agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 13Worked for most · soon
joris887Skill

security-audit

joris887/exosuit/.claude/skills/security-audit/SKILL.md

Security review for code touching authentication, credentials, file access, or user data. Includes CWE checklist ranked by AI vulnerability frequency, phantom package detection, ASVS-aligned controls, and supply chain checks. MANDATORY for auth code, credential handling, file operations with user data, network comms, or database queries with user input.

742d agoDiscuss
AWSSkill

setup-security-agent

aws/agent-toolkit-for-aws/plugins/aws-agents-for-devsecops/skills/setup-security-agent/SKILL.md

Configure AWS Security Agent for the current workspace — provision or reuse an agent space, IAM service role, and S3 bucket. Use when the user asks to "set up security agent", "configure security scanner", "is security agent configured", or on first-time use before any scan or pentest.

2.7k4mo agoDiscuss
imMamdouhaboammarSkill

fable-security

imMamdouhaboammar/get-fable/skills/fable-security/SKILL.md

Conduct threat modeling, vulnerability assessments, secret sanitization, and security reviews across trust boundaries, auth flows, and untrusted inputs. Use when auditing authentication/authorization logic, inspecting APIs for injection/CORS/CSRF risks, checking for hardcoded credentials, or reviewing security-sensitive diffs — even if the user does not explicitly say \"fable-security\" (e.g. \"security audit this code\", \"check for vulnerabilities\", \"verify auth logic\", \"scan for leaked secrets\"). Do NOT use for general style reviews (use fable-review) or non-security bug fixes (use fable-tdd).

633d agoDiscuss
vignesh2027Skill

security-chief

vignesh2027/Claude-Agentic-Skills2.0-version/security-chief/SKILL.md

Activates SecurityChief for cybersecurity analysis and threat intelligence. Use when you need STRIDE threat modeling for any system architecture, OWASP top 10 analysis, security log analysis and SIEM triage, incident response playbook execution, SOC2/ISO 27001/NIST CSF control mapping, or vulnerability assessment and remediation planning.

64mo agoDiscuss
dralgorhythmSkill

security-auditor

dralgorhythm/claude-agentic-framework/.claude/skills/security-auditor/SKILL.md

Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.

1182mo agoDiscuss
zhaoxuya520Skill

supply-chain-security

zhaoxuya520/reverse-skill/skills/supply-chain-security/SKILL.md

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

38k9d agoDiscuss
JamalMohafilSkill

security-review

JamalMohafil/claude-skills/security-review/SKILL.md

Run a security review of code changes exactly like Claude Code's /security-review command — but in ANY AI coding agent (Claude Code, Cursor, Codex, Windsurf, Gemini CLI, Cline…). Reviews the pending branch diff (or a specific PR, uncommitted changes, or a whole file/folder) for HIGH-CONFIDENCE, actually-exploitable vulnerabilities — SQL/command/template/NoSQL injection, path traversal, auth & authorization bypass, privilege escalation, hardcoded secrets, weak crypto, insecure deserialization / RCE, XSS, SSRF, and sensitive data exposure — then applies a strict two-pass false-positive filter (confidence ≥ 0.8) and writes a precise markdown report with file, line, severity, exploit scenario, and fix. Optionally fixes each confirmed finding. Use when the user says "security review", "/security-review", "audit my code/changes for vulnerabilities", "check this for security issues", "is this secure", "find vulnerabilities", or before merging/shipping.

2510d agoDiscuss
atherio-danpSkill

security-backend

atherio-danp/cde-dotnetcc/.claude/skills/security-backend/SKILL.md

Audit the .NET backend (apps/api) for security issues against OWASP Top 10 mapped to .NET/Minimal API/EF Core (Npgsql), plus tenant isolation, secret handling, and EU data residency. Use when reviewing backend changes for security, or running a backend security audit. Preloaded by the security-auditor-backend agent.

1093mo agoDiscuss
hongyuancSkill

security-audit

hongyuanc/codex-game-studios/.agents/skills/security-audit/SKILL.md

Use when game code or data flows need a diagnostic security review before release or multiplayer exposure.

53mo agoDiscuss
KhaledSaeed18Skill

owasp-security

KhaledSaeed18/dotclaude/skills/security/owasp-security/SKILL.md

Review code being written or modified against the OWASP Top 10:2025 and ASVS secure-coding requirements, in any language or stack, catching vulnerability classes before they ship. Use when writing auth logic, handling user input, adding API endpoints, choosing cryptography, processing uploads, or touching any trust boundary. Complements secret-scan and dependency-audit with line-level review.

53mo agoDiscuss
TheBeardedBearSASSkill

security-flutter

TheBeardedBearSAS/claude-craft/.claude/skills/security-flutter/SKILL.md

Sécurité Flutter. Use when reviewing security, implementing auth, or hardening code.

1052mo agoDiscuss
MicrosoftSkill

security-report-check

microsoft/TypeScript/.github/skills/security-report-check/SKILL.md

Are you doing security research on this repo? This document covers what guarantees and non-guarantees are provided. Consult this document before reporting a security issue or conducting security research.

111k2y agoDiscuss
MagerkoSkill

launch-security

Magerko/claude-code-skills/skills/launch-security/SKILL.md

Пред-запусковый аудит безопасности приложения — секреты и ключи, аутентификация и сессии, доступ к чужим данным (IDOR, RLS), инъекции и XSS, загрузка файлов, заголовки и CORS, лимиты и расходы, утечки в ответах и логах, зависимости, прод-гигиена, вебхуки и платежи. Выдаёт отчёт с приоритетами; код не правит. Только ручной запуск.

2248d agoDiscuss
wgpsecSkill

ai-identity-security

wgpsec/AboutSecurity/skills/ai-security/ai-identity-security/SKILL.md

AI 系统身份与权限安全测试方法论。当目标系统涉及 Agent 身份认证、多 Agent 权限管理、 角色设定安全、会话管理、或 MCP/API 凭据管控时触发。 覆盖: 角色逃逸(假定场景/假定角色/遗忘法/目标劫持)、权限失控(Action 越权/MCP 未授权资源获取)、 多 Agent 身份伪造、会话劫持、凭据泄露与滥用。

1.8k4mo agoDiscuss
gtrabancoSkill

review-security

gtrabanco/agentic-workflow/skills/review-security/SKILL.md

Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks secrets, input validation, injection, authn/authz, PII exposure, and dependency risk on the changed surface. Findings only; never edits code.

218d agoDiscuss
wintermeyerSkill

heinzel-security

wintermeyer/heinzel/.claude/skills/heinzel-security/SKILL.md

Run a heinzel security audit on a server — SSH

9111d agoDiscuss
EyadkellehSkill

security-patterns

Eyadkelleh/awesome-skills-security/skills/security-patterns/SKILL.md

Sensitive data patterns for security testing: API keys, credit cards, emails, SSNs, phone numbers, IPs, and more. Use for data discovery and validation.

3844mo agoDiscuss
EyadkellehSkill

security-payloads

Eyadkelleh/awesome-skills-security/skills/security-payloads/SKILL.md

Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.

3844mo agoDiscuss
claude-worldSkill

security-audit

claude-world/claude-agent/.claude/skills/security-audit/SKILL.md

Audit host security using built-in system tools (netstat, lsof, ss, ufw, systemctl, ps, who, last). Check open ports, running services, listening processes, firewall rules, and recent logins. No external CLI needed. Use when user says "security audit", "check open ports", "harden server", or "what's listening on my machine".

46mo agoDiscuss
Cogni-AI-OUSkill

security-audit

Cogni-AI-OU/cogni-ai-agent-skills/security-audit/SKILL.md

Commands, step-by-step procedures, and mechanical execution for performing deep security audits, vulnerability assessments, and report generation on codebases and configurations. You MUST load this skill when performing security audits or validation.

45mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.