agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 14Worked for most · soon
gabrieldabbahSkill

security-audit

gabrieldabbah/genesis/skills/security-audit/SKILL.md

Audit a surface for security problems, score them honestly, and turn each into a task with a fix. Use before declaring work done, after wiring an integration, before a deploy handoff, or when the user says \"/security-audit\", \"check security\", \"audit this\", \"is this safe\". Builds the checklist from general application-security concerns plus the per-integration items in the integrations registry. Reports findings with severity, file:line and evidence; states which fixes it applied and which need a human decision; never prints secrets.

42mo agoDiscuss
gonimarSkill

security-audit

gonimar/claude-web-studio/skills/security-audit/SKILL.md

Audits the application against OWASP Top 10:2025 / ASVS for the project's stack — code review by appsec-engineer, tooling (vulnerability, secret and SAST scanners), CVSS-scored findings with fixes in docs/security/security-audit-<date>.md; modes full, quick, api, auth, infra, <path>. Required before release; use for 'security audit', 'is this secure', 'OWASP check', 'review the auth code'.

44d agoDiscuss
jLAM-ERRSkill

security-audit

jLAM-ERR/corp-llm-gateway/.claude/skills/security-audit/SKILL.md

Whole-repo leak-surface security audit of corp-llm-gateway against its zero-leak criterion and the 6 CLAUDE.md invariants — sanitizer coverage, NEVER-gate, auth/tokens, placeholder bijection, egress/DLP. Produces CONFIRMED/SUSPECTED findings with file:line + fixes. Use for "security audit", "sec-audit", "find leak paths", "do the invariants still hold". For reviewing a pending diff instead, use the built-in security-review.

43mo agoDiscuss
kelgirechandrakant-cpuSkill

security-audit

kelgirechandrakant-cpu/vibe-coding-playbook/skills/security-audit/SKILL.md

Security audit methodology. OWASP Top 10 + STRIDE threat model with zero-noise false positive filtering. Checks API key exposure, database rules, XSS vectors, CSRF, auth bypass. Use when handling user data or preparing for production.

444d agoDiscuss
KirillTrubitsynSkill

security-audit

KirillTrubitsyn/kirilltrubitsyn-claude-skills/.claude/skills/security-audit/SKILL.md

Комплексный аудит безопасности приложений, API, репозиториев, AI/agent-систем, MCP-интеграций, инфраструктуры и цепочки поставок. Использовать при явном запросе — «аудит безопасности», «security audit», «проверь на уязвимости», «security review», «threat model», «hardening», «проверка перед продакшеном», «prompt injection», «MCP security», — а также при secure-design review или планировании авторизованного пентеста. Не использовать для обычного code review, отладки или рефакторинга без запроса о безопасности.

440d agoDiscuss
saitarrunSkill

security-audit

saitarrun/Devforge-ai/skills/security-audit/SKILL.md

This skill should be used when the user mentions keywords related to security-audit.

43mo agoDiscuss
senoritadeveloper01Skill

spring-security

senoritadeveloper01/claude-skills/.claude/skills/spring-security/SKILL.md

Use this skill when implementing or reviewing security in a Spring Boot application. Covers authentication, authorization, input validation, secure configuration, and API security best practices.

46mo agoDiscuss
Wang200935Skill

security-audit

Wang200935/security-agent-skills/skills/cloud-security/security-audit/SKILL.md

Security audit of a codebase — web apps, APIs, services, CLI tools, libraries,

450d agoDiscuss
xsourabhsharmaSkill

security-audit

xsourabhsharma/ai-security-audit-pro/skills/security-audit/SKILL.md

Defensive web and web-application security auditing for local projects, localhost, staging, and authorized public/private websites. Use when the user asks to audit, scan, review, find vulnerabilities, check OWASP issues, inspect security headers, assess APIs, or produce a security report for a website or web app.

44mo agoDiscuss
thejefflarsonSkill

security-review

thejefflarson/soundcheck/.claude/skills/security-review/SKILL.md

Runs a full OWASP/CWE security audit via isolated subagents. Use when the user

202mo agoDiscuss
AndrewDrygaSkill

security-engineer

AndrewDryga/emisar/.claude/skills/security-engineer/SKILL.md

Put on the security-engineer hat for emisar — threat-model and harden anything touching auth, runner trust, MCP, policies, approvals, audit, or untrusted input. Use when reviewing or building auth/session/MFA, the runner socket, the MCP API, policy evaluation, approval flows, audit logging, secret handling, or any code that ingests runner/LLM input. emisar IS a security product — this hat is mandatory there.

3392mo agoDiscuss
NoorQureshiSkill

ai-mcp-security

NoorQureshi/ronin/skills/ai-ml/ai-mcp-security/SKILL.md

Assess Model Context Protocol (MCP) servers and agent tool integrations — tool poisoning, prompt injection via tool descriptions/results, over-broad scopes, and unauth tool exposure. Load when the target uses MCP servers, agent tool/function integrations, or connectors. Signals: mcp.json, MCP server, tool schemas, connector marketplace, agent with external tools.

1822d agoDiscuss
caiaffaSkill

security-review

caiaffa/claude-code-ultimate-engineering-system/skills/security-review/SKILL.md

Review code, APIs, infrastructure, IAM, secrets, and data handling for practical application and platform security risks.

1717d agoDiscuss
yusupsupriyadiSkill

security-review

yusupsupriyadi/claude-code-mastering/.claude/skills/security-review/SKILL.md

Performs comprehensive security review of code changes. Automatically activates when reviewing authentication, authorization, data handling, input validation, encryption, or when user mentions security audit, vulnerability, or penetration testing. Keywords: security, auth, authentication, authorization, jwt, token, vulnerability, injection, xss, csrf, owasp

178mo agoDiscuss
alexpateSkill

security-page

alexpate/devtool-skills/skills/security-page/SKILL.md

Build a credible security/trust page for a developer tool before SOC 2 — concrete controls, encryption specifics, subprocessor list, responsible disclosure, data lifecycle, and honest scoping of what you can claim. Use when the user wants a security page, trust page, or trust center, asks "do we need SOC 2", got a vendor security questionnaire, or is losing deals to security review. Also use when they mention a DPA, subprocessors, security.txt, responsible disclosure, or "enterprise readiness", even if they never say "security page".

02mo agoDiscuss
BobagiSkill

security-sweep

Bobagi/claude-skills/security-sweep/SKILL.md

Varredura de segurança agnóstica a projeto que ENCONTRA, TESTA ao vivo (adversarialmente) e CORRIGE vulnerabilidades — não só reporta. Cobre race conditions/TOCTOU, IDOR/autorização, enumeração de usuário, injeção (SQL/command), SSRF, upload, XSS, segredos, sessão/auth, crypto, exposição de dados e lógica de negócio, contra uma rubric versionada que cresce a cada uso. Use quando o usuário pedir "varredura de segurança", "faça um pentest", "está seguro?", "audite a segurança", "verifique vulnerabilidades", ou ao final de QUALQUER feature que toque autenticação, dinheiro, permissões, input do usuário, upload ou dados sensíveis.

03mo agoDiscuss
bt2goSkill

security-pass

bt2go/claude-skills/skills/security-pass/SKILL.md

Use when the user wants a security check of a diff, an endpoint, or code handling input, auth or secrets.

02mo agoDiscuss
Shobhit-HalseSkill

security-expo

Shobhit-Halse/skills/skills/security-expo/SKILL.md

Security and crash-prevention skill for React Native and Expo mobile apps. MUST be loaded when the task touches: auth flows, token handling, login/logout, session management, secure storage, API request construction, deep links, push notification handlers, WebViews, input validation, error handling, crash prevention, error boundaries, secrets, environment variables, certificate pinning, TLS configuration, biometric authentication, rate limiting, brute-force protection, dependency auditing, LLM/AI feature integration, or production hardening. Also load when reviewing AI-generated code that touches networking, storage, or auth. This skill exists because mobile clients are untrusted devices and the backend is the only trust boundary — do not skip loading it because the task "looks small". Version 1.1.0.

017d agoDiscuss
Yakoub-aiAGENTS.md

Tech-Skills / security

Yakoub-ai/Tech-Skills/skills/security/AGENTS.md

Coordinates security and compliance - manages Security Architects, Compliance Officers, and Security Hardeners

05mo agoDiscuss
CapristaSkill

security-review

Caprista/KarvyLoop/.claude/skills/security-review/SKILL.md

Dev-time security audit of KarvyLoop's OWN source (twin of /code-review, but for security). Use when asked to "audit the security of these changes", "审这轮改动的安全", "security review this endpoint/diff", or before landing anything that touches the untrusted-input frontier (new API endpoints, URL/file fetch, tool authorization, sandbox, LLM output that reaches a persistent store or the shell). Runs a multi-agent adversarial audit — parallel discovery agents, then ≥3 refutation passes per finding (keep only if ≥2/3 say REAL) — and REPORTS ONLY; it never edits code. Not a KarvyLoop product feature.

163mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.