agentleFS
Sign inSign up

CLAUDE.md examples from real projects

How real projects brief Claude Code: the commands, conventions and warnings they put in CLAUDE.md.

Best matches · from page 19Worked for most · soon
scitixCLAUDE.md

siclaw

scitix/siclaw/CLAUDE.md

must load successfully; never silently execute against local configuration when its snapshot fails. ### 🔴 Shell Security: Defense-in-Depth > Full spec: `docs/design/security.md`; output sanitization: `docs/design/sanitization.md` Primary defense: **OS-level user isolation

2364mo agoReads credentialsDiscuss
yusufkaraaslanCLAUDE.md

lazy-bird

yusufkaraaslan/lazy-bird/CLAUDE.md

bird/ tests/ # Lint mypy lazy_bird/ # Type check (strict mode) bandit -r lazy_bird/ # Security scan # Run the API server directly python -m lazy_bird.api.main # Starts uvicorn on :8000 # Celery workers

23611mo agoReads credentialsDiscuss
OpenRouterLabsCLAUDE.md

spawn

OpenRouterLabs/spawn/CLAUDE.md

that no longer exist - Broken features (e.g., `spawn delete` references non-existent shell scripts) - Security concerns that need separate review - Architectural debt that would be too large

2354mo agoDiscuss
MicrosoftCLAUDE.md

Dataverse-skills

microsoft/Dataverse-skills/CLAUDE.md

steer users to System Administrator. Only escalate for genuinely admin-scoped operations (security roles, org settings). Run `python .github/evals/static_checks.py` after every change; it must stay green. --- ## Testing a Skill Change

23313d agoDiscuss
MelvynxCLAUDE.md

aiblueprint

Melvynx/aiblueprint/CLAUDE.md

Claude Code with permissions skipped - **Command Validation**: Pre-tool-use hooks for bash command security - **Custom Statusline**: Shows git info, costs, and token usage via ccusage - **AIBlueprint Commands**: Pre-configured

23125d agoDiscuss
OdradekAICLAUDE.md

bundles-forge

OdradekAI/bundles-forge/CLAUDE.md

project workflow integrity, Calls/Called-by symmetry, graph connectivity). All 6 are collected by `tests/run_all.py`. ### Quality & Security ```bash bundles-forge audit-skill [target-dir] # project-level skill quality audit (auto-detects mode

2305mo agoReads credentialsDiscuss
rohunjCLAUDE.md

claude-build-workflow

rohunj/claude-build-workflow/CLAUDE.md

back to you..." and summarize the key user stories. --- ## PHASE 4: Technical Architecture & Security Say: > "Now let's figure out the technical approach. Based on what we're building, here

2309mo agoDiscuss
JameZUKCLAUDE.md

Arkana

JameZUK/Arkana/CLAUDE.md

watchpoints, 10 max snapshots, 10K max trace entries. User stubs: 200 max, validated names. - **Security**: Auth lowercases ASGI headers. Error messages truncate input to 50 chars. Dashboard validates address length

2256mo agoDiscuss
idolamanCLAUDE.md

galactic

idolaman/galactic/CLAUDE.md

Enforces client coding conventions. Use when writing, reviewing, or modifying React/TypeScript code in the client/ directory. Ensures proper use of Tailwind/shadcn UI components, path aliases, TypeScript interfaces, icon usage, platform-safe storage/git logic, and consistent design system rules.

2239mo agoDiscuss
timothywarner-orgCLAUDE.md

claude-code / data

timothywarner-org/claude-code/data/CLAUDE.md

demos in Segments 3 and 4 point Claude at these files to show security review, refactoring, PR review, and MCP memory in action. The files are staged to be found

2232mo agoReads credentialsDiscuss
initializCLAUDE.md

forge

initializ/forge/CLAUDE.md

Structure Multi-module Go workspace with three modules: - `forge-core/` — Core library (registry, tools, security, channels, LLM) - `forge-cli/` — CLI commands, TUI wizard, runtime - `forge-plugins/` — Channel plugins (telegram, slack

2223mo agoDiscuss
secondskyCLAUDE.md

claude-skills

secondsky/claude-skills/CLAUDE.md

started/ # Onboarding guides │ ├── guides/ # Contribution, best practices, marketplace ops │ ├── reference/ # Standards, categorization, common mistakes │ ├── security-audit/ # Audit reports and findings │ └── validation/ # JSON schema validation docs ├── schemas/ # JSON schemas (marketplace, plugin

22222d agoDiscuss
Maneek21CLAUDE.md

Deft

Maneek21/Deft/CLAUDE.md

window. Soft-deleted projects hide from views but preserve tasks for audit. - **Task 0.1 security fix (resolved)** — watchers + assignees routes enforce `org_id` + auth. - **Task 0.4 dashboard fix (resolved

2214mo agoReads credentialsDiscuss
netboxlabsCLAUDE.md

netbox-mcp-server

netboxlabs/netbox-mcp-server/CLAUDE.md

token with appropriate permissions - `LOG_LEVEL`: Logging verbosity (default: `INFO`, options: `DEBUG`, `WARNING`, `ERROR`) ## Security Considerations - **Read-only tokens**: Always use read-only API tokens with minimal required permissions

22112mo agoDiscuss
shaharia-labCLAUDE.md

slackcli

shaharia-lab/slackcli/CLAUDE.md

helps the community and maintainer understand and evaluate the request. ### 4. Code quality and security are top priority - Code quality and security MUST be treated as the highest priority

22046d agoDiscuss
nirholasCLAUDE.md

three.ws

nirholas/three.ws/CLAUDE.md

feeds the changelog automatically. - **Everything else users would notice** (feature, improvement, fix, SDK release, security work): append an entry to `data/changelog.json` with date, community-readable title + summary (plain language

21711d agoReads credentialsDiscuss
spytensorCLAUDE.md

openmozi

spytensor/openmozi/CLAUDE.md

watchdog/ # Independent process: heartbeat, auto-restart, force kill ├── config/ # Config management with hot-reload ├── security/ # JWT (HMAC-SHA256), RBAC, permissions (L0-L3), hard gates, │ # enterprise auth (OIDC/SAML stubs), pairing ├── tenants

2152mo agoReads credentialsDiscuss
alexei-ledCLAUDE.md

k8s-mcp-server

alexei-led/k8s-mcp-server/CLAUDE.md

parameter - `ToolAnnotations`: `readOnlyHint=True` for describe tools, `destructiveHint=True, openWorldHint=True` for execute tools ### Security (`src/k8s_mcp_server/security.py`) - `validate_command()` — blocked patterns, required resource names for destructive ops - `kubectl exec` restrictions

2137mo agoDiscuss
tigerless-labsCLAUDE.md

design-harness

tigerless-labs/design-harness/CLAUDE.md

experiments/`, and the invariant or doc that rests on them links back as `evidence:`. ## Security — agents run autonomously, so the system must fail safe - **Trust nothing by default.** Treat external

2133mo agoDiscuss
samberCLAUDE.md

cc-skills

samber/cc-skills/CLAUDE.md

domain expertise that enriches any relevant conversation without being explicitly asked — code style, security patterns, brand voice, commit conventions. Use `true` (user-invocable) for multi-step workflows the user explicitly

21243d agoDiscuss
CLAUDE.md vs AGENTS.md

About CLAUDE.md

What is CLAUDE.md?

A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.

Where does it go?

At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.

What should it contain?

Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.

CLAUDE.md or AGENTS.md?

Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.