agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 15Worked for most · soon
GoldenWing-360Skill

nextjs-security

GoldenWing-360/claude-security-skills/nextjs-security/SKILL.md

Find Next.js-specific security issues across App Router, Pages Router, and Server Actions. Covers the middleware-bypass class, NEXT_PUBLIC environment leakage, RSC over-fetch, CSP for App Router, open redirects, and next/image SSRF via permissive remotePatterns. Invoke when reviewing a Next.js app before launch, after a major version upgrade, or when adding authenticated routes.

165mo agoDiscuss
usk6666Skill

security-review

usk6666/yorishiro-proxy/.claude/skills/security-review/SKILL.md

Perform TLS / network / Go-specific security reviews

1617d agoDiscuss
dinsteinSkill

security-audit

dinstein/agent-hub/.agents/skills/security-audit/SKILL.md

Run AgentHub's security sweep with parallel finders, adversarial verification, adjudication, and a report before fixes. Use for a whole-repository audit or a security review of a named path or theme.

343d agoDiscuss
Imran-mlSkill

security-audit

Imran-ml/claude-skills/.claude/skills/security-audit/SKILL.md

Use this skill to perform a security audit, scan for vulnerabilities, check OWASP Top 10 issues, or review code for security problems. Triggered by "security audit", "check security", "find vulnerabilities".

37mo agoDiscuss
wchen02Skill

security-audit

wchen02/cursor-agent-learning/.cursor/skills/security-audit/SKILL.md

Run a security audit (dependencies, secrets, auth, inputs). Use when the user asks for a security review, dependency audit, or to check for vulnerabilities and hardcoded secrets.

37mo agoDiscuss
AWSSkill

remediating-with-aws-security-agent

aws/agent-toolkit-for-aws/plugins/aws-agents-for-devsecops/skills/remediating-with-aws-security-agent/SKILL.md

Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. Use this whenever the user mentions Security Agent, security findings, pentest or penetration test results, code review findings, vulnerabilities found in their AWS account, "what did the security scan find", remediating or triaging security risks, or wants to start fixing reported vulnerabilities — even if they don't name the service explicitly. Trigger it for phrases like "get my security findings", "what vulnerabilities do we have", "let's fix the pentest results", or "triage the security report". The skill discovers scans, exports findings to a gitignored local directory (so sensitive exploit detail is never committed), produces a prioritized triage summary, and offers to start fixing the highest-risk issues.

2.7k4mo agoDiscuss
ruvnetSkill

agent-security-manager

ruvnet/ruflo/.agents/skills/agent-security-manager/SKILL.md

Agent skill for security-manager - invoke with $agent-security-manager

73k21d agoDiscuss
raphaeltmSkill

security-auditor

raphaeltm/simple-agent-manager/.agents/skills/security-auditor/SKILL.md

Security review specialist for credential safety, OWASP vulnerabilities, JWT validation, and WebSocket security. Use proactively after implementing auth, encryption, credential handling, or workspace access code. Invoke before PRs touching security-sensitive files.

594d agoDiscuss
tody-agentSkill

cm-security-gate

tody-agent/codymaster/.agents/skills/cm-security-gate/SKILL.md

[Deprecated] deploy safety merged. Use `cm-safe-deploy` instead.

525mo agoDiscuss
AhlutSkill

security-check

Ahlut/batuta/skills/security-check/SKILL.md

Security analysis of recent changes — a forked, read-only review of the git diff of the modified area. Use after implementing in the SECURITY, DATA-MIGRATION, SCHEMA or FEATURE tiers, before the commit.

210d agoDiscuss
ai4brands-designSkill

solidity-security

ai4brands-design/claude-skills/solidity-security/SKILL.md

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

26mo agoDiscuss
BigPapiCBSkill

security-audit

BigPapiCB/Universal-Claude-Skills/security-audit/SKILL.md

Security audit with OWASP top 10 checklist, dependency scanning, secrets detection, input validation, and injection prevention. Use when auditing code security, reviewing auth implementations, handling user input, or hardening applications.

28mo agoDiscuss
Citadel-Cloud-ManagementSkill

security-audit

Citadel-Cloud-Management/citadel-saas-factory/.claude/skills/security-audit/SKILL.md

Security audit for code and infrastructure. Auto-invoked on security-related keywords.

23mo agoDiscuss
ffsshhttiikkSkill

cloud-security

ffsshhttiikk/opencode-agents-skills/cloud-security/SKILL.md

Cloud security best practices and implementation

27mo agoDiscuss
gmanch94Skill

security-audit

gmanch94/claude-code-aidlc-template/.claude/skills/security-audit/SKILL.md

Deep security audit of the current codebase from a hacker/researcher perspective. Spawns a general-purpose agent with a deterministic prompt that enumerates RLS gaps, IDOR, privilege escalation, input validation bypasses, SSRF, auth bypass, and stack-specific attack surfaces. Returns CRITICAL→LOW findings with file+line citations and remediation hints. Use BEFORE multi-PR sprints touching DB/auth, BEFORE production deploy, and AFTER major feature sweeps. Optionally pass a stack hint as $1 (e.g., "supabase", "firebase", "hasura", "express").

23mo agoDiscuss
is-boSkill

forge-security

is-bo/fullstack-forge-skill/.agents/skills/forge-security/SKILL.md

Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases.

233d agoDiscuss
is-boSkill

forge-security

is-bo/fullstack-forge-skill/skills/forge-security/SKILL.md

Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases.

233d agoDiscuss
jessefmooreSkill

cloud-security

jessefmoore/offensive-claude-code/skills/cloud-security/SKILL.md

Cloud penetration testing — AWS/Azure/GCP privilege escalation, container escape, Kubernetes attacks, serverless exploitation, IaC misconfigurations

24mo agoDiscuss
JustineDevsSkill

ai-ml-security

JustineDevs/premortem/.agents/skills/ai-ml-security/SKILL.md

AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

24mo agoPipes a download into a shellDiscuss
lucianomilaniSkill

security-audit

lucianomilani/AI-ditoria/skills/security-audit/SKILL.md

Audits any codebase for the 13 fixed security/RGPD-compliance categories (tenant isolation & injection, UI-only permission checks, IDOR, hardcoded secrets, XSS, auth/session handling & crypto misuse, SSRF, CSRF/path/upload/concurrency integrity, rate limiting & resource exhaustion, dependency/IaC/supply-chain hygiene, information disclosure, RGPD compliance, malicious code/backdoors), stack-agnostic — detects the target's language/framework/ORM/auth/frontend/deploy setup first, then maps each category to it. Writes a findings.json and updates the shared Audit Report Studio dashboard. Trigger: /security-audit.

217d agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.