agentleFS
Sign inSign up

CLAUDE.md examples from real projects

How real projects brief Claude Code: the commands, conventions and warnings they put in CLAUDE.md.

Best matchesWorked for most · soon
affaan-mCLAUDE.md

ECC

affaan-m/ECC/CLAUDE.md

/e2e, etc.) - **hooks/** - Trigger-based automations (session persistence, pre/post-tool hooks) - **rules/** - Always-follow guidelines (security, coding style, testing requirements) - **mcp-configs/** - MCP server configurations for external integrations - **scripts/** - Cross-platform

246k30d agoDiscuss
affaan-mCLAUDE.md

ECC / examples

affaan-m/ECC/examples/CLAUDE.md

Unit tests for utilities - Integration tests for APIs - E2E tests for critical flows ### 4. Security - No hardcoded secrets - Environment variables for sensitive data - Validate all user inputs - Parameterized queries only

246k30d agoReads credentialsDiscuss
n8n-ioCLAUDE.md

n8n

n8n-io/n8n/.github/CLAUDE.md

visual) | | `ci-` | Continuous integration | | `util-` | Utilities (notifications) | | `build-` | Build processes | | `release-` | Release automation | | `sec-` | Security scanning | Reusable workflows: add `-reusable` or `-callable` suffix. ### Common Tasks **Add workflow:** Create in `workflows

206k19d agoDiscuss
Significant-GravitasCLAUDE.md

AutoGPT / classic

Significant-Gravitas/AutoGPT/classic/CLAUDE.md

agents (saves to `autogpt.yaml`) | | **Deny** | Deny this command (saves to appropriate deny list) | ### Default Security Out of the box, the following are **denied by default**: - Reading sensitive files

188k19d agoReads credentialsDiscuss
garrytanCLAUDE.md

gstack

garrytan/gstack/CLAUDE.md

listener rules, Unicode sanitization at egress, SSE/CDP helpers, setup symlink hardening, and the sidebar security stack all live there, each pinned by a CI tripwire. **Egress receipts at every

134k6d agoReads credentialsDiscuss
browser-useCLAUDE.md

browser-use

browser-use/browser-use/CLAUDE.md

file management - **PopupsWatchdog**: Manages JavaScript dialogs and popups - **SecurityWatchdog**: Enforces domain restrictions and security policies - **DOMWatchdog**: Processes DOM snapshots, screenshots, and element highlighting - **AboutBlankWatchdog**: Handles empty page redirects ### CDP Integration

117k4mo agoDiscuss
JuliusBrusseeCLAUDE.md

caveman

JuliusBrussee/caveman/CLAUDE.md

until changed or session ends. ### Auto-clarity rule Caveman drops to normal prose for: security warnings, irreversible action confirmations, multi-step sequences where fragment ambiguity risks misread, user confused

108k6mo agoPipes a download into a shellDiscuss
addyosmaniCLAUDE.md

agent-skills

addyosmani/agent-skills/CLAUDE.md

skills/ → Core skills (SKILL.md per directory) agents/ → Reusable agent personas (code-reviewer, test-engineer, security-auditor, web-performance-auditor) hooks/ → Session lifecycle hooks .claude/commands/ → Slash commands (/spec, /plan, /build, /test

100k5d agoDiscuss
ruvnetCLAUDE.md

RuView

ruvnet/RuView/CLAUDE.md

them. ## Contributor metaharness (`@ruvnet/ruview@0.4.0`) ADR-283 defines the current community metaharness. It adds secure local Claude/Codex execution, a reviewed shared brain, default-deny MCP mutation policy, and gated Darwin/Flywheel

95k7mo agoReads credentialsDiscuss
Model Context ProtocolCLAUDE.md

servers

modelcontextprotocol/servers/CLAUDE.md

reviewed against the [PR template](.github/pull_request_template.md) checklist -- ensure MCP docs are read, security best practices followed, and changes tested with an LLM client

91k6mo agoDiscuss
ruvnetCLAUDE.md

ruflo

ruvnet/ruflo/CLAUDE.md

tasks, low complexity (<30%) | | **3** | Sonnet/Opus | 2-5s | $0.003-0.015 | Complex reasoning, architecture, security (>30%) | - Always check for `[CODEMOD_AVAILABLE]` or `[TASK_MODEL_RECOMMENDATION]` before spawning agents - When

73k21d agoReads credentialsDiscuss
ruvnetCLAUDE.md

ruflo / v3

ruvnet/ruflo/v3/CLAUDE.md

/shared/` | Shared types and utilities | | `@claude-flow/security` | `@claude-flow/security/` | Input validation, path security, CVE remediation | ## Code Quality - Files under 500 lines - No hardcoded secrets - Input validation at system

73k21d agoDiscuss
CherryHQCLAUDE.md

cherry-studio

CherryHQ/cherry-studio/CLAUDE.md

MUST READ**: [docs/references/ipc/README.md](docs/references/ipc/README.md) — paradigm boundary (RPC vs REST), schema/router/preload/facade layering, `IpcContext`, error model, security. Non-data command IPC (window/system/shell/notification/external/file) goes through **IpcApi** — the fifth subsystem alongside BootConfig/Cache/Preference/DataApi, RPC-over

52k42d agoDiscuss
Imbad0202CLAUDE.md

academic-research-skills

Imbad0202/academic-research-skills/.claude/CLAUDE.md

with matrix-mirrored statuses and an asserted-status ceiling). - **Governance stated, security response proceduralized.** Root `GOVERNANCE.md` records decision authority, per-operator cross-model scope (error-detection control, not organizational independence

50k6d agoDiscuss
luongnv89CLAUDE.md

claude-howto / uk

luongnv89/claude-howto/uk/CLAUDE.md

Якість коду ```bash # Lint and format Python code ruff check scripts/ ruff format scripts/ # Security scan bandit -c scripts/pyproject.toml -r scripts/ --exclude scripts/tests/ # Type checking mypy scripts/ --ignore-missing-imports

42k5d agoDiscuss
luongnv89CLAUDE.md

claude-howto / vi

luongnv89/claude-howto/vi/CLAUDE.md

Lượng Code ```bash # Lint và format Python code ruff check scripts/ ruff format scripts/ # Security scan bandit -c scripts/pyproject.toml -r scripts/ --exclude scripts/tests/ # Type checking mypy scripts/ --ignore-missing-imports

42k5d agoDiscuss
AnthropicCLAUDE.md

financial-services

anthropics/financial-services/CLAUDE.md

named agent) │ └── / │ ├── agent.yaml # system + skills → ../../plugins/agent-plugins/ /... │ ├── subagents/*.yaml # depth-1 leaf workers │ ├── steering-examples.json │ └── README.md # security tier + handoff notes ├── claude-for-msft-365-install/ # admin tooling for the Microsoft

38k2mo agoDiscuss
davila7CLAUDE.md

claude-code-templates

davila7/claude-code-templates/CLAUDE.md

push to `main` > (changes in `dashboard/**`). Manual deploy uses `wrangler pages deploy`, not Vercel. ## Security Guidelines ### ⛔ CRITICAL: NEVER Hardcode Secrets or IDs **NEVER write API keys, tokens, passwords, project

32k3mo agoReads credentialsDiscuss
davila7CLAUDE.md

claude-code-templates

davila7/claude-code-templates/docs/CLAUDE.md

type has specific structure: **Agents** (162 total) - AI specialists organized by category (Development, Data/AI, Security, Business, etc.) - Stored in `cli-tool/components/agents/{category}/{name}.md` - Installation: `--agent ` **Commands** (210 total

32k3mo agoDiscuss
tirth8205CLAUDE.md

code-review-graph

tirth8205/code-review-graph/CLAUDE.md

clients. - File reads: read the bytes once, hash them, then parse the same bytes. ## Security Invariants - No `eval()`, `exec()`, `pickle` or `yaml.unsafe_load()`. - No `shell=True` in subprocess calls. - `_validate

32k4mo agoDiscuss

About CLAUDE.md

What is CLAUDE.md?

A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.

Where does it go?

At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.

What should it contain?

Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.

CLAUDE.md or AGENTS.md?

Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.