agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 2Worked for most · soon
flywheel-productSkill

security

flywheel-product/ai-build-skills/security/SKILL.md

Audit a vibe-coded web app's security against a practical checklist — RLS/auth, exposed secrets, signups, storage, IDOR, webhooks, headers, XSS. Tuned for React/Vite + Supabase on Netlify/Vercel/Cloudflare, with adaptations for Firebase and custom Node/Next APIs. Use whenever asked to do a security review/audit, check for vulnerabilities, find exposed secrets/keys, verify RLS or auth, harden an app before launch, or when the user types /security. Supports `/security --fix` (apply safe fixes on a branch) and `/security --grep` (offline CI-friendly scan only).

23mo agoDiscuss
JustinK33Skill

security

JustinK33/foreman/skills/security/SKILL.md

Use when the user asks for a security review, vulnerability scan, security audit, or to check code for security issues, front end or back end. Also trigger on "/foreman:security" or "/security".

28d agoDiscuss
subhansh-devSkill

SECURITY

subhansh-dev/agent-maxxing/SECURITY/SKILL.md

Security Policy ## Reporting a Vulnerability If you discover a security vulnerability in this project, please report it responsibly. Do NOT open a public GitHub issue for security vulnerabilities. Open

23mo agoDiscuss
tomas-uSkill

security

tomas-u/claude-skills/security/SKILL.md

Expert security architect providing comprehensive security guidance, architecture assessments, threat modeling, and compliance verification. Follows OWASP, NIS2, ISO 27001, NIST, and industry best practices. Use for security architecture design and review, threat modeling, security strategy, compliance assessment (OWASP, NIS2, GDPR, PCI DSS, SOC 2), infrastructure security, API security patterns, and incident response planning. For code-level security reviews, use the code-review skill.

29mo agoDiscuss
vikneshwaran16032005-altSkill

security

vikneshwaran16032005-alt/claude-skills/security/SKILL.md

Secure web and desktop application development. Use when writing authentication, authorization, API endpoints, form handling, database queries, file uploads, Electron apps, Tauri apps, IPC handlers, cryptography, secrets management, security headers, input validation, or when reviewing code for vulnerabilities. Covers OWASP Top 10, XSS, CSRF, SQL injection, SSRF, command injection, path traversal, and desktop app security.

24mo agoDiscuss
BappozSkill

security

Bappoz/My-Claude-Skills/skills/engineering/security/SKILL.md

Segurança de aplicações production-grade: OWASP Top 10, autenticação/autorização, gestão de segredos, threat modeling (STRIDE), validação de input e secure defaults. Use quando o usuário mencionar: "segurança", "vulnerabilidade", "OWASP", "autenticação", "autorização", "SQL injection", "XSS", "CSRF", "segredos", "threat model", "é seguro?", "hardening", "pentest". Não auxilia ataques maliciosos — foco em defesa e testes autorizados.

13mo agoDiscuss
ksed8Skill

security

ksed8/cc-loopkit/.claude/skills/security/SKILL.md

Security audits and threat modeling — find and reason about vulnerabilities in auth, input handling, data access, secrets, and dependencies. Use when reviewing code for security, threat-modeling a feature, hardening an endpoint, handling auth/authz, or checking for injection, secret leakage, or unsafe data exposure. For a focused review of the current diff, prefer the `/security-review` command.

13mo agoDiscuss
OpenAISkill

security-scan

openai/codex-security/plugins/codex-security/skills/security-scan/SKILL.md

Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.

11k20d agoDiscuss
withkynamSkill

vc-security

withkynam/vibecode-pro-max-kit/.claude/skills/vc-security/SKILL.md

STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.

1.1k3mo agoDiscuss
bmarshall511Skill

security

bmarshall511/Trellis/.claude/skills/security/SKILL.md

Use when handling user input, authentication, authorisation, secrets, file uploads, or database queries. Also when adding a dependency, exposing an endpoint, or reviewing whether something is safe to ship.

050d agoDiscuss
CarriedWorldUniverseSkill

security

CarriedWorldUniverse/nexus/.agents/skills/security/SKILL.md

Secure-coding rules for nexus + the vulnerability/secret/SAST scan gate run at review and merge.

07d agoDiscuss
danielgefenSkill

security

danielgefen/sous/skills/security/SKILL.md

Adversarial security gate. Reviews the change for vulnerabilities and tries to exploit them against a local environment. A confirmed exploit blocks the merge. Runs after merge-risk, before qa. Usage - /sous:security <change-id>

036d agoDiscuss
Geoffe-GaSkill

security

Geoffe-Ga/well-worn-tools/.claude/skills/security/SKILL.md

Implement secure coding practices against common vulnerabilities. Use when handling user input, file paths, subprocess calls, SQL queries, API keys, or building web endpoints. Covers input validation, injection prevention, secret management, and XSS/CSRF protection across Python, TypeScript, Go, and Rust. Do NOT use for general error handling (use error-handling skill) or for remediating dependency vulnerability scanner failures and CVE / GHSA advisories (use cve-remediation skill).

03mo agoDiscuss
jack1415926Skill

security

jack1415926/claude-skills/skills/security/SKILL.md

Create security architecture diagrams using PlantUML syntax with identity, encryption, firewall, and compliance stencil icons. Best for IAM flows, zero-trust models, encryption pipelines, and threat detection architectures.

048d agoDiscuss
jessedegansSkill

security

jessedegans/jstack/skills/security/SKILL.md

Use when reviewing code for security vulnerabilities, before shipping to production, or when the user asks for a security audit. Runs OWASP Top 10 + STRIDE analysis with a strict false positive filter. Confidence gate at 8/10. No theoretical hand-waving.

06mo agoDiscuss
jorekaiSkill

security

jorekai/skills/skills/security/security/SKILL.md

Choose the next security skill for a new repository, a weekly sweep, or a leaked credential. Explains priorities, safeguards before each fix, and how to measure its result.

023d agoDiscuss
mj-devingSkill

Security

mj-deving/pai-skills/skills/Security/SKILL.md

Security assessment — network recon, web app testing, prompt injection testing, security news, and vulnerability scanning. USE WHEN recon, port scan, subdomain, DNS, WHOIS, pentest, threat model, OWASP, prompt injection, LLM security, security news, trivy, CVE, vulnerability scan, sops, encrypt secrets.

05mo agoDiscuss
ngnthanhdevSkill

security

ngnthanhdev/claude_template_code/.claude/skills/security/SKILL.md

The single security skill — diff/PR audit method with a high-confidence bar (BOLA/IDOR, mass assignment, DTO validation, injection, secrets, rate limiting), STRIDE threat modeling before large features, backend auth hardening (guards, Passport, RBAC, CORS/CSRF, OWASP ASVS), and mobile hardening (MASVS: token storage, deep links, WebView, build config). Load the SKILL.md for routing, then read ONLY the references/ file matching the job.

041d agoDiscuss
ReaperOAKSkill

security

ReaperOAK/ForgeOS/.claude/skills/security/SKILL.md

Security best practices including STRIDE threat modeling, OWASP Top 10, agentic guardrails, and vulnerability assessment guidelines.

04mo agoDiscuss
soreavisSkill

security

soreavis/ai-docent/skills/security/SKILL.md

Multi-session defensive security coach: prompt injection, data leaks, agent safety, and incident response, taught with inert examples. Use only when asked to start or continue this course.

014d agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.