agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 8Worked for most · soon
OpenAISkill

deep-security-scan

openai/codex-security/plugins/codex-security/skills/deep-security-scan/SKILL.md

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

11k20d agoDiscuss
OpenAISkill

security-diff-scan

openai/codex-security/plugins/codex-security/skills/security-diff-scan/SKILL.md

Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.

11k20d agoDiscuss
SentrySkill

security-review

getsentry/warden/packages/warden/src/builtin-skills/security-review/SKILL.md

Finds exploitable application security vulnerabilities in code changes. Use for Warden security scans, appsec review, OWASP-style checks, authentication or authorization bugs, injection, XSS, SSRF, path traversal, secrets, unsafe crypto, webhook verification, open redirects, or sensitive data exposure.

4098mo agoDiscuss
1398281322-a11ySkill

api-security

1398281322-a11y/java-backend-guardrails/skills/java-backend-guardrails/api-security/SKILL.md

Use when hardening APIs: HTTPS, HMAC 签名, timestamp+nonce 防重放, CORS, 脱敏, JWT none 算法, 密钥不进 URL. For SQL injection and resource 越权 WHERE, use backend-safe-check.

230d agoDiscuss
alex-voloshin-devSkill

security-scan

alex-voloshin-dev/ai-skills/.agents/skills/security-scan/SKILL.md

Security scan workflow — dependency audit, OWASP checklist, secrets scan, vulnerability report. Applies software-engineer role with security focus. Use standalone or as part of code review.

25mo agoDiscuss
ffsshhttiikkSkill

app-security

ffsshhttiikk/opencode-agents-skills/app-security/SKILL.md

Expert-level knowledge and advanced techniques for App Security

27mo agoDiscuss
INERATESkill

security-law

INERATE/atelier/skills/security-law/SKILL.md

The Atelier Security Law — OWASP-grade defense for every request path (injection, XSS, CSRF, tenant isolation, rate limiting, transport). Load before writing ANY endpoint, form, or data-processing code — not just auth. Auth token/session mechanics live in [[auth-law]]; this is everything else.

29d agoDiscuss
JustineDevsSkill

llm-security

JustineDevs/premortem/.cursor/skills/llm-security/SKILL.md

LLM and AI agent security testing for prompt injection, RAG poisoning, MCP injection, and guardrail evaluation. Authorization required.

24mo agoDiscuss
ronjunevaldozSkill

kmp-security

ronjunevaldoz/kmp-agent-skills/skills/kmp-security/SKILL.md

Mobile app security for Kotlin Multiplatform beyond Android-only R8 obfuscation — certificate/SSL pinning (expect/actual, no cross-platform Ktor support exists natively), root/jailbreak/tamper detection via freeRASP's real KMP variant, encrypted local storage via KSafe, iOS/ Kotlin-Native release-binary symbol stripping, and an OWASP Mobile Top 10 2024 coverage map across this collection. Does NOT cover Android-specific R8/ProGuard obfuscation — that's kmp-proguard-r8's own scope, cross- referenced here rather than duplicated. Does NOT cover secrets-in-source scanning (gitleaks pre-commit) — that's kmp-setup-hooks Option F.

22mo agoDiscuss
Rootx202Skill

api-security

Rootx202/appsec-skills/api-security/SKILL.md

Focused API security auditor for REST, GraphQL, and webhook endpoints in any stack. Use when the user is building or reviewing an API layer, mentions rate limiting, API keys, webhooks, CORS, or specifically wants "API security" checked — as opposed to a full-project audit.

23mo agoDiscuss
seikaikyoSkill

security-scan

seikaikyo/dash-skills/skills/security-scan/SKILL.md

用外部掃描工具對 repo 做相依漏洞、機密外洩、SAST 三層檢查,並把結果對回 OWASP Top 10:2025 分類。適用:面試或對外發布前的作品體檢、接手不熟的 repo、想確認自己的修正經得起獨立工具驗證。不適用:判斷認證邏輯對不對、權限有沒有寫錯這類要讀懂程式意圖的問題,那要人或 agent 讀碼。

29mo agoDiscuss
axisroboSkill

arch-security

axisrobo/ea-harness/.agents/skills/arch-security/SKILL.md

Deep-dive security audit of a technical architecture diagram. Focused exclusively on authentication, authorization, credential protection, network boundaries, and data classification. Does NOT score overall quality — produces a prioritized security finding list. Use after arch-validate when you want a security specialist's deep cut.

136d agoDiscuss
wgpsecSkill

ai-data-security

wgpsec/AboutSecurity/skills/ai-security/ai-data-security/SKILL.md

AI 系统数据安全测试方法论。当需要评估 LLM/AI 系统的数据泄露风险、训练数据安全、 或 RAG/向量库数据完整性时触发。覆盖: System Prompt 泄露(元 Prompt/角色扮演/关键字定位)、 训练数据推导与提取、成员推断攻击、模型反演攻击、RAG 数据投毒、API 信息泄露、 级联幻觉攻击、外部数据源信息泄露。

1.8k4mo agoDiscuss
kousenSkill

security-review

kousen/claude-code-training/skills/security-review/SKILL.md

Read-only security audit of code for SQL injection, XSS, auth/authz flaws, input validation gaps, sensitive data exposure, and insecure cryptography. Surfaces findings without modifying code.

34510mo agoDiscuss
shawnpangSkill

security-review

shawnpang/startup-founder-skills/skills/security-review/SKILL.md

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".

3317mo agoDiscuss
MicrosoftSkill

security-alerts

microsoft/powerplatform-build-tools/.claude/skills/security-alerts/SKILL.md

Fetch all open security alerts from S360/ADO, Dependabot, and npm audit, apply all fixes, verify, commit, and create a PR.

3036mo agoDiscuss
OpenCovenSkill

security-agent

OpenCoven/coven/skills/security-agent/SKILL.md

Comprehensive OpenClaw security assessment, hardening, and monitoring agent. Covers 7 domains — gateway hardening, channel/sender policy, tool/exec policy, credential hygiene, prompt injection defense, host OS hardening, and continuous monitoring. Use when asked to audit security, harden the setup, check for exposed secrets, assess threat model, schedule security monitoring, respond to potential compromise, fix security audit findings, or review OpenClaw config safety. Triggers on phrases like "security audit", "harden my setup", "check my security", "exposed secrets", "am I secure", "security agent", "threat model", "I think I'm compromised", "fix security warnings", "security posture".

562mo agoDiscuss
OpenAISkill

deep-security-scan

openai/plugins/plugins/codex-security/skills/deep-security-scan/SKILL.md

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

6.8k5mo agoDiscuss
naviktSkill

security-owasp

navikt/copilot/skills/security-owasp/SKILL.md

OWASP Top 10:2025 kodenivå-mønstre for Kotlin, Go, Java og Node.js — tilgangskontroll, forsyningskjede, injeksjon og feilhåndtering

5416d agoDiscuss
nahid-sparktalesSkill

agent-security

nahid-sparktales/agent-dispatcher/skills/security/agent-security/SKILL.md

Secure an agent system as a permission surface — what authority each tool call runs under, where the confused deputy sits, which controls are enforced outside the model and which are only prompt text, and how far one bad call reaches. Use when granting an agent tools or credentials, wiring in MCP servers or subagents, reviewing an agent that acted beyond what the requester could have done, or before letting an agent touch a shared or production system. Not for wording the ingestion trust boundary in detail (prompt-injection-defense), not for scoping what an agent is for (agent-design), and it never grants an agent permission it did not already have.

5210d agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.