agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matchesWorked for most · soon
zhaoxuya520Skill

api-security

zhaoxuya520/reverse-skill/skills/api-security/SKILL.md

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

38k9d agoDiscuss
zhaoxuya520Skill

llm-security

zhaoxuya520/reverse-skill/skills/llm-security/SKILL.md

Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.

38k9d agoDiscuss
OpenAISkill

security-scan

openai/codex-security/plugins/codex-security/skills/security-scan/SKILL.md

Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.

11k20d agoDiscuss
SentrySkill

sentry-security

getsentry/sentry/.agents/skills/sentry-security/SKILL.md

Sentry-specific security review based on real vulnerability history. Use when reviewing Sentry endpoints, serializers, or views for security issues. Trigger keywords: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint".

45k3mo agoDiscuss
ruvnetSkill

security-audit

ruvnet/ruflo/.agents/skills/security-audit/SKILL.md

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

73k21d agoDiscuss
PostHogSkill

security-audit

PostHog/posthog/.agents/skills/security-audit/SKILL.md

Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings. Use when the user asks to "audit", "security-audit", "find vulnerabilities", "check for IDOR/SSRF/XSS/injection", or wants a security review of a file, directory, branch diff, or PR. Covers access control, injection, auth/secrets, sensitive data, business logic, web boundary, and AI agent/LLM trifecta risks. Produces calibrated findings with data flow, exploit request, fix, and confidence — no theoretical or defense-in-depth nits.

40k5d agoReads credentialsDiscuss
zhaoxuya520Skill

email-security

zhaoxuya520/reverse-skill/skills/email-security/SKILL.md

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

38k9d agoDiscuss
affaan-mSkill

security-review

affaan-m/ECC/.agents/skills/security-review/SKILL.md

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

246k30d agoReads credentialsDiscuss
DonchitosSkill

security-audit

Donchitos/Claude-Code-Game-Studios/.claude/skills/security-audit/SKILL.md

Security audit — save tampering, cheat vectors, network exploits, data exposure, input validation. Before public or multiplayer release.

25k8d agoDiscuss
CloudflareSkill

security-audit

cloudflare/security-audit-skill/skills/security-audit/SKILL.md

Security guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts.

18k16d agoDiscuss
GitHubSkill

security-review

github/awesome-copilot/skills/security-review/SKILL.md

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for SQL injection, XSS, command injection, exposed API keys, hardcoded secrets, insecure dependencies, access control issues, or any request like "is my code secure?", "review for security issues", "audit this codebase", or "check for vulnerabilities". Covers injection flaws, authentication and access control bugs, secrets exposure, weak cryptography, insecure dependencies, and business logic issues across JavaScript, TypeScript, Python, Java, PHP, Go, Ruby, and Rust.

39k8d agoReads credentialsDiscuss
AnthropicSkill

claude-security

anthropics/claude-plugins-official/plugins/claude-security/skills/claude-security/SKILL.md

Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the user asks to scan, audit or check code with Claude Security, to scan their changes with Claude Security, or to fix or patch Claude Security findings.

37k7mo agoDiscuss
rtk-aiSkill

security-guardian

rtk-ai/rtk/.claude/skills/security-guardian/SKILL.md

CLI security expert for RTK - command injection, shell escaping, hook security

82k8d agoDeletes or force-pushesDiscuss
code-yeongyuSkill

security-research

code-yeongyu/oh-my-openagent/.agents/skills/security-research/SKILL.md

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

70k10d agoDiscuss
zhaoxuya520Skill

database-security

zhaoxuya520/reverse-skill/skills/database-security/SKILL.md

Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.

38k9d agoDiscuss
zhaoxuya520Skill

hardware-security

zhaoxuya520/reverse-skill/skills/hardware-security/SKILL.md

Use for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support.

38k9d agoDiscuss
Model Context ProtocolSkill

security-advisory

modelcontextprotocol/inspector/.claude/skills/security-advisory/SKILL.md

Take a privately reported vulnerability through this repo's security advisory flow — board it, verify who owns the code path, accept or reject, fix it in the private fork, ship to every affected release line, publish, then turn the card into public tracking. Use when a vulnerability is reported privately; when deciding whether an advisory is ours to fix; when looking up or creating its private fork; when answering a reporter; or when a GHSA-titled board card needs handling.

11k8d agoReads credentialsDiscuss
OpenAISkill

deep-security-scan

openai/codex-security/plugins/codex-security/skills/deep-security-scan/SKILL.md

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

11k20d agoDiscuss
OpenAISkill

security-diff-scan

openai/codex-security/plugins/codex-security/skills/security-diff-scan/SKILL.md

Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.

11k20d agoDiscuss
GitHubSkill

mcp-security-audit

github/awesome-copilot/skills/mcp-security-audit/SKILL.md

Audit MCP (Model Context Protocol) server configurations for security issues. Use this skill when: - Reviewing .mcp.json files for security risks - Checking MCP server args for hardcoded secrets or shell injection patterns - Validating that MCP servers use pinned versions (not @latest) - Detecting unpinned dependencies in MCP server configurations - Auditing which MCP servers a project registers and whether they're on an approved list - Checking for environment variable usage vs. hardcoded credentials in MCP configs - Any request like "is my MCP config secure?", "audit my MCP servers", or "check .mcp.json" keywords: [mcp, security, audit, secrets, shell-injection, supply-chain, governance]

39k8d agoReads credentialsDiscuss

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.