Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
bankrbot avatar

Aeon Skill Security Scan

  • 14 installs
  • 1.2k repo stars
  • Updated August 1, 2026
  • bankrbot/skills

aeon-skill-security-scan is a Claude skill that audits installed skills' SKILL.md and scripts for shell injection, secret exfiltration, prompt-override payloads, and obfuscation before they run.

About

aeon-skill-security-scan is a Claude skill that audits installed skills before you run them. It scans each SKILL.md and companion script for shell injection, secret exfiltration, path traversal, prompt-override payloads, destructive commands, and modern obfuscation like zero-width Unicode and base64-decode pipes. It surfaces only new or resolved findings versus prior scans and stays read-only. A developer uses it to check whether a skill is safe to install.

  • Audits installed skills before you run them for injection and exfiltration risks
  • Scans SKILL.md and companion scripts for shell injection, secret exfiltration, and prompt-override payloads
  • Detects 2026-era obfuscation: zero-width Unicode, bidi override, base64-decode pipes, and SSRF hosts

Aeon Skill Security Scan by the numbers

  • 14 all-time installs (skills.sh)
  • Ranked #1,623 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 4, 2026 (Skillselion catalog sync)
At a glance

aeon-skill-security-scan capabilities & compatibility

Read-only local scanning; state in scan-state.json

Capabilities
skill evals · skill repair · security audit
Works with
github
Use cases
security audit · code review
Pricing
Free
From the docs

What aeon-skill-security-scan says it does

A malicious or sloppy skill can shell-inject, exfiltrate secrets, override instructions, or run destructive commands.
SKILL.md
Read-only scanning.
SKILL.md
npx skills add https://github.com/bankrbot/skills --skill aeon-skill-security-scan

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs14
repo stars1.2k
Last updatedAugust 1, 2026
Repositorybankrbot/skills

What it does

Audit installed skills' SKILL.md and scripts for injection, exfiltration, and obfuscation before running them.

Who is it for?

Vetting whether an installed skill is safe to run

Skip if: Modifying skills, since it is read-only scanning

When should I use this skill?

You want to audit a skill or check whether it is safe to install

What you get

A CLEAN / ATTENTION / DEGRADED verdict with per-finding remediation and delta vs prior scans

  • A CLEAN/ATTENTION/DEGRADED verdict with per-skill PASS/WARN/FAIL
  • Per-finding remediation for new HIGH findings

By the numbers

  • 6 threat categories scanned
  • Verdict has 3 levels: CLEAN, ATTENTION, DEGRADED

Files

SKILL.mdMarkdownGitHub ↗

aeon-skill-security-scan

Skills tell agents what to do. A malicious or sloppy skill can shell-inject, exfiltrate secrets, override instructions, or run destructive commands. This skill scans every installed SKILL.md and companion script and surfaces the risks before they execute.

Scope

  • <skills-dir>/*/SKILL.md — primary.
  • <skills-dir>/*/scripts/*.sh and *.py — companion scripts.
  • <skills-dir>/*/references/* — documents loaded at runtime.

Default <skills-dir> is the current working directory.

Threat patterns

CategoryWhat it looks like
Shell injectionUnquoted variable expansion, eval, backticks, $(...) with user data.
Secret exfiltrationEnv vars or file contents piped to outbound HTTP.
Path traversal../.. chains, absolute paths reaching outside the skill dir.
Prompt override"Ignore previous instructions", persona swaps, instructions inside fetched content.
Destructive commandsRecursive deletes rooted at / or ~, device writes.
ObfuscationU+200B / U+FEFF / U+202E (Trojan Source), base64-decode-into-shell, SSRF hosts (ngrok, interact.sh, webhook.site, pipedream).

Processing

1. Pattern scanner produces matches {file, line, pattern, severity}. 2. Code-fence downgrade — matches inside fenced code blocks drop one tier. Real run: blocks are never downgraded. 3. Baseline suppression — drop (file, pattern, line) tuples in scan-baseline.yml. 4. Trusted-publisher filter — entries in trusted-publishers.txt get format-only validation. Opt-in only. 5. Delta vs scan-state.json — fingerprint by sha256(file + line_content + pattern). Classify NEW / RESOLVED / PERSISTENT.

Per-finding remediation

PatternFix
eval / backticks / $(...) with variableQuote the variable; replace eval with a function.
curl with secret in URLMove secret into prefetch script; never interpolate into shell.
Path traversalAllow-list validation; reject absolute paths.
Prompt override phrasingDocumentation → baseline suppression; payload → delete the skill.
Recursive delete rooted at / or ~Scope to the skill's own working directory.
ObfuscationDelete unless documented and reviewed.

Output

Verdict CLEAN / ATTENTION / DEGRADED. Needs-attention section per NEW HIGH with one-line remediation. Resolved-since-last-scan section. Per-skill PASS / WARN / FAIL.

Written only when NEW, RESOLVED, or any current HIGH findings.

Rules

  • Never auto-deletes a baseline suppression.
  • Never edits the pattern library from inside the skill.
  • Never notifies on a pure no-op week.
  • Read-only scanning.

Related skills

FAQ

Does it modify skills?

No. It is read-only scanning and never auto-deletes a baseline suppression or edits the pattern library.

How does it reduce false positives?

Matches inside fenced code blocks drop one severity tier, and a trusted-publisher filter gives format-only validation on an opt-in basis.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.