they run.
About
aeon-skill-security-scan is a Claude skill that audits installed skills before you run them. It scans each SKILL.md and companion script for shell injection, secret exfiltration, path traversal, prompt-override payloads, destructive commands, and modern obfuscation like zero-width Unicode and base64-decode pipes. It surfaces only new or resolved findings versus prior scans and stays read-only. A developer uses it to check whether a skill is safe to install.
- Audits installed skills before you run them for injection and exfiltration risks
- Scans SKILL.md and companion scripts for shell injection, secret exfiltration, and prompt-override payloads
- Detects 2026-era obfuscation: zero-width Unicode, bidi override, base64-decode pipes, and SSRF hosts
Aeon Skill Security Scan by the numbers
- 14 all-time installs (skills.sh)
- Ranked #1,623 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 4, 2026 (Skillselion catalog sync)
aeon-skill-security-scan capabilities & compatibility
Read-only local scanning; state in scan-state.json
- Capabilities
- skill evals · skill repair · security audit
- Works with
- github
- Use cases
- security audit · code review
- Pricing
- Free
What aeon-skill-security-scan says it does
A malicious or sloppy skill can shell-inject, exfiltrate secrets, override instructions, or run destructive commands.
Read-only scanning.
npx skills add https://github.com/bankrbot/skills --skill aeon-skill-security-scanAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 14 |
|---|---|
| repo stars | ★ 1.2k |
| Last updated | August 1, 2026 |
| Repository | bankrbot/skills ↗ |
What it does
Audit installed skills' SKILL.md and scripts for injection, exfiltration, and obfuscation before running them.
Who is it for?
Vetting whether an installed skill is safe to run
Skip if: Modifying skills, since it is read-only scanning
When should I use this skill?
You want to audit a skill or check whether it is safe to install
What you get
A CLEAN / ATTENTION / DEGRADED verdict with per-finding remediation and delta vs prior scans
- A CLEAN/ATTENTION/DEGRADED verdict with per-skill PASS/WARN/FAIL
- Per-finding remediation for new HIGH findings
By the numbers
- 6 threat categories scanned
- Verdict has 3 levels: CLEAN, ATTENTION, DEGRADED
Files
aeon-skill-security-scan
Skills tell agents what to do. A malicious or sloppy skill can shell-inject, exfiltrate secrets, override instructions, or run destructive commands. This skill scans every installed SKILL.md and companion script and surfaces the risks before they execute.
Scope
<skills-dir>/*/SKILL.md— primary.<skills-dir>/*/scripts/*.shand*.py— companion scripts.<skills-dir>/*/references/*— documents loaded at runtime.
Default <skills-dir> is the current working directory.
Threat patterns
| Category | What it looks like |
|---|---|
| Shell injection | Unquoted variable expansion, eval, backticks, $(...) with user data. |
| Secret exfiltration | Env vars or file contents piped to outbound HTTP. |
| Path traversal | ../.. chains, absolute paths reaching outside the skill dir. |
| Prompt override | "Ignore previous instructions", persona swaps, instructions inside fetched content. |
| Destructive commands | Recursive deletes rooted at / or ~, device writes. |
| Obfuscation | U+200B / U+FEFF / U+202E (Trojan Source), base64-decode-into-shell, SSRF hosts (ngrok, interact.sh, webhook.site, pipedream). |
Processing
1. Pattern scanner produces matches {file, line, pattern, severity}. 2. Code-fence downgrade — matches inside fenced code blocks drop one tier. Real run: blocks are never downgraded. 3. Baseline suppression — drop (file, pattern, line) tuples in scan-baseline.yml. 4. Trusted-publisher filter — entries in trusted-publishers.txt get format-only validation. Opt-in only. 5. Delta vs scan-state.json — fingerprint by sha256(file + line_content + pattern). Classify NEW / RESOLVED / PERSISTENT.
Per-finding remediation
| Pattern | Fix |
|---|---|
eval / backticks / $(...) with variable | Quote the variable; replace eval with a function. |
curl with secret in URL | Move secret into prefetch script; never interpolate into shell. |
| Path traversal | Allow-list validation; reject absolute paths. |
| Prompt override phrasing | Documentation → baseline suppression; payload → delete the skill. |
Recursive delete rooted at / or ~ | Scope to the skill's own working directory. |
| Obfuscation | Delete unless documented and reviewed. |
Output
Verdict CLEAN / ATTENTION / DEGRADED. Needs-attention section per NEW HIGH with one-line remediation. Resolved-since-last-scan section. Per-skill PASS / WARN / FAIL.
Written only when NEW, RESOLVED, or any current HIGH findings.
Rules
- Never auto-deletes a baseline suppression.
- Never edits the pattern library from inside the skill.
- Never notifies on a pure no-op week.
- Read-only scanning.
{
"schemaVersion": 1,
"slug": "aeon-skill-security-scan",
"provider": "Aeon",
"providerUrl": "https://github.com/aaronjmars/aeon",
"logo": null,
"demo": {
"title": "skill-security-scan.sh",
"language": "bash",
"code": "# Scan every installed skill\naeon-skill-security-scan\n\n# Scan one\naeon-skill-security-scan target=aeon-distribute-tokens"
},
"setup": [
"Install: `install the aeon-skill-security-scan skill from https://github.com/BankrBot/skills/tree/main/aeon-skill-security-scan`",
"Run before enabling any newly installed skill",
"Re-run on a schedule to catch updates introduced by other skills",
"Source: https://github.com/BankrBot/skills/tree/main/aeon-skill-security-scan"
],
"install": {
"type": "bankr",
"repoPath": "aeon-skill-security-scan",
"command": "install the aeon-skill-security-scan skill from https://github.com/BankrBot/skills/tree/main/aeon-skill-security-scan"
}
}
Related skills
FAQ
Does it modify skills?
No. It is read-only scanning and never auto-deletes a baseline suppression or edits the pattern library.
How does it reduce false positives?
Matches inside fenced code blocks drop one severity tier, and a trusted-publisher filter gives format-only validation on an opt-in basis.