agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 8Worked for most · soon
SentrySkill

security-review

getsentry/sentry-python/.agents/skills/security-review/SKILL.md

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

2.2k7mo agoDiscuss
rtk-aiSkill

security-guardian

rtk-ai/rtk/.claude/skills/security-guardian/SKILL.md

CLI security expert for RTK - command injection, shell escaping, hook security

82k8d agoDeletes or force-pushesDiscuss
bybren-llcSkill

security-audit

bybren-llc/safe-agentic-workflow/.agents/skills/security-audit/SKILL.md

RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes for auth, scanning for vulnerabilities, reviewing for exposed credentials, or performing pre-deployment security review. Do NOT use for routine feature development.

4052mo agoReads credentialsDiscuss
bybren-llcSkill

security-audit

bybren-llc/safe-agentic-workflow/.claude/skills/security-audit/SKILL.md

RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes, or scanning for security issues.

4052mo agoReads credentialsDiscuss
n24q02mSkill

security-sweep

n24q02m/better-code-review-graph/skills/security-sweep/SKILL.md

Graph-driven security sweep -- scan for dangerous sinks, then rank each finding by whether an entry point can actually reach it, and triage the rest into suppressions.

696mo agoDiscuss
code-yeongyuSkill

security-research

code-yeongyu/oh-my-openagent/.agents/skills/security-research/SKILL.md

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

70k11d agoDiscuss
hypnguyen1209Skill

cloud-security

hypnguyen1209/offensive-claude/skills/cloud-security/SKILL.md

Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT theft, GCP impersonation chains, Kubernetes/container escape, IaC/CI-CD federation abuse

38210d agoDiscuss
rusel95Skill

ios-security

rusel95/ios-agent-skills/skills/ios-security/SKILL.md

Use for any iOS security question — whether you're asking about a specific vulnerability, checking if a pattern is secure, or running a full audit. Triggers on: Keychain vs UserDefaults decisions, ATS/NSAllowsArbitraryLoads configuration, certificate pinning implementation, WebView security (UIWebView, WKWebView), hardcoded secrets or API keys, jailbreak/tamper detection, biometric authentication, MASVS controls, OWASP mobile security, App Store rejection risks, and compliance requirements (HIPAA, PCI DSS, GDPR). Also use when someone asks 'is this secure?', 'what should I use instead?', or 'how do I fix this?' about any iOS storage, network, or cryptography pattern.

116mo agoDiscuss
vitormiziaraSkill

saas-security

vitormiziara/saas-security/SKILL.md

Comprehensive SaaS security skill covering code auditing, checklist generation, and vulnerability reporting. TRIGGER this skill whenever the user asks to: audit code for security issues, review a codebase for vulnerabilities, generate a security checklist, check for OWASP compliance, review authentication or authorization logic, check for injection risks, race conditions, or insecure configurations, or asks anything related to SaaS security hardening. Also trigger proactively when the user shares code and asks for a review — always include a security perspective using this skill.

116mo agoDiscuss
agammSkill

owasp-security

agamm/claude-code-owasp/.claude/skills/owasp-security/SKILL.md

Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic Applications (2026). Use when reviewing code or a diff for security issues, implementing authentication, authorization, sessions, or cryptography, handling untrusted input, files, or URLs, hardening config, dependencies, or CI, or building LLM and AI agent features.

3686d agoDiscuss
codecharmhqSkill

ai-security

codecharmhq/claude-code-skills/ai-security/SKILL.md

Use when hardening AI-powered features against prompt injection, auditing LLM outputs before production use, or designing AI systems with defense-in-depth against model exploitation

15mo agoDiscuss
ngothanhtungSkill

ck:security

ngothanhtung/claude-code-skills/.claude/skills/ck-security/SKILL.md

STRIDE + OWASP-based security audit with optional red-team persona discovery loop and auto-fix. Scans code for vulnerabilities from multiple attacker perspectives (auth attacker, supply chain, insider, infrastructure), categorizes by severity, and can iteratively fix findings using ck:autoresearch pattern.

142d agoDiscuss
WelluxSkill

ai-security

Wellux/claude-code-deprecated/.claude/skills/ai-security/SKILL.md

LLM and AI agent security: prompt injection, jailbreaks, agent defense, guardrails. Invoke for: "prompt injection", "LLM security", "agent security", "jailbreak defense", "AI safety audit", "system prompt leakage", "adversarial inputs", "AI pipeline security", "tool call validation", "LLM guardrails", "model security", "is my prompt safe".

16mo agoDiscuss
EvilFreelancerSkill

iac-security

EvilFreelancer/secs/.agents/skills/iac-security/SKILL.md

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego).

1053d agoDiscuss
xu-xiangSkill

security-review

xu-xiang/everything-claude-code-zh/.agents/skills/security-review/SKILL.md

当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

1.9k7mo agoReads credentialsDiscuss
techforum-repoSkill

aem-security

techforum-repo/aem-claude-code/.claude/skills/aem-security/SKILL.md

AEM security review — admin resolver, query injection, path validation, exposed endpoints, hardcoded secrets

97mo agoDiscuss
codeaholicguySkill

security-review

codeaholicguy/ai-devkit/skills/security-review/SKILL.md

AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.

1.6k16d agoDiscuss
nahid-sparktalesSkill

auth-security

nahid-sparktales/agent-dispatcher/skills/security/auth-security/SKILL.md

Attack and harden an existing auth surface — session fixation and rotation, token verification, horizontal and vertical privilege escalation, password reset and account recovery, MFA bypass. Use when reviewing login, session, token, reset, invite, impersonation or role-elevation code, when someone reports seeing another user's data or an account takeover, or when auth changes are about to ship. Not for designing the login mechanism or permission model in the first place (authentication, authorization), not for infrastructure IAM, and never run against a system you have not been told you may test.

5210d agoDiscuss
jdanigoSkill

security-scan

jdanigo/hydraia/skills/security-scan/SKILL.md

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

819d agoReads credentialsDiscuss
ShaheerKhawajaSkill

security-scan

ShaheerKhawaja/ProductionOS/.claude/skills/security-scan/SKILL.md

ProductionOS security scanner. Auto-activates when editing auth, payment, credential, or admin files. Runs OWASP Top 10 checks, dependency audit, and secret detection.

86mo agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.