agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 6Worked for most · soon
n24q02mSkill

security-sweep

n24q02m/better-code-review-graph/skills/security-sweep/SKILL.md

Graph-driven security sweep -- scan for dangerous sinks, then rank each finding by whether an entry point can actually reach it, and triage the rest into suppressions.

696mo agoDiscuss
code-yeongyuSkill

security-research

code-yeongyu/oh-my-openagent/.agents/skills/security-research/SKILL.md

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

70k11d agoDiscuss
hypnguyen1209Skill

cloud-security

hypnguyen1209/offensive-claude/skills/cloud-security/SKILL.md

Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT theft, GCP impersonation chains, Kubernetes/container escape, IaC/CI-CD federation abuse

38210d agoDiscuss
rusel95Skill

ios-security

rusel95/ios-agent-skills/skills/ios-security/SKILL.md

Use for any iOS security question — whether you're asking about a specific vulnerability, checking if a pattern is secure, or running a full audit. Triggers on: Keychain vs UserDefaults decisions, ATS/NSAllowsArbitraryLoads configuration, certificate pinning implementation, WebView security (UIWebView, WKWebView), hardcoded secrets or API keys, jailbreak/tamper detection, biometric authentication, MASVS controls, OWASP mobile security, App Store rejection risks, and compliance requirements (HIPAA, PCI DSS, GDPR). Also use when someone asks 'is this secure?', 'what should I use instead?', or 'how do I fix this?' about any iOS storage, network, or cryptography pattern.

116mo agoDiscuss
vitormiziaraSkill

saas-security

vitormiziara/saas-security/SKILL.md

Comprehensive SaaS security skill covering code auditing, checklist generation, and vulnerability reporting. TRIGGER this skill whenever the user asks to: audit code for security issues, review a codebase for vulnerabilities, generate a security checklist, check for OWASP compliance, review authentication or authorization logic, check for injection risks, race conditions, or insecure configurations, or asks anything related to SaaS security hardening. Also trigger proactively when the user shares code and asks for a review — always include a security perspective using this skill.

116mo agoDiscuss
agammSkill

owasp-security

agamm/claude-code-owasp/.claude/skills/owasp-security/SKILL.md

Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic Applications (2026). Use when reviewing code or a diff for security issues, implementing authentication, authorization, sessions, or cryptography, handling untrusted input, files, or URLs, hardening config, dependencies, or CI, or building LLM and AI agent features.

3686d agoDiscuss
codecharmhqSkill

ai-security

codecharmhq/claude-code-skills/ai-security/SKILL.md

Use when hardening AI-powered features against prompt injection, auditing LLM outputs before production use, or designing AI systems with defense-in-depth against model exploitation

15mo agoDiscuss
ngothanhtungSkill

ck:security

ngothanhtung/claude-code-skills/.claude/skills/ck-security/SKILL.md

STRIDE + OWASP-based security audit with optional red-team persona discovery loop and auto-fix. Scans code for vulnerabilities from multiple attacker perspectives (auth attacker, supply chain, insider, infrastructure), categorizes by severity, and can iteratively fix findings using ck:autoresearch pattern.

142d agoDiscuss
WelluxSkill

ai-security

Wellux/claude-code-deprecated/.claude/skills/ai-security/SKILL.md

LLM and AI agent security: prompt injection, jailbreaks, agent defense, guardrails. Invoke for: "prompt injection", "LLM security", "agent security", "jailbreak defense", "AI safety audit", "system prompt leakage", "adversarial inputs", "AI pipeline security", "tool call validation", "LLM guardrails", "model security", "is my prompt safe".

16mo agoDiscuss
EvilFreelancerSkill

iac-security

EvilFreelancer/secs/.agents/skills/iac-security/SKILL.md

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego).

1053d agoDiscuss
techforum-repoSkill

aem-security

techforum-repo/aem-claude-code/.claude/skills/aem-security/SKILL.md

AEM security review — admin resolver, query injection, path validation, exposed endpoints, hardcoded secrets

97mo agoDiscuss
codeaholicguySkill

security-review

codeaholicguy/ai-devkit/skills/security-review/SKILL.md

AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.

1.6k16d agoDiscuss
nahid-sparktalesSkill

auth-security

nahid-sparktales/agent-dispatcher/skills/security/auth-security/SKILL.md

Attack and harden an existing auth surface — session fixation and rotation, token verification, horizontal and vertical privilege escalation, password reset and account recovery, MFA bypass. Use when reviewing login, session, token, reset, invite, impersonation or role-elevation code, when someone reports seeing another user's data or an account takeover, or when auth changes are about to ship. Not for designing the login mechanism or permission model in the first place (authentication, authorization), not for infrastructure IAM, and never run against a system you have not been told you may test.

5210d agoDiscuss
vince-winkintelSkill

glab-security

vince-winkintel/gitlab-cli-skills/glab-security/SKILL.md

Configure GitLab project security scan profiles with glab. Use when enabling, disabling, or checking GitLab security scan profiles such as SAST, dependency scanning, secret detection, container scanning, or dependency-scanning auto-remediation. Triggers on GitLab security config, security scan profile, enable SAST, dependency scanning, secret detection, glab security.

4815d agoDiscuss
zhaoxuya520Skill

database-security

zhaoxuya520/reverse-skill/skills/database-security/SKILL.md

Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.

38k9d agoDiscuss
zhaoxuya520Skill

hardware-security

zhaoxuya520/reverse-skill/skills/hardware-security/SKILL.md

Use for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support.

38k9d agoDiscuss
KimYx0207Skill

code-security

KimYx0207/SkillSemgrep/SKILL.md

Runs Semgrep security scans on the current project to detect vulnerabilities, secrets leakage, and OWASP Top 10 issues. Use when the user asks for security scanning, vulnerability detection, code auditing, secrets checking, or says things like 安全扫描, 代码扫描, 扫漏洞, 安全检查, 漏洞检测, 扫一下安全.

377mo agoDiscuss
altafinoSkill

kit-security

altafino/FableClaudeMDForOpus/.claude/skills/kit-security/SKILL.md

Security guardrails pack — injection, secrets, path traversal, auth defaults, deserialization, untrusted-content discipline. Use when asked for a security pass or when code touches user input, secrets, or auth.

63mo agoDiscuss
redpanda-dataSkill

rpk-security

redpanda-data/skills/skills/rpk-security/SKILL.md

Manage Redpanda authentication and authorization from the CLI using the `rpk security` command group (`user`, `acl`, `role`, `secret` subcommands; `rpk acl` is a deprecated alias). Use when creating or deleting SASL/SCRAM users, granting or revoking Kafka ACLs on topics, groups, the cluster, or transactional IDs, creating or assigning RBAC roles (Enterprise), managing secrets for Redpanda Cloud clusters, or configuring SASL/PLAIN, OAUTHBEARER/OIDC, GSSAPI/Kerberos, or mTLS principal mapping. Also covers Enterprise security config keys like Audit Logging, GBAC, Schema ID Validation, and FIPS mode, plus bootstrapping a new cluster with a superuser. For Schema Registry-specific ACL patterns, see /redpanda:rpk-registry; for the Enterprise license itself, see /redpanda:rpk-cluster.

657d agoDiscuss
sergeyklaySkill

scan-security

sergeyklay/.agents/.agents/skills/scan-security/SKILL.md

Run a Snyk SAST + SCA security audit on the repository, remediate findings that pass the project's verification gates, and write a prioritized report to .audit/. Optional scope argument: all (default), code, deps, or changed.

65d agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.