agentleFS
Sign inSign up

AGENTS.md examples from real projects

How real projects brief Codex, Cursor and every other agent that reads AGENTS.md.

Best matches · from page 22Worked for most · soon
nrslibAGENTS.md

takt

nrslib/takt/AGENTS.md

lint`, and `npm test`, then include the TAKT review summary when required by `CONTRIBUTING.md`. ## Security & Configuration Tips Never commit API keys or tokens. Use `~/.takt/config.yaml`, project `.takt/config.yaml`, or environment variables

1.4k16d agoDiscuss
m0n0x41dAGENTS.md

haft

m0n0x41d/haft/AGENTS.md

execution authority; approve, reopen, or rebaseline a SpecSection; make a material product/value/scope, public-promise, security, legal, privacy, finance, irreversible-data, compatibility, or authority-allocation choice. - If current Work would rely

1.4k51d agoDiscuss
MicrosoftAGENTS.md

fhir-server

microsoft/fhir-server/AGENTS.md

Clearly link code changes back to the user story or requirement that motivated them. --- ## Security and Compliance - Never commit secrets or credentials. - Follow Azure security best practices: encrypted transport, least

1.4k4mo agoDiscuss
vellum-aiAGENTS.md

vellum-assistant

vellum-ai/vellum-assistant/AGENTS.md

approvals`. - **Human attention comments**: After creating a PR with non-routine changes (architectural decisions, security, complex logic, deletions, low confidence), leave a `gh pr comment` highlighting where to focus review

1.3k3mo agoReads credentialsDiscuss
vellum-aiAGENTS.md

vellum-assistant / cli

vellum-ai/vellum-assistant/cli/AGENTS.md

Gateway: rw, CES: ro | `config.json`, conversations, apps, skills, db, logs, `.backups/`, `.backup.key` | | **Gateway security** (` -gateway-sec`) | `/gateway-security` | Gateway only | `trust.json`, `actor-token-signing-key`, capability-token secrets | | **CES security

1.3k3mo agoDiscuss
vellum-aiAGENTS.md

vellum-assistant / gateway

vellum-ai/vellum-assistant/gateway/AGENTS.md

bash` + canonical CLI surfaces. Start with `assistant config get` for generic config keys and secure credential surfaces (`assistant credentials`, `assistant keys`) for secrets. Do not use direct gateway `curl

1.3k3mo agoDiscuss
vellum-aiAGENTS.md

vellum-assistant / skills

vellum-ai/vellum-assistant/skills/AGENTS.md

chat.** API keys, tokens, passwords, and webhook secrets must be collected via a secure UI path — never pasted into the conversation where they enter the LLM context. Two approved paths

1.3k3mo agoDiscuss
study8677AGENTS.md

repobrain / openspec

study8677/repobrain/openspec/AGENTS.md

Make breaking changes (API, schema) - Change architecture or patterns - Optimize performance (changes behavior) - Update security patterns Triggers (examples): - "Help me create a change proposal" - "Help me plan a change" - "Help

1.3k3mo agoDiscuss
yjl9903AGENTS.md

AnimeGarden

yjl9903/AnimeGarden/AGENTS.md

results, and screenshots for web changes. Note required env vars, migrations, or deployment steps. ## Security & Configuration Tips Do not commit `.animegarden/`, `node_modules/`, `dist/`, build outputs, or local secrets

1.3k38d agoDiscuss
utkusenAGENTS.md

sast-skills / sast-files

utkusen/sast-skills/sast-files/AGENTS.md

SAST Security Assessment Your goal is to identify security vulnerabilities in the codebase located in the current directory. --- ## Step 1: Codebase Analysis & Threat Modeling Before running, check if `sast/architecture.md` already

1.3k6mo agoDiscuss
puppyone-aiAGENTS.md

puppyone-cloud

puppyone-ai/puppyone-cloud/AGENTS.md

endpoint; any MCP-compatible client (Claude Desktop, Cursor, etc.) can connect directly - **Code sandbox** — Securely execute code in isolated Docker/E2B containers; agents can invoke sandbox endpoints remotely ### Collaborate - **Authentication & access

1.3k13d agoDiscuss
sipyourdrink-ltdAGENTS.md

bernstein

sipyourdrink-ltd/bernstein/AGENTS.md

src/bernstein/core/lineage/AGENTS.md` | Lineage: artifact provenance | | `src/bernstein/core/orchestration/AGENTS.md` | Orchestration engine | | `src/bernstein/core/quality/AGENTS.md` | Quality gates and verification | | `src/bernstein/core/security/AGENTS.md` | Security: audit chain, identity, policy | | `tests/AGENTS.md` | Test suite | ## Build & test ``` uv sync # install + lock uv run python

1.3k9d agoDiscuss
dohoooAGENTS.md

helmor

dohooo/helmor/AGENTS.md

Bump cadence: every release cycle if upstream has shipped a notable fix; immediately on security advisories. Pin so the auth-status JSON shape Helmor parses doesn't drift unexpectedly. - **Bundled

1.3k3mo agoDiscuss
SupabaseAGENTS.md

supabase-swift

supabase/supabase-swift/AGENTS.md

verifyOTPForSecureEmailChange cd Tests/IntegrationTests supabase stop ``` `verifyOTPForSecureEmailChange` needs `auth.email.enable_confirmations = true` to reach GoTrue's secure-email-change "single confirmation" response, which every other integration test relies on being `false

1.3k14d agoDiscuss
pnokerAGENTS.md

iot-dc3

pnoker/iot-dc3/AGENTS.md

only source of truth; documentation drifts. - Tenant isolation is a correctness and security requirement, never a trade-off. - Wire contracts evolve backward-compatibly; breaking changes are explicit and `!`-marked. - Code

1.3k3mo agoReads credentialsDiscuss
coleam00AGENTS.md

claude-memory-compiler

coleam00/claude-memory-compiler/AGENTS.md

full. Format: ```markdown # Knowledge Base Index | Article | Summary | Compiled From | Updated | |---------|---------|---------------|---------| | [[concepts/supabase-auth]] | Row-level security patterns and JWT gotchas | daily/2026-04-02.md | 2026-04-02 | | [[connections/auth-and-webhooks]] | Token verification patterns shared across Supabase

1.3k6mo agoReads credentialsDiscuss
MongoDBAGENTS.md

kingfisher / features

mongodb/kingfisher/docs-site/docs/features/agents.md

Use Kingfisher with LLMs and AI agents. TOON output format for token-efficient scanning, prompt redaction, and structured output for automated workflows.

1.2k8d agoDiscuss
OpenPetsHQAGENTS.md

openpets

OpenPetsHQ/openpets/AGENTS.md

Read first. - **`docs/desktop.md`** — the Electron app: process model, tray/Control Center, windows, app state, lifecycle, security, logging, CSP. - **`docs/ipc.md`** — local IPC protocol + `@open-pets/client`: discovery, transports, the lease model, request

1.2k3mo agoDiscuss
lcoutodemosAGENTS.md

clui-cc

lcoutodemos/clui-cc/docs/AGENTS.md

state, theming, user input, message display | | **Preload** | `src/preload/` | Typed IPC bridge (`window.clui` API). Security boundary. | | **Main** | `src/main/` | Process lifecycle, tab state machine, permission server, marketplace | ### Key Files by Concern | Concern

1.2k7mo agoDiscuss
alvinunrealAGENTS.md

openpets

alvinunreal/openpets/AGENTS.md

Read first. - **`docs/desktop.md`** — the Electron app: process model, tray/Control Center, windows, app state, lifecycle, security, logging, CSP. - **`docs/ipc.md`** — local IPC protocol + `@open-pets/client`: discovery, transports, the lease model, request

1.2k3mo agoDiscuss
CLAUDE.md vs AGENTS.md

About AGENTS.md

What is AGENTS.md?

An open format for instructions to coding agents, read by Codex, Cursor and others. Think of it as a README written for agents.

Where does it go?

At the repository root, with more specific files in subdirectories. Agents read the one closest to the file they're editing.

What should it contain?

Setup and test commands, code style, and the rules a new contributor would need to know.

Does Claude Code read it?

Claude Code reads CLAUDE.md. A one-line CLAUDE.md that points at AGENTS.md covers both.