agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 18Worked for most · soon
jornalistainclusivoSkill

security-audit

jornalistainclusivo/jinc-skills/.agents/skills/security-audit/SKILL.md

Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

15mo agoDiscuss
Kur1sulabSkill

ai-ml-security

Kur1sulab/whitebox/hack-ai-ml-security/SKILL.md

AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

150d agoPipes a download into a shellDiscuss
martialarconSkill

security-check

martialarcon/claude-code-expert/.claude/skills/security-check/SKILL.md

Valida políticas de seguridad del proyecto: no secrets hardcoded, contenedores sin root, dependencias ARM64 compatibles, Dockerfiles seguros. Usar antes de commits, PRs, o después de modificar Dockerfiles/docker-compose.

17mo agoDiscuss
mickzijdelSkill

rails-security

mickzijdel/rails-toolkit/skills/rails-security/SKILL.md

Use when implementing authentication, authorization, or security features in Rails

17d agoDiscuss
mmondoraSkill

owasp-security

mmondora/claude-skills/.claude/skills/owasp-security/SKILL.md

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).

18mo agoDiscuss
morodomiSkill

security-audit

morodomi/dev-crew/skills/security-audit/SKILL.md

セキュリティスキャン+レポート生成を一括実行するオーケストレータ。Task()でsecurity-scan→attack-reportを委譲。「セキュリティ監査」「security audit」「脆弱性診断して」で起動。

115d agoDiscuss
PantessaSkill

security-audit

Pantessa/website/.claude/skills/security-audit/SKILL.md

Run a security review of Yeetful using its own threat model — key custody and autonomous execution, authorization on non-signing surfaces, supply chain, data boundaries, and prompt injection. Use when asked to audit security, review a surface for vulnerabilities, check authorization or key handling, threat-model a new feature, or triage a suspected security issue. Also use before shipping anything that touches keys, sessions, spend policy, delegated execution, or a new MCP integration.

16mo agoDiscuss
SecretJuJuSkill

owasp-security

SecretJuJu/claude-code-setting/skills/owasp-security/SKILL.md

OWASP security best practices for code review, authentication, authorization, input handling, and web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026). Use this skill whenever writing or reviewing code that handles user input, authentication, authorization, session management, cryptography, error handling, or external data. Also use when the user asks about security best practices, wants to implement secure auth flows, or mentions OWASP, security hardening, or vulnerability prevention. Even if the user just says "이거 보안 괜찮아?" or "secure this", this skill should activate to provide the relevant security checklist.

17mo agoDiscuss
techbuzzzSkill

security-audit

techbuzzz/awesome-opencode/skills/security-audit/SKILL.md

Use when auditing code for security vulnerabilities: OWASP Top 10 checks, secret scanning, dependency audits, SQL injection, XSS, CSRF, authentication flaws, insecure deserialization. Works with any stack.

13mo agoDiscuss
ThanasimosSkill

flare-security

Thanasimos/Thanas-flare-builders-toolkit/flare-security/SKILL.md

Security-first checklist for Flare-family contract design, deployment, and audit. Covers both (1) GENERIC EVM security patterns the user must apply by default — Ownable2Step over Ownable, ReentrancyGuardTransient, SafeERC20, CEI, custom errors, no tx.origin, bounded loops, pull-over-push, immutable for constructor values — and (2) FLARE-SPECIFIC overlays that the generic audit skills don't catch: Permit2 chain availability, fee-on-transfer detection, blacklistable stablecoin surface, FTSO redistributor proxy upgradeability, basefee floors on testnets, public RPC log-range caps, EIP-3855 PUSH0 status. Use whenever you're designing or reviewing a contract that will live on Flare/Songbird/Coston2, before EVERY mainnet deploy, and as the gate for the `audit` and `audit-contract` skills' scope. Trigger on: "security review", "audit checklist", "is this safe for Flare", "ownership", "reentrancy", "Permit2 on Songbird", "blacklistable token", "FoT detection", "should I use OZ or transient guard".

15mo agoDiscuss
anbeimeSkill

antinet-security-scan

anbeime/skill/skills/antinet-security-scan/SKILL.md

信息安全分析师与软件开发工程师在搭建文档处理流水线时,当需要拦截违规文件或外部URL,请挂载此技能作为强制前置安检,自动输出 pass/reject 判定与详细合规扫描报告,一键守住零信任安全底线。

7.3k4mo agoDiscuss
OpenAISkill

security-threat-model

openai/skills/skills/.curated/security-threat-model/SKILL.md

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.

27k7mo agoDiscuss
Fandry96Skill

security-auditor

Fandry96/k3-agentic-skills/skills/security-auditor/SKILL.md

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

275mo agoDiscuss
jshsakuraSkill

security-auditor

jshsakura/awesome-opencode-skills/skills/security-auditor/SKILL.md

Use when a task needs focused security review of code, auth flows, secrets handling, input validation, or infrastructure configuration.

273mo agoDiscuss
berntpoppSkill

security-review

berntpopp/genefoundry-router/.claude/skills/security-review/SKILL.md

Use when reviewing genefoundry-router security before deploy, when touching auth/proxy/logging/limits config, or when answering an infosec/DSB question.

63mo agoDiscuss
bestdeejay-designSkill

security-review

bestdeejay-design/agent-skills/skills/security-review/SKILL.md

Security review orchestrator for dependency lockfiles and source: inventory of lockfiles/manifests (npm, pip, cargo, go, gem, maven, gradle, composer), exit-code classifier for 13 security tools (semgrep, bandit, gitleaks, osv-scanner, pip-audit, trufflehog, checkov, trivy, grype, npm audit, cargo audit), JSON normalizer to a unified finding schema, and human-readable reports. Stdlib-only Python helper + workflow for OWASP-aligned security review.

653d agoDiscuss
davidmeirlevySkill

security-review

davidmeirlevy/obvious-skills/skills/security-review/SKILL.md

Do a security review

63mo agoDiscuss
dkpapadopoulosSkill

security-scanner

dkpapadopoulos/auto-claude-skills/skills/security-scanner/SKILL.md

Use when reviewing code changes for security issues — during REVIEW phase or on explicit security, vulnerability, SAST, or secret-scan requests — running a STRIDE threat-model pre-pass, then available Semgrep/Opengrep, Trivy, and Gitleaks scanners with a self-healing fix loop

69d agoDiscuss
MicrosoftSkill

security-analysis

microsoft/haste/.github/skills/security-analysis/SKILL.md

Dependabot and security analysis skill for HASTE. Parse alerts, group related vulnerabilities, apply severity rules, and produce structured reports. Use when: 'Dependabot alert', 'security scan', 'vulnerability triage', 'dependency audit', 'npm audit', 'pip audit', 'CVE analysis'.

10538d agoDiscuss
daemon-blockint-techSkill

certified-information-systems-security-professional

daemon-blockint-tech/Agentic-Enteprises-Skill/certified-information-systems-security-professional/SKILL.md

Guides security leadership aligned with the (ISC)² CISSP CBK—eight domains: Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; IAM; Security Assessment and Testing; Security Operations; Software Development Security. Use for CISSP/CBK exam prep structure (no brain dumps), program design, policy and governance, risk and control selection, audit narratives, and translating CBK to practice. Triggers: CISSP, cissp, CBK, (ISC)², security domains, study plan, security governance, defense in depth. NOT SOC triage (soc-analyst), incident command (incident-responder), pentest (penetration-tester), cloud-only compliance (cloud-compliance-specialist), board strategy without CBK (chief-information-security-officer), control implementation (information-security-engineer), legal advice.

84mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.