agentleFS
Sign inSign up

AGENTS.md examples from real projects

How real projects brief Codex, Cursor and every other agent that reads AGENTS.md.

Best matches · from page 24Worked for most · soon
OpenLAIRAGENTS.md

dr-claw / server

OpenLAIR/dr-claw/server/AGENTS.md

try/catch. - Return proper HTTP status: 400, 403, 404, 500. - Log with `console.error('[ERROR]', ...)`. ## Path security Always validate file paths: ```js const resolved = path.resolve(allowedRoot, userInput); if (!resolved.startsWith(allowedRoot + path.sep)) { return

1.1k6mo agoDiscuss
SentryAGENTS.md

sentry-go

getsentry/sentry-go/AGENTS.md

conventions - `/code-review` — Review PRs following Sentry practices - `/find-bugs` — Audit local changes for bugs and security issues

1.1k15mo agoDiscuss
lee-toAGENTS.md

ai-factory

lee-to/ai-factory/AGENTS.md

test plan → test cases │ ├── aif-qa-check/ # Execute QA cases in human/automated-agent mode │ ├── aif-security-checklist/ # Security audit │ ├── aif-skill-generator/ # Generate new skills │ └── aif-verify/ # Verify implementation against plan

1.1k9d agoDiscuss
alibabaAGENTS.md

skill-up

alibaba/skill-up/AGENTS.md

internal/runner/`, also run `make e2e`. 5. Update `CHANGELOG.md` if the change is user-visible. ## Security considerations - Credentials resolve in this priority order: CLI flag -> environment variable -> `~/.skill-up/credentials.yaml`. Never

1.1k5mo agoDiscuss
marcusAGENTS.md

sidecar

marcus/sidecar/AGENTS.md

state until the result message arrives. This matters most on machines running an endpoint security agent (e.g. CrowdStrike), where every file open and process spawn carries a large fixed

1.1k24d agoDiscuss
StripeAGENTS.md

sync-engine

stripe/sync-engine/AGENTS.md

they create real objects). - The npm-bundled `esbuild` binary is blocked by Santa (endpoint security). Set `ESBUILD_BINARY_PATH` to the Homebrew-installed binary: `source scripts/prefer-system-esbuild.sh

1.1k5mo agoReads credentialsDiscuss
openops-cloudAGENTS.md

openops

openops-cloud/openops/AGENTS.md

body format --- ## Tech Stack - **Backend:** Fastify, TypeORM 0.3 (PostgreSQL or SQLite), JWT auth with secure cookie sessions - **Frontend:** React 18, Zustand, react-query v5, shadcn, Axios (via `api.ts` wrapper

1.1k3mo agoReads credentialsDiscuss
asklokeshAGENTS.md

loki-mode / references

asklokesh/loki-mode/references/agents.md

creation and optimization - Kubernetes manifest review - Helm chart development - Infrastructure as Code review - Container security - Multi-stage builds - Resource limits and requests **Task Types:** - `dockerfile`: Create/optimize Dockerfile - `k8s-manifest`: Write

1.1k4mo agoDiscuss
asklokeshAGENTS.md

loki-mode / skills

asklokesh/loki-mode/skills/agents.md

management **The 41 agent types are ROLES defined through prompts.** Create specialized behavior: ```python # Security reviewer = general-purpose + security-focused prompt Task( subagent_type="general-purpose", model="opus", description="Security

1.1k4mo agoDiscuss
SentryAGENTS.md

sentry-cli

getsentry/sentry-cli/AGENTS.md

times - Memory usage matters for CI environments - Network operations should be optimized and retryable ### Security Best Practices - Handle authentication tokens securely - Validate file paths to prevent directory traversal - Consider impact

1k9mo agoDiscuss
SentryAGENTS.md

sentry-cli / workflows

getsentry/sentry-cli/.github/workflows/AGENTS.md

CI/CD Workflow Guidelines ## Security: Pin Actions by Commit Hash **ALWAYS pin GitHub Actions to specific commit SHAs** instead of version tags for enhanced security. This prevents supply chain attacks where

1k9mo agoDiscuss
michaelshimelesAGENTS.md

skills

michaelshimeles/skills/AGENTS.md

project, append what agents need to execute the beats there: commands & checks, hard invariants (security and architecture rules), an environment quick reference, local test infrastructure (stubs, fixtures), and anything that

1k27d agoDiscuss
melandlabsAGENTS.md

openloomi / composio

melandlabs/openloomi/skills/composio/AGENTS.md

Use 1000+ external apps via Composio - either directly through the CLI or by building AI agents and apps with the SDK

1k3mo agoPipes a download into a shellDiscuss
stackqlAGENTS.md

stackql

stackql/stackql/AGENTS.md

when not applicable). - All required checks (build, lint, robot) must be green before merge. ## Security & Configuration Tips StackQL supports flexible configuration management, including authentication secrets and connection parameters, through environment

1k58d agoDiscuss
johannesjoAGENTS.md

parallel-code

johannesjo/parallel-code/AGENTS.md

when changing exports or module dependencies. - See `.github/workflows/ci.yml` for the complete CI sequence, including security-rule fixture tests and the real-PTY coordinator test. Ordinary test runs skip

1k6d agoDiscuss
alpacahqAGENTS.md

alpaca-mcp-server

alpacahq/alpaca-mcp-server/AGENTS.md

defined in `toolsets.py`. A trust-boundary middleware (`security.py`) wraps every tool result in a security envelope to mitigate prompt injection via tool outputs. The test suite has three layers: - `tests/test_integrity.py

99516d agoReads credentialsDiscuss
Azure-SamplesAGENTS.md

AI-Gateway

Azure-Samples/AI-Gateway/AGENTS.md

Gateway pattern through Azure API Management. It focuses on managing AI services APIs with security, reliability, performance, and cost controls. Labs use Jupyter notebooks with Python, Bicep templates, and Azure

98821mo agoDiscuss
MicrosoftAGENTS.md

power-platform-skills / mobile-apps

microsoft/power-platform-skills/plugins/mobile-apps/AGENTS.md

same Wrap-page + pasted-client-ID flow. - ✅ `/add-native` v0 scope: camera, location, push, biometrics, secure-store (already in template) - ✅ Cross-host Metro diagnostics: user-owned `npm run dev`, port-probe

93844d agoDiscuss
MicrosoftAGENTS.md

power-platform-skills / model-apps

microsoft/power-platform-skills/plugins/model-apps/AGENTS.md

privileges on the backing table that ACTIVATION creates, so they are applied in the **`security` phase**, after both the flow and the personas' roles exist — persona lookup there is **case

93844d agoDiscuss
MicrosoftAGENTS.md

power-platform-skills / power-pages

microsoft/power-platform-skills/plugins/power-pages/AGENTS.md

directory). Validator changes are not an exception; they must always ship with test coverage. - **Secure process validation** — After changing Power Pages `child_process` usage, run `node scripts/validate-secure-process-execution.js` from the repository

93844d agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About AGENTS.md

What is AGENTS.md?

An open format for instructions to coding agents, read by Codex, Cursor and others. Think of it as a README written for agents.

Where does it go?

At the repository root, with more specific files in subdirectories. Agents read the one closest to the file they're editing.

What should it contain?

Setup and test commands, code style, and the rules a new contributor would need to know.

Does Claude Code read it?

Claude Code reads CLAUDE.md. A one-line CLAUDE.md that points at AGENTS.md covers both.