Ten Skills That Keep an Unsupervised AI Agent Honest
Ten Aeon skills, one pattern: each refuses to lose a receipt, a verdict, or a human gate. A guided map of the catalog, every skill file free to take.

Aeon is an autonomous agent that runs on GitHub Actions, powered by Claude Code. Every skill in its catalog is one markdown file: it fires on a schedule or on dispatch, does its work, and leaves. Over the past weeks ten of those skills each got a full launch article. This post is the map.
Read the ten side by side and a pattern falls out. None of these skills adds a new capability in the raw sense; the agent could already call APIs, open PRs, and move USDC. What each skill adds is a refusal. Each one names something the default workflow throws away (a phase, a receipt, a verdict, a human gate) and makes keeping it the whole job. That is the tour below: ten skills, grouped by what they refuse to lose.
Driving tools that expect a human
arc-studio drives Circle Arc Studio, the contract dev environment on the Arc testnet, from a runner with nobody at the keyboard. Arc Studio is built as a conversation; a GitHub Actions runner only gets to leave voicemails. The skill splits one interactive session into three verbs that each fit inside a single headless run (start, poll, answer) and parks the phase in memory/arc-studio.json between runs. The terminal was never the session; the state file is. One notify at the start of a turn, one at the end, and a question like “how many token decimals?” waits in the phase file until the operator answers over coffee.
The reframe generalizes past Arc: any interactive tool session is a state machine that usually hides inside a terminal window. Name the phases, persist them, and the terminal becomes optional.
Proof, not vibes
Three skills exist because “looks right” is not evidence.
create-prove attacks the softest spot in agent development: a PR that changes a skill gets read, linted, and merged, and nobody ever watched the changed skill execute. The skill takes a target pinned to an exact commit SHA, runs the changed skill for real through the repo's own aeon.yml workflow, and posts a machine-readable receipt back to the PR: run URL, output excerpt, SHA, welded into one line of JSON. Every gate fails closed. Head moved mid-proof is PROVE_STALE, no safe real invocation is PROVE_UNSAFE, a green wrapper with empty output is PROVE_MISSING_EVIDENCE. Once proof is an artifact, the absence of proof is visible too.
sc-audit is the deep Solidity audit arm, split out of vuln-scanner. It starts by writing the spec: actors, trust boundaries, and a short list of invariants that must hold on every reachable path. Then it hunts for a path that breaks one, switches sides and tries to refute each survivor, and backs what it can with a property fuzzer whose harness must first prove it reaches the code it claims to test. On-chain mode pulls verified source, follows proxies to implementations, and SHA-diffs every vendored dependency against genuine upstream, because the explorer's “verified” badge proves source matches bytecode and proves nothing about source matching upstream. Confirmed findings route through responsible disclosure, with the human gate getting stronger the more money the finding touches.
rightstack applies the same skepticism to advice. It queries the RightStack Web3 stack advisor (recommend, inspect, compare, explain, migrate) against a pinned version and a hard schema line, then cross-examines the answer: does the workflow match the chain, the custody model, the users? Every brief ships with a verdict, usable, usable-with-corrections, or looks-wrong, and the verdict is the product. A confident answer to the wrong question gets caught by checking fit, never by rereading the answer.
Money in, money out, human in the loop
Four skills handle USDC, and all four are built around the same split: reads are free, writes are gated.
cortx-reliability runs before any x402 payment. An x402 purchase is a seven-stage pipeline, and the stages that fail after the USDC has left the wallet (delivery, parse, schema) are exactly the ones an uptime check never sees. An endpoint can pass every check that costs nothing and fail every check that costs money. The skill queries CORTX, which monitors x402 endpoints end-to-end with real USDC on Base, and turns the record into a hard proceed, warn, or block. Data older than an hour is treated as no data, because a reliability number without a fresh timestamp is a guess wearing a uniform.
taskmarket-delegate points the agent at TaskMarket, the agent-worker market. Browsing bounties is free and unlimited; creating a task or submitting work is an irreversible paid action, so the exact action must arrive in the dispatch variable, the operator sees a one-line preview with the price, and nothing moves without an explicit yes. The skill encodes a quiet economic shift: the agent's own inference is just one supplier with a price and a quality curve, and low confidence on a task is a price signal to route the work to whoever is actually good at it.
compute-resell works the other side of the market: it sells idle provider credit (Bankr, Bedrock, Vertex) on the Surplus Intelligence marketplace. The edge is in reading the order book properly. The book is public, but most of it is dead weight: unhealthy offers, untrusted sellers, listings with no volume. In one live snapshot the skill file cites, ranks 1 through 66 of 239 offers on a model were dead and the real clearing price sat at rank 67. The engine filters the book down to sellers that can actually serve buyers, takes the lowest survivor as the floor, and lists at 99 percent of it. Pricing stops being a setting and becomes a reading, re-derived every run.
submit-hook closes the gap between deployed and discoverable. A Uniswap v4 hook that is live on mainnet but listed nowhere is indistinguishable from one that never shipped. The skill reads the instance's own deploy ledger as a publish queue, sanity-checks each record (the hook's flags must equal the low 14 bits of its address), derives a name, category, and plain-language rules from the deploy brief, and opens a PR against the public aeonfun/univ4-hooks registry. Idempotent by design: already listed is a safe no-op, and “did this ever get published?” becomes a single re-run instead of an investigation.
The agent as its own maintainer and publicist
feedback-builder drains the backlog that agents themselves write. A well-built service records agent bug reports and feature requests through a /feedback endpoint, and that is where the default workflow stops. The skill fetches the reports, treats every item as untrusted data, clusters the ones asking for the same change, checks each claim against the actual code, and builds the single best accepted cluster as one small PR. A bug it cannot locate in the code is NEEDS-INFO, never BUILD. A human approves by merging; the skill never merges. The complaint box turns out to have been a machine-written backlog with vote counts all along.
skill-article is the meta entry, and the reason the other nine have launch posts. Point it at any skill in the instance and it compiles an announcement from evidence: it mines run logs and output directories for a real count to headline, falls back to mechanism when no count exists, and bans the fabricated stat and the hypothetical dressed as a case study by rule. The full SKILL.md ships embedded verbatim at the bottom of every article, so the post is the pitch and the download at once. Sell the insight, give the file away.
The common refusal
Stack the ten up and the shared move is visible. The arc-studio phase file, the create-prove receipt, the rightstack verdict, the cortx-reliability delivery rate, the taskmarket-delegate preview-and-yes, the sc-audit invariant list: each is a piece of state the lazy version of the workflow discards because discarding it is easier. An autonomous agent does not get to be lazy that way. It runs unsupervised, so everything it would normally offload to a human's attention has to be written down, checked, and gated instead.
That is what an Aeon skill actually is: not a feature, but a discipline small enough to fit in one markdown file.
Ship it
All ten skills live in the official Aeon catalog at www.aeon.fun and in the repo at github.com/aeonfun/aeon, each with its own deep-dive article and the full skill file embedded for the taking. Browse all Aeon skills, fork the repo, and pick the discipline your agent is missing.
The launch post for each skill, on @aeonframework: