agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 10Worked for most · soon
igmarinSkill

security-check

igmarin/rails-agent-skills/skills/security-check/SKILL.md

Use when auditing a Rails app for XSS, CSRF, SQLi, IDOR, secrets, or auth bypass. Never print secrets. Trigger words: security, audit, XSS, CSRF, SQL injection, vulnerability.

262mo agoDiscuss
0xlayerghostSkill

defi-security

0xlayerghost/solidity-agent-kit/skills/defi-security/SKILL.md

[AUTO-INVOKE] MUST be invoked BEFORE deploying DeFi contracts (DEX, lending, staking, LP, token). Covers anti-whale, anti-MEV, flash loan protection, launch checklists, and emergency response. Trigger: any deployment or security review of DeFi-related contracts.

47mo agoDiscuss
carreirasSkill

security-lgpd

carreiras/claude-skills/security-lgpd/SKILL.md

Guia completo de conformidade com a LGPD (Lei Geral de Proteção de Dados — Lei 13.709/2018) para desenvolvimento de software e operações de TI no Brasil. Use esta skill sempre que o usuário mencionar LGPD, proteção de dados pessoais, dados sensíveis, consentimento, base legal, titular de dados, ANPD, DPO (Encarregado), ROPA (Registro de Atividades de Tratamento), DPIA (Relatório de Impacto), DSR (requisição de titular), incidente de dados, vazamento de dados, anonimização, pseudonimização, retenção de dados, transferência internacional, privacy by design, privacy by default, ou quando o usuário perguntar "isso está em conformidade com a LGPD?", "preciso de consentimento para isso?", "como implementar LGPD no sistema?", "quais dados posso coletar?", "como responder uma solicitação de titular?", ou qualquer variação relacionada à privacidade de dados pessoais de usuários brasileiros ou de sistemas operando no Brasil.

43mo agoDiscuss
gonimarSkill

team-security

gonimar/claude-web-studio/skills/team-security/SKILL.md

Full security cycle: threat-model refresh → security-audit (code) → dependency-audit → harden (perimeter/containers) → optional pentest of the project's own app → consolidated report and stories. Use before release or after adding auth/payments/uploads/multiplayer.

43d agoDiscuss
zloetherSkill

okta-security

zloether/okta-skills/skills/okta-security/SKILL.md

Read Okta ThreatInsight configuration, security events providers (Shared Signals Framework / SSF receivers), SSF stream status, and bot protection settings. Use when asked about suspicious IP handling, whether ThreatInsight blocks or audits requests, SSF/CAEP integrations for cross-app session signal sharing, or bot detection enforcement.

434d agoDiscuss
ethosagentSkill

security-audit

ethosagent/ethos/.agents/skills/security-audit/SKILL.md

Subsystem-scoped security audit of the Ethos codebase. Use when asked to "audit the gateway", "review the trust boundaries of X", "security review of subsystem Y", "check personality isolation", "audit the skill loader", "audit the channel adapter", or any focused security-posture question against a named subsystem. NOT for per-PR diff review (that's a different motion). NOT for "audit Ethos" without a subsystem named — split the audit before starting. Produces an evidence-led report at plan/audits <subsystem>-audit-YYYY-MM-DD.{html,md}. Read-only — never edits the codebase during the audit. Does not commit; the user decides what to do with findings.

2226d agoDiscuss
TheBeardedBearSASSkill

security-symfony

TheBeardedBearSAS/claude-craft/.claude/skills/security-symfony/SKILL.md

Sécurité & RGPD - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.

1052mo agoDiscuss
jim60105Skill

security-audit

jim60105/copilot-prompt/skills/security-audit/SKILL.md

Security audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.

213d agoDiscuss
anton-karlovskiySkill

web-security

anton-karlovskiy/claude-code-demo/.claude/skills/web-security/SKILL.md

Enforce web security and avoid security vulnerabilities

05mo agoDiscuss
beelabstudioSkill

security-scan

beelabstudio/ai/skills/security/security-scan/SKILL.md

Scan a Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. Use when auditing a .claude/ directory — CLAUDE.md, settings.json, MCP servers, hooks, or agent definitions — before committing config changes or onboarding to a repo with existing agent configs.

011d agoDiscuss
blamejsSkill

api-security

blamejs/exceptd-skills/skills/api-security/skill.md

API security for mid-2026 — OWASP API Top 10 2023, AI-API specific (rate limits, prompt-shape egress, MCP HTTP transport), GraphQL + gRPC + REST + WebSocket attack surfaces, API gateway posture, BOLA/BFLA/SSRF/Mass Assignment

045d agoDiscuss
dajneem23Skill

evm-security

dajneem23/my-evm-security-skills/SKILL.md

Security assessment and hardening workflow for EVM smart contracts. Use when Codex needs to audit Solidity or Vyper code, review protocol architecture for abuse paths, validate access control and value-accounting invariants, assess upgradeable/proxy deployments, evaluate oracle/bridge/DEX integration risk, or produce prioritized remediation guidance with reproducible proof-of-concept tests.

07mo agoDiscuss
danwykesdevSkill

saas-security

danwykesdev/skills/security/SKILL.md

Create or review threat models, data classification, tenancy controls, upload security, API secret handling, and public route security.

04mo agoDiscuss
dataGriffSkill

api-security

dataGriff/skills/skills/api-security/SKILL.md

Review, harden, and design HTTP APIs against the OWASP API Security Top 10 (2023): object- and property-level authorization (BOLA/IDOR, mass assignment, over-exposure), authentication and JWT/OAuth2 token validation, unrestricted resource consumption and rate limiting, SSRF, misconfiguration (CORS, TLS, headers, error leakage), and endpoint inventory. Produces evidence-backed findings ranked by severity with concrete fixes. Use when the user asks for an API security review, audit, or threat model, asks "is my API secure" or to prepare for a pen test, mentions BOLA, IDOR, broken auth, mass assignment, rate limiting, or the OWASP API Top 10, wants security requirements for a new API design, or asks to fix an authentication or authorization bug in an API.

021d agoDiscuss
EndikaSkill

security-bar

Endika/eskills/skills/security-bar/SKILL.md

Use when reviewing changes for security to apply my checklist on top of security-review — input handling, secrets, authz, Supabase RLS, egress limits, server-side PIN enforcement, and the agent-harness surface (config secrets, hook injection, MCP risk, over-broad permissions).

014d agoDiscuss
hereshecodesSkill

api-security

hereshecodes/secureskills/skills/api-security/SKILL.md

Use when building REST APIs, GraphQL endpoints, or webhooks

07mo agoDiscuss
leaf76Skill

security-scan

leaf76/agent-skills/security-scan/SKILL.md

Comprehensive security scanning and vulnerability assessment for code, dependencies, and infrastructure. Includes SAST, DAST, dependency scanning, and security hardening recommendations. Use before deployments, after major changes, or for regular security audits.

045d agoDiscuss
lgzarturoSkill

security-grc

lgzarturo/codeconductor/.agents/skills/security-grc/SKILL.md

Map controls to SOC2, ISO 27001, PCI, or internal policy for the org you work for. Evidence and control design — not audit theater.

015d agoDiscuss
lgzarturoSkill

security-web

lgzarturo/codeconductor/.agents/skills/security-web/SKILL.md

Review and harden web apps (authz, XSS, CSRF, SSRF, injection) on code you maintain. Complements the OWASP `security` skill. No exploit kits.

015d agoDiscuss
prasadmogulothuSkill

rls-security

prasadmogulothu/agent-skills/rls-security/SKILL.md

Generate row-level-security policies plus a cross-user isolation test, so users can only access their own rows. Written for Postgres/Supabase; adaptable to other databases. Use for any per-user or multi-tenant data.

03mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.