agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 12Worked for most · soon
racciolySkill

security-pass

raccioly/websec-validator/skills/security-pass/SKILL.md

Defensive security self-assessment of the operator's OWN codebase. Local and read-only by default — it reads the repo, runs static scanners, and writes a briefing; no live system is touched. Active probes are opt-in, run only against a TEST instance the human owns and supplies, and require explicit per-run human approval; production and third-party targets are out of scope. Use when the user wants to security-review their own app, harden it, check for BOLA/IDOR/JWT/SSRF/mass-assignment issues, pentest their own code, or "see if my app is safe" before shipping.

23mo agoDiscuss
loulanyueSkill

laravel-security

loulanyue/awesome-claude-notes/skills/laravel-security/SKILL.md

Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

2726mo agoDiscuss
GitHubSkill

developer-security

github/gh-aw/.github/skills/developer-security/SKILL.md

Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration.

5.2k4mo agoDiscuss
naviktSkill

security-review

navikt/copilot/skills/security-review/SKILL.md

Bruk før commit, push eller pull request for å sjekke at koden er trygg å merge

5416d agoDiscuss
wpankSkill

solidity-security

wpank/ai/skills/devops/solidity-security/SKILL.md

Smart contract security patterns, vulnerability prevention, gas optimization, and audit preparation for Solidity development. Use when writing, auditing, or hardening smart contracts against reentrancy, overflow, access control, oracle manipulation, and front-running attacks.

118mo agoDiscuss
ruvnetSkill

V3 Security Overhaul

ruvnet/RuView/.claude/skills/v3-security-overhaul/SKILL.md

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

95k7mo agoDiscuss
MicrosoftSkill

security-review

microsoft/devsquad-copilot/.github/plugins/devsquad/skills/security-review/SKILL.md

Security assessment workflow in two modes: architectural (design) and code (implementation). Use when a security trigger is detected during planning (architectural mode) or implementation/review (code mode). Covers STRIDE, OWASP, dependency scanning, Azure compliance, and GitHub security alerts. Do not use for general code quality (use devsquad.review), for threat modeling as a standalone activity, or for compliance audits.

445mo agoDiscuss
emaraschioSkill

security-audit

emaraschio/cursor-commands/.cursor/skill-contracts/security-audit/SKILL.md

Security audit of codebase or change

955d agoDiscuss
ruvnetSkill

V3 Security Overhaul

ruvnet/ruflo/.agents/skills/v3-security-overhaul/SKILL.md

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

73k21d agoDiscuss
talayashSkill

security-review

talayash/agentrium/.claude/skills/security-review/SKILL.md

Security audit checklist and patterns for Tauri desktop apps with PTY spawning

4120d agoDiscuss
wolverin0Skill

security-review

wolverin0/claude-skills/skills/security-review/SKILL.md

Review security-sensitive code changes involving auth, user input, secrets, APIs, payments, files, RLS, or third-party integrations.

4138d agoDiscuss
GoogleSkill

gke-workload-security

google/skills/skills/cloud/gke-workload-security/SKILL.md

Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling), and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing cluster security posture, isolating namespaces, applying pod security standards, setting up Workload Identity, or configuring network policies and secret volume mounts. Don't use for cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).

20k10d agoDiscuss
DIL8654Skill

security-audit

DIL8654/claude-code-dotnet-template/.claude/skills/security-audit/SKILL.md

Review .NET services for safe defaults in input handling, authentication, authorization, secret management, logging exposure, and configuration hygiene. Use before release, during reviews, or when hardening an API or integration.

86mo agoDiscuss
lilangMaxSkill

security-audit

lilangMax/ClaudeCodeGameStudios/.claude/skills/security-audit/SKILL.md

Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.

85mo agoDiscuss
Helg-gitSkill

web3-security

Helg-git/claude-skills/web3-security/SKILL.md

Web3 安全审计专家 - 智能合约漏洞检测与防护

18mo agoDiscuss
lwhsuSkill

port-security

lwhsu/freebsd-claude-skills/skills/port-security/SKILL.md

Handle a FreeBSD port security advisory. This skill should be used when the user needs to create a VuXML entry and update a port for a security vulnerability, or mentions CVE, security advisory, or VuXML.

156d agoDiscuss
pinkpixel-devSkill

tauri-security

pinkpixel-dev/tauri-skills/skills/tauri-security/SKILL.md

Guidance for Tauri v2 capabilities, scope configuration, and ACL-based permission control.

153d agoDiscuss
OpenAISkill

security-best-practices

openai/skills/skills/.curated/security-best-practices/SKILL.md

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

27k7mo agoDiscuss
CTOexpertSkill

cybersorted

CTOexpert/claude-skills/cybersorted/SKILL.md

Security and enterprise architecture advisory skill. Use this skill when the user needs help with cybersecurity strategy, threat modeling, risk assessment, compliance, security architecture, enterprise architecture, or governance. Trigger when the user mentions: security posture, threat model, STRIDE, PASTA, risk assessment, risk register, compliance mapping, SOC2, ISO 27001, NIST 800-53, CIS benchmarks, MITRE ATT&CK, zero trust, incident response, IR plan, security policy, architecture decision record, ADR, vendor risk, third-party risk, board briefing, security maturity, maturity assessment, gap analysis, security review, code review for security, IaC review, Terraform security, Kubernetes security, CI/CD security, API security, cloud configuration review, tabletop exercise, red team, blue team, penetration test planning, security architecture, network segmentation, defense in depth, least privilege, data classification, encryption strategy, key management, identity and access management, IAM, SIEM, SOC, vulnerability management, patch management, business continuity, disaster recovery, BCP, DRP, privacy by design, GDPR, CCPA, data protection, platform security, build vs buy security, DevSecOps, shift left security, supply chain security, SBOM, secure coding, secure by design, OWASP Top 10, OWASP ASVS, OWASP SAMM, input validation, output encoding, SQL injection prevention, XSS prevention, CSRF prevention, secrets management, dependency security, SAST, DAST, SCA, secure API design, penetration test, pentest, pen test, red team, offensive security, vulnerability assessment, exploit, Kerberoasting, Active Directory attack, privilege escalation, lateral movement, CVSS, CSTM, Cyber Scheme, web application testing, network penetration test, cloud penetration test, container security testing, physical security assessment, or any security and architecture advisory request. Supports roles: CISO, CTO, CPO, Security Architect, Security Engineer, Enterprise Architect, Secure Developer, Penetration Tester.

07mo agoDiscuss
diegocconsoliniSkill

security-hooks

diegocconsolini/ClaudeSkillCollection/security-hooks/SKILL.md

Use this skill to install ready-made Claude Code hooks for security — a ConfigChange compliance audit trail (logs every settings/skill change), plus PreToolUse guards and optional HTTP notifications for security-relevant events. Covers command, http, and prompt hook types.

712mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.