agentleFS
Sign inSign up

AGENTS.md examples from real projects

How real projects brief Codex, Cursor and every other agent that reads AGENTS.md.

Best matches · from page 16Worked for most · soon
OpenAIAGENTS.md

openai-agents-js

openai/openai-agents-js/AGENTS.md

Project Structure Guide](#project-structure-guide) 4. [Operation Guide](#operation-guide) ## Policies & Mandatory Rules ### Security Requirements Follow [SECURITY.md](SECURITY.md) for repository scope and private vulnerability reporting, and [CONTRIBUTING.md](CONTRIBUTING.md#security

3.9k8mo agoReads credentialsDiscuss
yvgudeAGENTS.md

lean-ctx

yvgude/lean-ctx/AGENTS.md

compression for a single command. ## Quality Bar - Zero clippy warnings, all tests pass - Security: PathJail, Shell Allowlist, bounded_lock, no hardcoded secrets - No mock data, no placeholders, no stubs ## Quality

3.8k2mo agoDiscuss
AtmosphereAGENTS.md

atmosphere

Atmosphere/atmosphere/AGENTS.md

fails. - Classpath detection must be gated on runtime evidence, not just `Class.forName()` success. ### 6. Security: Every mutating surface requires explicit authorization - **Every mutating/admin endpoint requires explicit authentication and authorization.** Default

3.8k6d agoDiscuss
MicrosoftAGENTS.md

mcp

microsoft/mcp/AGENTS.md

check transport type or access HttpContext if (Environment.GetEnvironmentVariable("ASPNETCORE_URLS") != null) { } var httpContext = _httpContextAccessor.HttpContext; ``` ### Security Best Practices 1. Always use HTTPS in production 2. Implement least privilege RBAC

3.7k30d agoReads credentialsDiscuss
Model Context ProtocolAGENTS.md

java-sdk

modelcontextprotocol/java-sdk/AGENTS.md

version or a transport type also counts). - Dependency bumps require a concrete reason (security, bug, needed feature) — see [DEPENDENCY_POLICY.md](DEPENDENCY_POLICY.md). Don't bump a dependency just because a newer version

3.7k3mo agoDiscuss
memodb-ioAGENTS.md

Acontext / landingpage

memodb-io/Acontext/landingpage/AGENTS.md

Core Principles 1. **TypeScript-First**: Always use TypeScript with proper types from Payload 2. **Security-Critical**: Follow all security patterns, especially access control 3. **Type Generation**: Run `generate:types` script

3.7k7mo agoReads credentialsDiscuss
ObservalAGENTS.md

Observal

Observal/Observal/AGENTS.md

users, agents, components, feedback, settings). SQLAlchemy async. - **ClickHouse**: session events, session aggregates, audit events, security events, and webhook deliveries. HTTP interface, MergeTree-family tables, bloom filter indexes. Schema changes

3.7k2mo agoDiscuss
GoogleAGENTS.md

recaptcha

google/recaptcha/AGENTS.md

Fixes` / `What's Changed`, `Compatibility & Upgrade Guide`, and `Full Changelog` compare link). --- ## 3. Architecture & Security Invariants ``` src/ ├── autoload.php # Standalone PSR-4-equivalent autoloader └── ReCaptcha/ ├── ReCaptcha.php # Main client & fluent verification builder

3.6k7d agoDiscuss
Ontos-AIAGENTS.md

knowhere

Ontos-AI/knowhere/AGENTS.md

AI_Security_Report.docx": { "chunks_count": 155, "types": { "image": 13, "table": 1, "text": 141 }, "top_keywords": ["model", "security", "ai", "operations", "artificial_intelligence"], "top_summary": "This document includes: Legal Notice, Foreword, 1. Overview, ...", "importance

3.5k5mo agoReads credentialsDiscuss
OpenAIAGENTS.md

openai-go

openai/openai-go/AGENTS.md

checker and effective budget come from main, not the PR. Keep default CODEOWNERS. ## Security requirements - Never commit, print, or upload API keys, bearer tokens, cloud credentials, private keys, webhook secrets

3.5k39d agoReads credentialsDiscuss
LangChainAGENTS.md

langgraphjs

langchain-ai/langgraphjs/AGENTS.md

Repository instructions ## Corridor security analysis When Corridor's `analyzePlan` tool is available, create a plan and use the tool to analyze it before generating or modifying code. Apply the resulting

3.3k37d agoDiscuss
nexu-ioAGENTS.md

nexu

nexu-io/nexu/AGENTS.md

guidance | `tools/dev/AGENTS.md` | | Frontend conventions | `specs/FRONTEND.md` | | Desktop runtime guide | `specs/guides/desktop-runtime-guide.md` | | Desktop update testing guide | `specs/guides/desktop-update-testing.md` | | Security posture | `specs/SECURITY.md` | | Reliability | `specs/RELIABILITY.md` | | Product model | `specs/PRODUCT_SENSE.md` | | Quality signals | `specs/QUALITY_SCORE.md` | | Product specs | `specs/product-specs/` | | Execution plans

3.3k6mo agoReads credentialsDiscuss
MongoDBAGENTS.md

mongo-csharp-driver

mongodb/mongo-csharp-driver/AGENTS.md

whole diff and run on every invocation of the `/review-areas` skill. | Concern | Reviewer | |---|---| | Security: secrets, TLS/crypto, redaction, deserialization safety | `security-reviewer` | | Public API / SemVer | `api-stability-reviewer` | | Async/threading hygiene | `async

3.2k51d agoDiscuss
MongoDBAGENTS.md

mongo-csharp-driver / MongoDB.Bson

mongodb/mongo-csharp-driver/src/MongoDB.Bson/AGENTS.md

first lookup. Without knowing about a concrete type, the deserializer can't materialize it. **Security:** when deserializing untrusted BSON into open polymorphic types, an attacker-controlled `_t` value can drive

3.2k51d agoDiscuss
MongoDBAGENTS.md

mongo-csharp-driver / Authentication

mongodb/mongo-csharp-driver/src/MongoDB.Driver/Authentication/AGENTS.md

Speculative auth supported. Requires `tlsCertificateKeyFile` (or programmatic `SslSettings.ClientCertificates`). Never use without TLS — the entire security argument relies on it. ### GSSAPI / Kerberos (`Gssapi/`) Files: `GssapiSaslMechanism.cs`, `GssapiFirstSaslStep.cs`, `GssapiNegotiateSaslStep.cs`, `GssapiInitializeSaslStep.cs`, `ISecurityContext.cs`, `SecurityContextFactory.cs` (platform

3.2k51d agoDiscuss
MongoDBAGENTS.md

mongo-csharp-driver / MongoDB.Driver.Encryption

mongodb/mongo-csharp-driver/src/MongoDB.Driver.Encryption/AGENTS.md

destroyed pointer. Don't rearrange disposal order without checking `GC.KeepAlive` calls. - **TLS callback security.** `ClientEncryptionOptions` rejects insecure TLS callbacks at construction. Don't add a "for testing" bypass that disables

3.2k51d agoDiscuss
chuspeeismAGENTS.md

dashi-taskboard

chuspeeism/dashi-taskboard/AGENTS.md

into a surrounding engineering project. This ordering does not waive higher-priority safety or security requirements. Keep validation that is necessary at real external boundaries, such as user input

3.2k6d agoDiscuss
liaohch3AGENTS.md

claude-tap

liaohch3/claude-tap/AGENTS.md

Review Guidelines When reviewing pull requests, prioritize findings that can cause correctness bugs, regressions, security or privacy issues, release failures, broken CI, broken packaging, or misleading evidence. Treat these

3.2k37d agoDiscuss
VercelAGENTS.md

fx

vercel-labs/fx/AGENTS.md

that should influence LLVM's hot and cold decisions * **Verification-only:** important correctness, recovery, security, or rare behavior that the final candidate must pass without making it hot * **Intentional exclusion

3.2k11d agoReads credentialsDiscuss
VercelAGENTS.md

fx / sdk

vercel-labs/fx/sdk/AGENTS.md

obvious invariant, or run the right proof. The native Node-API architecture and security model are documented in `sdk/NAPI.md`. ## Start from the correct owner The SDK has two WebAssembly surfaces

3.2k11d agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About AGENTS.md

What is AGENTS.md?

An open format for instructions to coding agents, read by Codex, Cursor and others. Think of it as a README written for agents.

Where does it go?

At the repository root, with more specific files in subdirectories. Agents read the one closest to the file they're editing.

What should it contain?

Setup and test commands, code style, and the rules a new contributor would need to know.

Does Claude Code read it?

Claude Code reads CLAUDE.md. A one-line CLAUDE.md that points at AGENTS.md covers both.