agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 17Worked for most · soon
mycelium-hqSkill

security-snapshot

mycelium-hq/ai-brain-starter/skills/security-snapshot/SKILL.md

Use when the user says /security-snapshot, /snapshot <domain>, "run a security check on X", "generate a security report for [company]", or wants a security hygiene snapshot or free lead-magnet report on a prospect''s public domain: SSL/TLS grade, HTTP security headers, SPF/DMARC email authentication, server fingerprint leaks. Passive, unauthenticated scans only. NOT for penetration testing, internal infrastructure audits, or application-layer vulnerability assessment.

376mo agoDiscuss
bis-codeSkill

security-review

bis-code/claude-toolkit/.claude/skills/security-review/SKILL.md

Run an OWASP-focused security analysis on code changes.

84mo agoDiscuss
borkwebSkill

review-security

borkweb/skills/skills/core/review-security/SKILL.md

Deep security review of a diff or a specific file, grounded in 20 evidence-based pattern libraries extracted from 400+ real-world bugs in major open-source projects (Linux kernel, OpenSSL, Chromium, Firefox, curl, Go, Rust, Kubernetes, Next.js, etc.). Use when the user says "security review", "security audit", "audit this for vulnerabilities", "threat model this", "check for CVEs", "check for injection/auth/crypto issues", or when a diff touches buffer handling, parsers, authentication, authorization, cryptography, state machines, CI/CD, dependencies, or trust boundaries. Also usable as a reference library — `/review` links here when a diff touches a security-sensitive area.

84mo agoDiscuss
kauffjSkill

review-security

kauffj/agent-config/skills/review-security/SKILL.md

Review changed code for authorization gaps, input validation failures, data exposure, and injection vulnerabilities

833d agoDiscuss
mgiovaniSkill

review-security

mgiovani/cc-arsenal/skills/review-security/SKILL.md

Perform an OWASP Top 10-focused static security review of a PR, commit, or

86d agoDiscuss
StormixSkill

security-review

Stormix/transcripts-mcp/.agents/skills/security-review/SKILL.md

Finds exploitable application security vulnerabilities in code changes. Use for Warden security scans, appsec review, OWASP-style checks, authentication or authorization bugs, injection, XSS, SSRF, path traversal, secrets, unsafe crypto, webhook verification, open redirects, or sensitive data exposure.

825d agoDiscuss
BejeweledMeSkill

security-review

BejeweledMe/codex-pro-agent-skills/skills/security-review/SKILL.md

Assess security claims for a scoped design, application change, release, repository, or OSS dependency. Use for abuse-path review, application-verification evidence, supplier posture, and security findings or release recommendations; ordinary maintainability review belongs to software-engineering.

725d agoDiscuss
rambozSkill

security-review

ramboz/jig/skills/security-review/SKILL.md

Team baseline for security review — a best-effort heuristic security pass over a diff or change-set. Auto-triggers for review this for security, any vulnerabilities here, security pass on this diff, is this code secure, check this for security issues, or security review this. Uses installed scanners when available; installs nothing. Defers to any other installed skill whose description identifies it as handling security review, SAST, or vulnerability analysis, including `adobe-security-*`; prefer it over this slim baseline. Do not use for spec-compliance review (use `/jig:independent-review`), general PR craft (use `/jig:pr-review`), or secret prevention (`jig-secret-scan`).

73mo agoDiscuss
5hirishSkill

security-audit

5hirish/duct/.agents/skills/security-audit/SKILL.md

Run deep local security audits for backend and app changes to catch secrets exposure, DB compromise vectors, and user privacy risks before PRs.

17d agoDiscuss
AlexandruTeodorofSkill

security-audit

AlexandruTeodorof/Alex-Skills/security-audit/SKILL.md

Performs comprehensive OWASP ASVS v5 security audits on any codebase (supersedes OWASP Top 10). ALWAYS invoke when the user asks to: review code for security issues, perform a security audit, find vulnerabilities or security weaknesses, check for security improvements, check for CVEs, do a pentest review, or uses words like "audit", "vulnerabilities", "security review", "security check", "secure code", "harden", or "penetration test". Also invoke for any general "code review" request — security is part of every good code review.

15mo agoDiscuss
alizafarbatiSkill

security-audit

alizafarbati/opencode-agents-mcp/skills/security-audit/SKILL.md

Expert security architect specializing in threat modeling, red teaming, cloud security, zero-trust architecture, and enterprise security assessment.

123d agoDiscuss
AL-JANEFSkill

security-audit

AL-JANEF/janefskills/skills/security/security-audit/SKILL.md

Audit-grade multi-layer security pass: Semgrep SAST, Gitleaks secret scanning, and dependency audit as deterministic ground truth, then specialist review, variant analysis, fix verification, timing review, and an honest coverage verdict naming what was and was not covered. Use for "full security pass", security audit, pre-launch review, or any serious security assessment. Defensive only.

112d agoDiscuss
art12slavikSkill

security-audit

art12slavik/skill-security-audit/SKILL.md

Run a structured security audit of Linux servers and self-hosted stacks, then harden what's found. Covers Ubuntu/Debian hardening (SSH, sudo, firewall, kernel sysctls, systemd isolation, patching), Docker and container escape paths, exposed datastores (Redis, Postgres, Qdrant, MongoDB), secrets handling, and AI agent risks such as webhook authentication, tool permissions, and prompt injection reaching real tool calls. Use whenever the user asks to audit, review, harden, or lock down a server, VPS, container stack, or agent deployment — and for narrower questions that are really audit questions, like "is my Redis exposed", "is this server safe", "чи безпечний мій сервер", "проведи аудит серверів", "закрий вразливості", or "why is this port open" — or when they paste a docker-compose.yml, sshd_config, or firewall ruleset and ask whether it looks right. Prefer this over ad-hoc checking, since it enforces read-only diagnostics, consistent severity ratings, and a repeatable report.

12mo agoDiscuss
cvszSkill

security-tests

cvsz/zomega/skills/security-tests/SKILL.md

zomega Skill 082: security-tests ## Owner `zomega-security` ## Objective Execute `security-tests` as a production engineering operation with traceable evidence. ## Procedure 1. Validate the supplied objective, scope, environment, and constraints

128d agoDiscuss
dawn840705Skill

security-audit

dawn840705/claude-code-studios/skills/security-audit/SKILL.md

Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.

134d agoDiscuss
drafaelSkill

owasp-security

drafael/coding-harness/skills/owasp-security/SKILL.md

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).

15mo agoDiscuss
evgenii-studitskikhSkill

security-audit

evgenii-studitskikh/Claude-Code-SaaS-Studio/.claude/skills/security-audit/SKILL.md

Audit the SaaS codebase (or a diff) against the path-scoped rules and an OWASP-style SaaS checklist: auth/session, RLS/tenant isolation, secrets, input validation, Stripe webhook verification, dependency vulnerabilities. Produces a severity-ranked findings report.

14mo agoDiscuss
farditaSkill

security-audit

fardita/ai-config/skills/security-audit/SKILL.md

Security audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.

142d agoDiscuss
GabrielYMCSkill

security-audit

GabrielYMC/security-audit/SKILL.md

Pre-deployment security audit for web projects, especially vibe-coded ones. Use this skill whenever the user asks to review their project for security issues, wants a vulnerability scan before deploying, mentions 'security check', 'is my app secure', 'check for vulns', or any pre-launch safety concern. Also trigger for 'I built this with AI, is it safe?', 'review before production', or 'check for hardcoded secrets'. Covers secrets, auth, input validation, data protection, infrastructure, headers, and AI/LLM security. Works on any scope: full repo, single module, single file, or code snippet.

17mo agoDiscuss
iabhisekbosepmSkill

security-audit

iabhisekbosepm/claude-god-setup/.claude/skills/security-audit/SKILL.md

Run a full security audit: OWASP Top 10, secrets detection, input validation, auth, dependency vulnerabilities.

16mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.