agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 20Worked for most · soon
genfeedaiSkill

security-expert

genfeedai/genfeed.ai/.agents/skills/security-expert/SKILL.md

Expert in application security, OWASP Top 10, authentication, authorization, data protection, and security best practices for React, Next.js, and NestJS applications. Use when implementing authentication or authorization, reviewing code for vulnerabilities, handling sensitive data, or implementing encryption or hashing.

419d agoDiscuss
synthaicodeSkill

security_review

synthaicode/XRefKit/skills/security_review/SKILL.md

Skill: security_review ## Purpose Execute `CAP-QA-007` and review C# code and evidence for security risks. ## Required Capability Definitions (XID) ## Required Knowledge (XID) - [C# quality review criteria](../../knowledge/quality/100_csharp_quality_review_criteria.md

44mo agoDiscuss
Wang200935Skill

ai-mcp-security

Wang200935/security-agent-skills/skills/cloud-security/ai-mcp-security/SKILL.md

AI 与 MCP 安全评估 — Prompt 注入、工具滥用、MCP 信任边界、Agent 权限逃逸、数据泄露、模型风险、GAARM 风险矩阵。Use

451d agoDiscuss
loulanyueSkill

springboot-security

loulanyue/awesome-claude-notes/skills/springboot-security/SKILL.md

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

2726mo agoDiscuss
awarexoneSkill

ai-agent-security

awarexone/AXguard/ai-agent-security/SKILL.md

Review AI agents with tools — shell, HTTP, files, browsers — for excessive agency, unsafe exec of model output, and missing human gates (CWE-78 / CWE-94).

1716d agoDiscuss
awarexoneSkill

axguard-security

awarexone/AXguard/axguard-security/SKILL.md

Analyze code for security vulnerabilities, investigate findings, verify fixes, and assess security risk before deployment. Use when reviewing security-sensitive changes, before ship/deploy, or when an agent should call AXGuard MCP instead of inventing its own scanner.

1716d agoDiscuss
awarexoneSkill

graphql-security

awarexone/AXguard/graphql-security/SKILL.md

Analyze GraphQL API security — use when reviewing schemas, resolvers, introspection, batching, authorization per field, or CSRF on cookie-authenticated GraphQL endpoints (API1/API5/API8:2023).

1716d agoDiscuss
cofinSkill

security-auditor

cofin/flow/skills/security-auditor/SKILL.md

Use when reviewing authentication, authorization, user input, secrets, API keys, database queries, file uploads, session management, external API calls, OWASP risks, or data handling attack surface.

175d agoDiscuss
d-padmanabhanSkill

security-testing

d-padmanabhan/agent-engineering-handbook/skills/security-testing/SKILL.md

Security best practices (OWASP Top 10) and testing strategies for software development. Covers secure coding, vulnerability prevention, testing pyramid, API design, and observability patterns. Use when reviewing code for security, writing tests, designing APIs, or when asking about security vulnerabilities, testing strategies, logging, or monitoring.

1713d agoDiscuss
MicrosoftSkill

supply-chain-security

microsoft/apm/.agents/skills/supply-chain-security/SKILL.md

Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.

3.9k15d agoDiscuss
MicrosoftSkill

supply-chain-security

microsoft/apm/.apm/skills/supply-chain-security/SKILL.md

Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.

3.9k15d agoDiscuss
SentrySkill

gha-security-review

getsentry/skills/skills/gha-security-review/SKILL.md

GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.

1k2mo agoDiscuss
GoldenWing-360Skill

android-security

GoldenWing-360/claude-security-skills/android-security/SKILL.md

Harden Android apps against the platform-specific failure modes. Covers Android Keystore and StrongBox, encrypted local storage, network security config and certificate pinning, WebView hardening, exported components and intent hijacking, backup rules, and Play Integrity with root detection as a signal. Invoke when shipping an Android app that holds credentials or tokens, before Play Store submission, or after a mobile security advisory.

165mo agoDiscuss
GoldenWing-360Skill

llm-app-security

GoldenWing-360/claude-security-skills/llm-app-security/SKILL.md

Apply operational controls to applications built on the Anthropic API or similar LLM SDKs. Maps the OWASP LLM Top 10 to practical controls, plus rate limiting, cost caps, PII scrubbing, audit logging, model-version pinning, and an AI-incident response playbook. Invoke when shipping an LLM feature to production, when handling an abuse complaint, or after a model-provider advisory.

165mo agoDiscuss
harperaaSkill

security-prompts

harperaa/secure-claude-skills/security-prompts/SKILL.md

Library of battle-tested security prompt templates for secure feature implementation. Use when implementing forms, endpoints, authentication, authorization, file uploads, or conducting security reviews. Triggers include "security prompt", "secure form", "RBAC", "threat model", "STRIDE", "admin endpoint", "file upload", "security testing", "code review", "OWASP".

1611mo agoDiscuss
Vinix24Skill

security-engineer

Vinix24/vnx-orchestration/.claude/skills/security-engineer/SKILL.md

SEOcrawler security vulnerability scanner and hardening specialist covering code analysis, dependency audits, and infrastructure review.

614d agoDiscuss
Vinix24Skill

security-engineer

Vinix24/vnx-orchestration/skills/security-engineer/SKILL.md

SEOcrawler security vulnerability scanner and hardening specialist covering code analysis, dependency audits, and infrastructure review.

614d agoDiscuss
delorenjSkill

security-monitor

delorenj/skills/security-monitor/SKILL.md

Real-time security monitoring for Clawdbot. Detects intrusions, unusual API calls, credential usage patterns, and alerts on breaches.

1511d agoDiscuss
Google CloudSkill

persona-security

GoogleCloudPlatform/cicd-foundation/skills/persona-security/SKILL.md

Adopts the Security Expert (SEC) persona. Focuses on system hardening, vulnerability auditing, and the protection of sensitive credentials and data.

1523d agoDiscuss
bhaumikmaanSkill

security-review

bhaumikmaan/claude-code-master-skills/skills/security-review/SKILL.md

Security analysis for code changes and requests. Classifies activities as permitted, forbidden, or requiring authorization context. Covers OWASP risks, boundary validation, and dual-use tool guidance. Use when reviewing code for security, handling security-related requests, performing threat modeling, or when asked to assess security posture.

36mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.