agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 19Worked for most · soon
EyadkellehSkill

security-passwords

Eyadkelleh/awesome-skills-security/skills/security-passwords/SKILL.md

Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).

3844mo agoDiscuss
EyadkellehSkill

security-usernames

Eyadkelleh/awesome-skills-security/skills/security-usernames/SKILL.md

Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.

3844mo agoDiscuss
EyadkellehSkill

security-webshells

Eyadkelleh/awesome-skills-security/skills/security-webshells/SKILL.md

Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.

3844mo agoDiscuss
AymanShamsSkill

security-best-practices

AymanShams/codex-coding-os/.agents/skills/security-best-practices/SKILL.md

Use when the user asks for language-specific or framework-specific security best practices, secure-by-default coding guidance, a security review, secure code report, vulnerability report, or security improvement recommendations for Python, JavaScript, TypeScript, or Go code. Use when writing new code that needs secure defaults, passively checking major security mistakes, or reviewing a repo against available security reference guidance. Do not use for general code review, normal debugging, architecture refactoring, non-security tasks, ownership analysis, incident response, or repository threat modeling. If the primary task is AppSec threat modeling with assets, trust boundaries, attackers, and abuse paths, use security-threat-model. If the primary task is security ownership or bus-factor risk from git history, use security-ownership-map. If the primary task is a broad security scan using the Codex Security plugin, use the relevant codex-security skill.

118d agoDiscuss
FlorianBruniauxSkill

security-guardian

FlorianBruniaux/ccboard/.claude/skills/security-guardian/SKILL.md

name: security-guardian version: 1.0.0description: Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie

945mo agoDiscuss
GoogleSkill

google-cloud-waf-security

google/skills/skills/cloud/google-cloud-waf-security/SKILL.md

Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF). Use this skill to evaluate workloads, identify security requirements, and provide actionable recommendations for IAM, network security, data protection, and operational security.

20k10d agoDiscuss
MicrosoftSkill

fix-security-issues

microsoft/fluentui-react-native/.github/skills/fix-security-issues/SKILL.md

Audit and remediate dependency security advisories while respecting package age policy, removing unused vulnerable capabilities, deduplicating Yarn resolutions, and validating affected tooling.

1.4k4mo agoDiscuss
fmindSkill

security-review

fmind/dotfiles/skills/security-review/SKILL.md

Review and fix code security; scan secrets and vulnerabilities with Gitleaks and Trivy.

511d agoDiscuss
GoogleSkill

gke-platform-security

google/skills/skills/cloud/gke-platform-security/SKILL.md

Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for workload-level security (Workload Identity, SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security instead).

20k10d agoDiscuss
thejefflarsonSkill

graphql-security

thejefflarson/soundcheck/.claude/skills/graphql-security/SKILL.md

Detects GraphQL schemas without depth limits, cost analysis, or introspection

202mo agoDiscuss
thejefflarsonSkill

security-cleanup

thejefflarson/soundcheck/.claude/skills/security-cleanup/SKILL.md

Applies fixes for security findings produced by /security-review. Use when the

202mo agoDiscuss
GoogleMakesMeBetterSkill

security-auditor

GoogleMakesMeBetter/claude-skills-collection/skills/testing/security-auditor/SKILL.md

Use this agent when conducting comprehensive security audits, compliance assessments, or risk evaluations across systems, infrastructure, and processes. Invoke when you need systematic vulnerability analysis, compliance gap identification, or evidence-based security findings. Specifically:\\n\\n<example>\\nContext: An organization requires a comprehensive security audit to validate SOC 2 compliance before their annual certification review.\\nuser: \"We need a complete security audit covering all controls, infrastructure, and processes. Can you assess our current SOC 2 compliance status and identify gaps?\"\\nassistant: \"I'll conduct a systematic security audit examining your controls, configurations, and compliance posture. I'll review your security policies, assess control implementation, identify vulnerabilities and compliance gaps, prioritize findings by risk, and provide a detailed remediation roadmap with timelines.\"\\n<commentary>\\nUse the security-auditor when you need structured, comprehensive security assessments with compliance mapping and risk prioritization. This agent methodically reviews controls, collects evidence, and delivers audit findings.\\n</commentary>\\n</example>\\n\\n<example>\\nContext: A cloud-hosted application needs assessment before going to production to ensure it meets PCI DSS requirements and internal security standards.\\nuser: \"Before launch, we need to audit the application's security posture. Can you check encryption, access controls, data handling, and compliance with PCI DSS?\"\\nassistant: \"I'll perform a detailed security audit of your application covering authentication mechanisms, data protection, access controls, API security, and compliance alignment. I'll identify configuration gaps, test security controls, assess patch management, and recommend specific improvements for PCI DSS compliance.\"\\n<commentary>\\nInvoke security-auditor when you need objective, evidence-based assessment of specific systems or environments before critical milestones like production deployment or compliance certification.\\n</commentary>\\n</example>\\n\\n<example>\\nContext: After a security incident, the organization wants an audit of incident response capabilities and overall security posture to prevent future occurrences.\\nuser: \"We just had a breach. Can you audit our incident response plan, detection capabilities, and overall risk management to identify what failed?\"\\nassistant: \"I'll conduct a post-incident audit examining your IR plan readiness, detection capabilities, response procedures, logging and monitoring, access controls that may have been compromised, and residual risk exposure. I'll classify findings by severity, assess what controls missed the incident, and provide a comprehensive remediation roadmap.\"\\n<commentary>\\nUse security-auditor for systematic post-incident analysis and broader security posture assessment when you need thorough, documented investigation with evidence collection and risk-based recommendations.\\n</commentary>\\n</example>

18mo agoDiscuss
Prorise-coolSkill

security-specialist

Prorise-cool/Claude-Code-Multi-Agent/.claude/skills/security-specialist/SKILL.md

提供安全审计、风险评估和合规检查能力。当需要进行安全审查、风险评估或合规验证时使用。

3049mo agoDiscuss
superagents-labSkill

audit-xcode-security-settings

superagents-lab/xcode27-skills/audit-xcode-security-settings/SKILL.md

Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up security-focused static analysis, enable static analysis, improve warning coverage, harden diagnostics, or catch more bugs at compile time in C/C++/Objective-C/Swift. SKIP: network security (TLS/ATS), code signing, privacy APIs.

3004mo agoDiscuss
rrezartprebrezaSkill

spring-security-jwt

rrezartprebreza/spring-boot-skills/skills/spring-boot-3/spring-security-jwt/SKILL.md

Use when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security. For JWTs issued by Keycloak, Auth0, Okta, Cognito, or another authorization server, use oauth2-resource-server.

29055d agoDiscuss
rrezartprebrezaSkill

spring-security-jwt

rrezartprebreza/spring-boot-skills/skills/spring-boot-4/spring-security-jwt/SKILL.md

Use when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security. For JWTs issued by Keycloak, Auth0, Okta, Cognito, or another authorization server, use oauth2-resource-server.

29055d agoDiscuss
lyonzinSkill

rag-security-first

lyonzin/knowledge-rag/skills/domain/rag-security-first/SKILL.md

For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the local corpus first. Assumes the RAG is loaded with security content (cybersecurity preset, MITRE data, threat reports, runbooks). Prevents wasted external threat-intel calls and grounds recommendations in the team's actual playbooks.

2885mo agoDiscuss
Cogni-AI-OUSkill

security-review

Cogni-AI-OU/cogni-ai-agent-skills/security-review/SKILL.md

Lightweight security review focused on Pull Requests and incremental changes. Uses a diff-centric approach to ensure no new vulnerabilities are introduced. You MUST load this skill when reviewing code changes in a PR.

45mo agoDiscuss
danjdewhurstSkill

hcloud-security

danjdewhurst/hcloud-skills/skills/hcloud-security/SKILL.md

Use when the user needs to manage SSH keys, TLS/SSL certificates (uploaded or managed), resource protection, reverse DNS, or labels across Hetzner Cloud resources.

48mo agoDiscuss
flytohubSkill

security-triage

flytohub/flyto-indexer/skills/security-triage/SKILL.md

Turn a large codebase into a short, ranked reading list of security-relevant code paths worth a human researcher's time, using the flyto-indexer MCP tools. Use when asked to find, prioritize, or triage potential vulnerabilities / taint flows / attack surface in a repository indexed (or indexable) by flyto-indexer — "what should I look at first", "where are the risky paths", "security review this repo". Produces a reading list, never a verdict.

42mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.