agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 22Worked for most · soon
digitaldreamsSkill

security-audit

digitaldreams/tuhin/skills/security-audit/SKILL.md

Security audit of the user's own codebase, two modes. FIND mode: adversary persona hunts every real security hole in scope and writes them to tasks/security_risks_{date}.md. VALIDATE mode: a fresh security-specialist persona verifies each reported finding was real and each implemented fix is correct. Use whenever the user says "security audit", "red team", "find security issues", "security holes", "act as a bad guy", "attack the app", "validate the security fixes", or "verify the security report". Authorization context: the user owns this codebase and is auditing it for defensive hardening.

03mo agoDiscuss
dorian-akhsSkill

solidity-security

dorian-akhs/skills/solidity-security/SKILL.md

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

030d agoDiscuss
gologo13Skill

security-audit

gologo13/agent-skills/skills/security-audit/SKILL.md

Comprehensive security review to identify and fix vulnerabilities in the codebase; keywords: security, review, fix. Use only on explicit request; before execution, review diffs and list impact scope.

08mo agoDiscuss
hallucinautSkill

security-audit

hallucinaut/skills/security-audit/SKILL.md

Perform security assessments, vulnerability scanning, and penetration testing for codebases, APIs, and infrastructure. Use when conducting security reviews, penetration tests, or compliance assessments.

04mo agoDiscuss
Hyp4tiaSkill

security-audit

Hyp4tia/Yummy-Skills/Code Security Skills/SKILL.md

Perform a rigorous, evidence-driven security audit of a codebase, covering web/frontend, backend/API, filesystem and process execution, native/desktop apps and embedded WebViews, cloud infrastructure and secrets, and dependency/supply-chain risk. Runs a standard pass first, then escalates to an adversarial deep-dive on any high-severity or boundary-heavy finding. Use this whenever the user asks for a security audit, security review, pentest-style review, vulnerability assessment, "is this safe to ship," pre-release security check, or wants a prior security fix verified — for any kind of codebase (web app, API/backend, CLI tool, native/desktop app, mobile app, infra/IaC repo), not just one platform. Trigger even if the user just says "check this for vulnerabilities" or "review this PR for security issues.

035d agoDiscuss
imMamdouhaboammarSkill

security-comms

imMamdouhaboammar/cybersecurity-skills/skills/security-comms/SKILL.md

Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales. Covers incident communication, post-mortem narrative, audit-findings-for-stakeholders, risk justification, security spend justification, and customer-facing breach disclosure. Use when the user mentions 'security comms,' 'communicate this finding,' 'explain to my boss,' 'board update,' 'executive summary,' 'incident communication,' 'breach notification,' 'customer disclosure,' 'security memo,' 'post-mortem narrative,' 'risk justification,' 'why this matters to the business,' 'translate this finding,' 'stakeholder update,' or has technical security work that needs to land with a non-security audience.

026d agoDiscuss
jgamaraalvSkill

redis-security

jgamaraalv/delivery-loop/.claude/skills/redis-security/SKILL.md

Redis production hardening — authentication (requirepass/ACL users), TLS, least-privilege ACLs, network restriction (bind, protected-mode, firewall), and disabling dangerous commands. Use when deploying, locking down, or auditing a Redis instance.

03mo agoDiscuss
Jinbae10Skill

security-check

Jinbae10/skills/skills/security-check/SKILL.md

Review code for security vulnerabilities (OWASP-style) with evidence-backed, exploitable findings — no speculative noise. Use when the user asks for a security review, audit, or vulnerability check.

03mo agoDiscuss
kaiohenricunhaSkill

security-audit

kaiohenricunha/dotbabel/skills/security-audit/SKILL.md

Whole-repository security audit with independent verification of every finding, vendored from cloudflare/security-audit-skill. Guidance by default; runs the full six-phase audit (parallel hunters, verifiers that did not hunt, coverage ledger, schema-validated findings.json) only on an explicit audit or pen-test request. Triggers on: "security audit", "audit this codebase", "pen test the code", "full security review", "end-to-end security review", "security audit report".

07d agoDiscuss
karim-bhalwaniSkill

genai-security

karim-bhalwani/agentic-harness/skills/genai-security/SKILL.md

Security auditing for GenAI/LLM applications. Primary focus: OWASP Top 10 for LLMs (2025). Use for LLM-powered applications, RAG pipelines, AI agents, prompt templates, and generative AI integrations. For agentic risks, prompt injection patterns, MITRE ATLAS mappings, threat modeling, or structured red teaming methodology, load specific reference documents - outputs are analysis and findings, not formal penetration test reports. NOT for: general code security (use guardian), building LLM apps (use llm-app-patterns), runtime rules (use security-boundaries), or infrastructure.

03mo agoDiscuss
kompiroSkill

security-alert

kompiro/hane/skills/security-alert/SKILL.md

Dependabot の security alert(GHSA / CVE 起因の脆弱性アラート)をトリアージして 解決するワークフロー。未解決の alert を一括取得し、direct / transitive を判別して 修正方針(PR マージ / 直接 bump / package manager の override)を決め、トラッキング Issue を作成して修正 PR を出し、判断根拠を ADR に記録する。transitive 依存で Dependabot が PR を起票しないケースを主対象にする。 Trigger when the user says: "security alert", "セキュリティアラート", "Dependabot alert", "脆弱性対応", "GHSA", "CVE 対応", "security alert 対応", "handle security alerts", "triage security alerts", "dependabot security", "依存の脆弱性", or similar phrases requesting to process Dependabot security alerts.

05mo agoDiscuss
leaf76Skill

security-audit

leaf76/agent-skills/security-audit/SKILL.md

Audit code for security vulnerabilities using repository-grounded review, attacker thinking, and targeted verification steps. Use before deploying to production, during security reviews, when reviewing PRs with security implications, or after discovering potential vulnerabilities.

045d agoDiscuss
lgzarturoSkill

security-cloud

lgzarturo/codeconductor/.agents/skills/security-cloud/SKILL.md

Harden IAM, storage, keys, and org policies in cloud accounts you administer. Focus on identity, logging, and public-exposure controls.

015d agoDiscuss
lgzarturoSkill

security-recon

lgzarturo/codeconductor/.agents/skills/security-recon/SKILL.md

Map owned assets, attack surface, and inventory for systems the requester is authorized to assess. Use for asset discovery, service catalogs, and exposure reviews — never unauthorized scanning.

015d agoDiscuss
Marco-SatisSkill

security-audit

Marco-Satis/claude-setup/skills/security-audit/SKILL.md

Security-fokussierter Audit — orchestriert security-reviewer-Subagent für SAST (Bandit, Semgrep, detect-secrets), CWE-Mapping, Threat-Reasoning, Secret-Scan, Permission-Audit. Distinkt zu /review (Multi-Achsen) und /full-audit (5 Reviewer parallel). Abgrenzung zu /cso — security-audit = Code-SAST-Wrapper für ein konkretes Repo/Diff ("security audit" dispatcht hierher); /cso = Infrastruktur-/Setup-weiter CSO-Modus (Secrets-Archaeologie, Supply-Chain, CI/CD, daily/monatlich, Trend-Tracking).

047d agoDiscuss
mattpartidaSkill

agent-security

mattpartida/agent-security/skills/agent-security/SKILL.md

Review and harden OpenClaw/Hermes agent security, including tool permissions, elevated access, exec approvals, allowlists, sandboxing, browser and web exposure, prompt-injection risk, model risk, persistence, and personal-vs-shared trust boundaries. Use when the task is primarily about agent or runtime security rather than host firewall or OS hardening.

05mo agoDiscuss
mguttmannSkill

trivy-security

mguttmann/code-audit-suite/skills/trivy-security/SKILL.md

This skill should be used when the user asks to "run Trivy", "scan dependencies", "check for CVEs", "SCA scan", "Schwachstellen prüfen", "Abhängigkeiten prüfen", "scan a container image", "check Dockerfile/IaC", "generate an SBOM", "Lizenz-Scan", or wants to find vulnerable dependencies, misconfigurations, hardcoded secrets and license issues. Runs Trivy in Docker against a directory or image and drives every finding to zero, processed directly in Claude Code (no dashboard).

04mo agoDiscuss
MikkoNumminenSkill

security-audit

MikkoNumminen/claude-skills/skills/security-audit/SKILL.md

Multi-phase security audit + remediation, gated for approval between every phase (never autopilots). Maps the attack surface (auth, authz, input, secrets, data exposure, deps, transport, ops), prioritizes findings, fixes them one at a time with regression tests, then writes AI-first security docs (SECURITY.md, threat model, invariants). Artifacts land under docs/security/; critical findings surface immediately. Use for "security audit", "review for vulnerabilities", "check the attack surface", or "harden this before launch".

03mo agoDiscuss
mqmalagrisSkill

security-audit

mqmalagris/agent-skills/skills/security-audit/SKILL.md

Focused security review of a CHANGE (a diff, a branch, a PR), layered on the wstg-security-testing skill. Finds HIGH-CONFIDENCE, concretely exploitable vulnerabilities the change newly introduces (injection, broken authn/authz, secrets and data exposure, unsafe deserialization, crypto misuse, SSRF) and audits dependencies when a lockfile moved, using the repo's own package manager. Runs as Check 7 of /implementation-review, and standalone when the user says 'review this diff for security', 'is this change safe', 'security-check my PR', 'threat check this branch', or before shipping something that touches auth, user input, secrets, or untrusted data. NOT for whole-codebase or posture audits ('audit this repo', 'is my app secure', 'find every IDOR', 'auditoria de seguranca') — this skill is diff-scoped and its precedents suppress absence-shaped findings, so on a codebase-wide ask it can report clean on a vulnerable repo; route those to /wstg mode 2. Maps findings to WSTG IDs via /wstg, then reports only findings with a concrete exploit path, never theoretical noise.

055d agoDiscuss
Nadav011Skill

owasp-security

Nadav011/apex-skills/skills/owasp-security/SKILL.md

v24.7.0 — Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).

05mo agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.