Aeon agent framework recognized by Nvidia for identifying security flaws
The open-source Aeon framework was added to Nvidia's security acknowledgements on September 22, 2026 after its Vuln Scanner skill found vulnerabilities in Nvidia software.
Aeon agent framework was added to Nvidia’s security acknowledgements on September 22, 2026 after its Vuln Scanner skill identified vulnerabilities in the company’s software.
Operator Aaron Mars used the framework to submit the findings, showing that users can audit high-profile software without manual oversight.
The framework operates as an autonomous agent system that completes tasks without continuous human approval loops.
According to the project documentation, the framework uses 84 distinct skills to complete work once given a direction.
The Vuln Scanner skill audits trending repositories for real security vulnerabilities and handles the disclosure process.
The system can assign Common Vulnerabilities and Exposures (CVE) identifiers and reports them to Nvidia, which lists contributions by CVE ID ranges from 2024 through 2026 on its security page.
Nvidia’s acknowledgement page also lists contributions from Tencent Xuanwu Lab, Wiz Research, IIT Kharagpur, and Tsinghua University.
Nvidia says its Vulnerability Disclosure Program allocates resources to analyze, validate, and provide corrective actions for reported concerns.
Mars shared a link to the Nvidia security acknowledgements page to highlight the framework’s contribution.
The Aeon project describes itself as the most autonomous agent framework available and distributes it under an MIT license.
The Aeon framework account on X noted that its vuln-scanner skill has examined repositories with millions of stars, including those belonging to Google, Microsoft, Alibaba Group, Tencent Global, and Cloudflare.
Security researchers are integrating autonomous agents into workflows to enable continuous monitoring without manual scan cycles.
Details of the specific vulnerabilities remain private until patches are released, though their existence appears on the acknowledgement list.