agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 21Worked for most · soon
FirzusSkill

security-review

Firzus/agent-skills/skills/engineering/security-review/SKILL.md

Perform source-only security audits of codebases, APIs, services, and applications. Use for security questions, focused vulnerability reviews, or explicitly requested full audits.

34d agoDiscuss
gener8vSkill

security-review

gener8v/gener8v.claude-skills/skills/security-review/SKILL.md

OWASP-informed, code-level security review of delivered code: injection, authentication and authorization, data exposure, configuration, dependencies, cryptography and logging, with attack scenarios for Medium+ findings and compliance constraints (CC-XXX) treated as Critical. Use after a delivery, especially one touching input handling, auth, sensitive data or external integrations, such as 'security review TICKET-007' or 'check what this delivery shipped for injection or auth bypass before we merge'. Not for a whole-codebase OWASP posture assessment (owasp-top10-review) or prompt-injection risk in LLM features (owasp-llm-top10-review).

316d agoDiscuss
Kur1sulabSkill

mobile-security

Kur1sulab/blackbox/pt-mobile-security/SKILL.md

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes,

350d agoDiscuss
me-cedricSkill

verify-security

me-cedric/agent-compass/skills/verify-security/SKILL.md

Security verification gate. Scans code for vulnerabilities, detects dangerous patterns, and ensures security decisions are documented. Use when the user mentions security scans, vulnerability detection, security audits, code security, OWASP, injection detection, or sensitive-data leaks. Auto-triggers for new modules, security-related changes, offensive/defensive tasks, and completed refactors.

33mo agoDiscuss
peopleforresterSkill

security-review

peopleforrester/claude-dotfiles/skills/quality/security-review/SKILL.md

Security-focused code audit. Checks OWASP Top 10, secrets exposure, and vulnerability patterns. Invokes the security-reviewer agent.

36mo agoDiscuss
yasserstudioSkill

perfex-security

yasserstudio/perfex-crm-skills/skills/perfex-security/SKILL.md

Use whenever a Perfex CRM task touches security-sensitive code — issuing or consuming single-use tokens (password reset, magic link, confirmation), race-safe atomic UPDATE with `affected_rows()` check, handling user-controlled redirect URLs (`?next=`, `?redirect=`, `?return_to=`), rate-limiting an AJAX endpoint that leaks boolean state, cross-module model loads, logging PII, adding `target="_blank"` links, or excluding a webhook from CSRF. Also trigger when the user says "my magic link works twice", "password reset is racy", "someone can enumerate users by email", "open redirect in my module", "CSRF blocking my webhook", "rate limit this endpoint", or mentions "TOCTOU", "enumeration", `html_purify`, or `app_generate_hash()`. Every rule here exists because its absence caused a real Perfex production incident.

36mo agoDiscuss
EastSwordSkill

security_reporter

EastSword/dfyx_skills_lib/security_reporter/SKILL.md

安全报告编写助手是一款专注于网络安全领域的智能报告生成工具,当用户提出需要针对给出的漏洞信息给出分析报告时,需要基于漏洞编号、名称或安全扫描工具报告,自动生成符合行业标准的漏洞分析报告,包含漏洞背景、漏洞描述、漏洞原理、漏洞利用条件和修复要求等核心内容,帮助安全从业者快速生成标准化、专业的安全报告。

547mo agoDiscuss
354685856-snSkill

security-check

354685856-sn/claude-code-skills/security-check/SKILL.md

安全与合规检查 - 检查代码是否符合安全规范

06mo agoDiscuss
arcobaleno64Skill

security-audit

arcobaleno64/council-forge/.github/skills/security-audit/SKILL.md

Generative vulnerability-discovery harness for an entire codebase, driven by parallel sub-agents and adversarial validation. Unlike the deterministic CI gates (repo_security_scan, regex_safety_audit, prompt_injection_scan) which prevent KNOWN bad patterns from recurring, this skill DISCOVERS unknown, exploitable vulnerabilities through a six-phase pipeline: recon, multi-angle hunting, adversarial validation, reporting, structured findings, and independent verification. Use this skill when asked to run a deep security audit, hunt for exploitable vulnerabilities, perform the quarterly threat-model discovery exercise, or find security bugs that pattern matching misses. Outputs findings.json conforming to report-schema.json and hands confirmed findings into the threat-model staging layer. Trigger on 'security audit', 'vulnerability hunt', 'quarterly threat model exercise', 'find exploitable bugs', or /security-audit.

05mo agoDiscuss
ayman-benmadaSkill

security-audit

ayman-benmada/owasp-security-audit/skills/security-audit/SKILL.md

Review source code, configuration, or architecture against the OWASP Top 10:2025 when the user requests an application security audit, OWASP review, vulnerability assessment, API security review, or security hardening assessment. Also use when asked to investigate access control, injection, authentication, secrets, cryptography, logging, supply chain, or error handling in an application. Produce evidence-backed findings with separate severity and confidence.

07d agoDiscuss
bcmyguestSkill

security-audit

bcmyguest/personal-skills/skills/security-audit/SKILL.md

Ruthlessly audit a codebase for its 1-3 most serious SECURITY vulnerabilities, verify each one adversarially, and report it with a CVE reference (for known-vulnerable dependencies) or a minimal proof-of-concept (for novel bugs). Use whenever the user invokes /security-audit or asks to "security audit this", "find the worst vulnerabilities here", "is this exploitable", "find the scariest security holes", "what's the biggest security risk in this repo", or wants a sharp, high-signal security review that stops at the top few issues rather than an exhaustive checklist. Spins up a small, capped multi-agent workflow of Sonnet agents to hunt attack surface and prove exploitability. For performance/cost problems use efficiency-audit instead.

03mo agoDiscuss
BenLaurensonSkill

security-audit

BenLaurenson/claude-skills/security-audit/SKILL.md

Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

07mo agoDiscuss
blamejsSkill

cloud-security

blamejs/exceptd-skills/skills/cloud-security/skill.md

Cloud security for mid-2026 — CSPM/CWPP/CNAPP posture, CSA CCM v4, AWS/Azure/GCP shared responsibility, cloud workload identity federation, runtime security with eBPF, AI workloads on cloud

046d agoDiscuss
blamejsSkill

mlops-security

blamejs/exceptd-skills/skills/mlops-security/skill.md

MLOps pipeline security for mid-2026 — training data integrity, model registry signing, deployment pipeline provenance, inference serving hardening, drift detection, feedback loop integrity; covers MLflow / Kubeflow / Vertex AI / SageMaker / Azure ML / Hugging Face

046d agoDiscuss
carlokopSkill

security-audit

carlokop/skills/security-audit/SKILL.md

Read-only security audit van React, marketing, Node en de database. Schrijft een rapport naar docs/reports/. Gebruik bij security audit, security-audit, beveiligingsaudit, of een verzoek om IDOR, RBAC, CORS, CSRF, SQL-injectie, RLS of Clerk-auth statisch te reviewen zonder code te wijzigen.

08d agoDiscuss
chinng-intaSkill

security-watch

chinng-inta/portal4agents-plugin/skills/security-watch/SKILL.md

Monitor CVEs and security advisories through the Chinng AI-Agent Portal. Use for incremental vulnerability checks, package watchlists, and actionable security summaries.

040d agoDiscuss
conjure-3301Skill

security_audit

conjure-3301/skills/security_audit/SKILL.md

Security audit of Substrate runtime built in Rust. Scans current dir by default, or a specific PR with --pr. Add --deep for adversarial reasoning.

045d agoDiscuss
conjure-3301Skill

session-security

conjure-3301/skills/session-security/SKILL.md

Session fixation, hijacking, predictable IDs, weak invalidation, JWT pitfalls, 2FA step-up bypass

045d agoDiscuss
conjure-3301Skill

solana-security

conjure-3301/skills/solana-security/SKILL.md

Solana program security covering account validation (signer/owner/key/writable), PDA bump canonicalization, type confusion via missing discriminators, CPI privilege escalation, account closing and revival attacks, Anchor framework constraints, remaining_accounts bypass, arithmetic overflow in release mode, and sysvar spoofing

045d agoDiscuss
Design-of-ManSkill

owasp-security

Design-of-Man/claude-skills/skills/owasp-security/SKILL.md

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, LLM Top 10 (2025), and Agentic AI security (2026).

048d agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.