agentleFS
Sign inSign up

AGENTS.md examples from real projects

How real projects brief Codex, Cursor and every other agent that reads AGENTS.md.

Best matches · from page 14Worked for most · soon
GitHubAGENTS.md

gh-aw

github/gh-aw/AGENTS.md

flow, and command playbooks → `.github/skills/developer/SKILL.md` - Code organization, file structure, WASM stubs, string patterns → `.github/skills/developer-code-organization/SKILL.md` - Security best practices, template injection, shell script safety, supply chain → `.github/skills/developer-security/SKILL.md` - Compiler internals, validation architecture, safe

5.2k4mo agoDiscuss
awarexoneAGENTS.md

Agentic-Bug-Hunter

awarexone/Agentic-Bug-Hunter/AGENTS.md

surface ranking from recon output + memory - `token-auditor` — fast meme coin/token rug pull and security analysis - `credential-hunter` — orchestrates wordlist-gen + osint-employees + breach-check; HARD STOPS at spray

5.2k4mo agoDiscuss
iflytekAGENTS.md

skillhub

iflytek/skillhub/AGENTS.md

across an organization. It provides a **REST API backend**, a **React web UI**, a **security scanner**, and a **ClawHub CLI compatibility layer**. ## Quick Reference | Item | Value | |------------|------------------------------------------------------------| | Backend | Spring Boot

5.2k33d agoDiscuss
VercelAGENTS.md

examples / wait-until

vercel/examples/rust/wait-until/AGENTS.md

durable agent loops or untrusted code: use Workflow (pause/resume/state) + Sandbox; use Vercel MCP for secure infra access

5.2k8mo agoReads credentialsDiscuss
SaladDayAGENTS.md

cc-switch-cli

SaladDay/cc-switch-cli/AGENTS.md

rounds. Ask the reviewer to independently inspect all current modifications and report correctness, regression, security, performance, UX, and test-coverage issues. - Validate every finding against the code. Make minimal fixes

5.1k18d agoReads credentialsDiscuss
tiannAGENTS.md

hapi

tiann/hapi/AGENTS.md

wide checks when explicitly requested as well. - Review this task's changes for correctness, security, and regressions. For local work, inspect unstaged/staged diffs (`git diff`, `git diff --cached

5.1k9mo agoDiscuss
TabularisDBAGENTS.md

tabularis

TabularisDB/tabularis/AGENTS.md

symbol — callers, callees, which execution flows it participates in — use `context({name: "symbolName"})`. - For security review, `explain({target: "fileOrSymbol"})` lists taint findings (source→sink flows; needs `analyze --pdg`). ## Never

5.1k22d agoDiscuss
clideyAGENTS.md

whodb

clidey/whodb/AGENTS.md

disjoint file ownership for parallel work. - Ask review-oriented agents to find correctness, regression, security, and missing-test issues first; summaries are secondary. ## Project Structure ``` core/ # Backend (Go) cmd/whodb/main.go # Entry

5k7d agoDiscuss
WaishnavAGENTS.md

devspace

Waishnav/devspace/AGENTS.md

terms precisely. In particular, do not use workspace, allowed root, checkout, and worktree interchangeably. ## Security boundaries Filesystem tools enforce approved-root containment. Shell commands run with the local user

5k3mo agoDiscuss
AWSAGENTS.md

aidlc-workflows

awslabs/aidlc-workflows/AGENTS.md

Markdown dependency, another block scanner, or a definition grammar. The security-sensitive `Bun.markdown.render` review-authority check is a deliberately separate code path. - The orchestrator skill (`harness/ /skills/aidlc/SKILL.md`) is per-harness

4.9k3d agoDiscuss
homeassistant-aiAGENTS.md

ha-mcp

homeassistant-ai/ha-mcp/AGENTS.md

repository is `homeassistant-ai/ha-mcp`; the package is `ha-mcp` on PyPI. ## Security Read [`SECURITY.md`](SECURITY.md) before changing authentication, OAuth, webhooks, network exposure, proxies, filesystem access, or trust boundaries

4.9k5d agoDiscuss
MicrosoftAGENTS.md

fluentui-blazor

microsoft/fluentui-blazor/AGENTS.md

management - `.github/CODEOWNERS` - Code ownership (@vnbaaij @dvoituron) - `docs/contributing.md` - Contribution guidelines - `docs/unit-tests.md` - Detailed unit testing documentation ## Security Considerations - Do not commit sensitive data or credentials - Review the `SECURITY.md` file for security policies

4.8k57d agoDiscuss
u14appAGENTS.md

deep-research

u14app/deep-research/AGENTS.md

developers) working on the **Deep Research** repository. Adhere to these patterns to ensure consistency, security, and maintainability. --- ## 🚀 Development Workflow & Commands The project uses **pnpm** as the primary package manager. ### Core

4.7k17mo agoReads credentialsDiscuss
zebbernAGENTS.md

claude-code-guide / react-best-practices

zebbern/claude-code-guide/skills/react-best-practices/AGENTS.md

invoked directly. Next.js documentation explicitly states: "Treat Server Actions with the same security considerations as public-facing API endpoints, and verify if the user is allowed to perform a mutation

4.6k8mo agoDiscuss
JetBrainsAGENTS.md

koog

JetBrains/koog/AGENTS.md

callLLM") assertNodes { askLLM withInput "Hello" outputs Message.Assistant("Hello!") } } } } ``` For comprehensive testing examples, see `agents/agents-test/TESTING.md`. ## Security ### API Key Management - **NEVER** commit API keys or secrets to the repository - Use environment variables

4.6k5mo agoDiscuss
SupabaseAGENTS.md

supabase-js

supabase/supabase-js/AGENTS.md

testing guide with Docker requirements per package - [`docs/RELEASE.md`](./docs/RELEASE.md) — release workflows and versioning strategy - [Security Policy](https://github.com/supabase/supabase-js/security/policy) — security policies and responsible disclosure - [`docs/JSR_PUBLISHING.md`](./docs/JSR_PUBLISHING.md) — JSR registry publishing

4.6k6mo agoDiscuss
VercelAGENTS.md

just-bash / just-bash

vercel-labs/just-bash/packages/just-bash/AGENTS.md

ignores) - Dependencies that use wasm are not allowed (exception: sql.js for SQLite, approved for security sandboxing). Binary npm packages are fine - When you implement multiple tasks (such as multiple commands

4.3k7mo agoDiscuss
archestra-aiAGENTS.md

archestra / platform

archestra-ai/archestra/platform/AGENTS.md

3000/settings> (lands on the first permitted tab; tabs: Organization, Service Accounts, Chat, LLM, MCP, Security, Knowledge, Environments, Users, Teams, Roles, GitHub, Identity Providers, Secrets) - **Personal Settings**: <http://localhost:3000/account> (personal

4.3k4d agoReads credentialsDiscuss
arcboxlabsAGENTS.md

arcbox / runtime

arcboxlabs/arcbox/runtime/AGENTS.md

capabilities, or hook paths. Document what you rely on before treating it as a security boundary. ## Conventions & pitfalls - **ID schemes differ — not interchangeable.** `ContainerId::new` strips dashes and TRUNCATES

4.3k2mo agoDiscuss
nolabs-aiAGENTS.md

nono

nolabs-ai/nono/AGENTS.md

nono agent guide nono is a security-critical, capability-based sandbox for untrusted AI agents. It uses Landlock on Linux and Seatbelt on macOS. Treat every change as a security

4.2k24d agoDiscuss
CLAUDE.md vs AGENTS.md

About AGENTS.md

What is AGENTS.md?

An open format for instructions to coding agents, read by Codex, Cursor and others. Think of it as a README written for agents.

Where does it go?

At the repository root, with more specific files in subdirectories. Agents read the one closest to the file they're editing.

What should it contain?

Setup and test commands, code style, and the rules a new contributor would need to know.

Does Claude Code read it?

Claude Code reads CLAUDE.md. A one-line CLAUDE.md that points at AGENTS.md covers both.