agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matches · from page 9Worked for most · soon
danielvm-gitSkill

security-review

danielvm-git/bigpowers/skills/security-review/SKILL.md

AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. Use when reviewing pending changes, before release-branch, during verify-work Phase 5, during build-epic Step 0 threat modeling, or when the user says "security review" or "scan for vulns".

24030d agoDiscuss
cloudsmith-labsSkill

csm-security

cloudsmith-labs/claude-code-skills/skills/csm-security/SKILL.md

Investigate security posture in Cloudsmith — vulnerabilities, quarantine, and audit logs. Use when the user wants to scan an org, repository, or package for CVEs/vulnerabilities, investigate a specific CVE, review or manage quarantined packages, see who changed or deleted something (audit log), review security events, or get a security summary before a release or promotion.

13mo agoDiscuss
HarambeeAISkill

security-scan

HarambeeAI/bayes-ship/skills/security-scan/SKILL.md

Security scanning against OWASP Top 10, secret detection, input validation, auth hardening. Used by the security reviewer during QA phase. Source: everything-claude-code.

16mo agoDiscuss
johnclawsonSkill

security-qbr

johnclawson/claude-skills/security-qbr/SKILL.md

Generate Quarterly Business Review (QBR) presentations for Information Security teams. Use this skill when creating QBR decks, quarterly security reviews, or executive briefings about security posture for CIO/CTO audiences. Covers content structure (risks, accomplishments, current work, KPIs), writing style, and slide organization. Triggers on requests for security QBRs, quarterly InfoSec reviews, CISO presentations, or security executive briefings.

17mo agoDiscuss
maridlabsaiSkill

security-scan

maridlabsai/jini/.claude/skills/security-scan/skill.md

Security Scan Use this skill for public Jini security review. ## Procedure 1. Scan changed files for secrets, credentials, private URLs, customer details, pricing strategy, and commercial rollout material

14mo agoDiscuss
morodomiSkill

security-scan

morodomi/dev-crew/skills/security-scan/SKILL.md

セキュリティスキャンを実行。RECON→SCAN→REPORT→LEARNワークフローで脆弱性を検出。「セキュリティスキャン」「security scan」「脆弱性チェック」「セキュリティ診断」「OWASPチェック」で起動。Do NOT use for レポートのみ(→ attack-report)やスキャン+レポート一括(→ security-audit)。

115d agoDiscuss
NemesLaszloSkill

security-scan

NemesLaszlo/Agent-Collection/.claude/skills/security-scan/SKILL.md

Security vulnerability scan using the Security Vulnerability Scanner agent workflow. Use when the user says security scan, check for vulnerabilities, security audit, is this secure, OWASP check, or before deploying to production.

16mo agoDiscuss
novatsinghSkill

security-scan

novatsingh/agentkick/.claude/skills/security-scan/SKILL.md

security scan workflow for disciplined AI coding agents.

15mo agoDiscuss
shivae372Skill

security-scan

shivae372/claude-bootstrap/.claude/skills/security-scan/SKILL.md

Security audit skill. Invoke before deploying, after adding auth code, or when reviewing for vulnerabilities. Auto-activates on "security check", "check for vulnerabilities", "pre-deploy audit", "scan for secrets", "is this auth secure". Routes to security-scanner sub-agent.

16mo agoDiscuss
ZeroTokenClawSkill

security-scan

ZeroTokenClaw/agents-skills/security-scan/SKILL.md

对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。

110d agoDiscuss
zhao-wuyanSkill

security-audit

zhao-wuyan/ccw-command-explorer/.claude/skills/security-audit/SKILL.md

OWASP Top 10 and STRIDE security auditing with supply chain analysis. Triggers on "security audit", "security scan", "cso".

455mo agoDiscuss
kklimukSkill

security-review

kklimuk/docx-cli/.claude/skills/security-review/SKILL.md

Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.

2143mo agoDiscuss
netresearchSkill

security-audit

netresearch/security-audit-skill/skills/security-audit/SKILL.md

Use when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.

438d agoDiscuss
daemon-blockint-techSkill

code-security

daemon-blockint-tech/Agentic-Enteprises-Skill/code-security/SKILL.md

Guides secure coding and security-focused code review across languages and infrastructure—OWASP-oriented vulnerability patterns (injection, XSS, auth, crypto, deserialization, SSRF, XXE), secrets handling, and IaC security (Terraform, Kubernetes, Docker, GitHub Actions). Use when writing or reviewing code that handles user input, authentication, files, databases, network requests, cryptography, or infrastructure config—or when the user asks to check for SQL injection, XSS, SSRF, hardcoded secrets, OWASP issues, Terraform security, or GitHub Actions security. Not for authorized penetration test engagements (ai-redteam, cybersecurity), compliance program mapping (compliance-engineer), YARA/malware rules (yara-rule-authoring), or CI pipeline setup only (devsecops).

84mo agoDiscuss
cyber-sortedSkill

cybersorted

cyber-sorted/skills-pro/cybersorted/SKILL.md

Security and enterprise architecture advisory skill. Use this skill when the user needs help with cybersecurity strategy, threat modeling, risk assessment, compliance, security architecture, enterprise architecture, or governance. Trigger when the user mentions: security posture, threat model, STRIDE, PASTA, risk assessment, risk register, compliance mapping, SOC2, ISO 27001, NIST 800-53, CIS benchmarks, MITRE ATT&CK, zero trust, incident response, IR plan, security policy, architecture decision record, ADR, vendor risk, third-party risk, board briefing, security maturity, maturity assessment, gap analysis, security review, code review for security, IaC review, Terraform security, Kubernetes security, CI/CD security, API security, cloud configuration review, tabletop exercise, red team, blue team, penetration test planning, security architecture, network segmentation, defense in depth, least privilege, data classification, encryption strategy, key management, identity and access management, IAM, SIEM, SOC, vulnerability management, patch management, business continuity, disaster recovery, BCP, DRP, privacy by design, GDPR, CCPA, data protection, platform security, build vs buy security, DevSecOps, shift left security, supply chain security, SBOM, secure coding, secure by design, OWASP Top 10, OWASP ASVS, OWASP SAMM, input validation, output encoding, SQL injection prevention, XSS prevention, CSRF prevention, secrets management, dependency security, SAST, DAST, SCA, secure API design, penetration test, pentest, pen test, red team, offensive security, vulnerability assessment, exploit, Kerberoasting, Active Directory attack, privilege escalation, lateral movement, CVSS, CSTM, Cyber Scheme, web application testing, network penetration test, cloud penetration test, container security testing, physical security assessment, or any security and architecture advisory request. Supports roles: CISO, CTO, CPO, Security Architect, Security Engineer, Enterprise Architect, Secure Developer, Penetration Tester.

37mo agoDiscuss
hyperlogueSkill

security-model

hyperlogue/r3/.claude/skills/security-model/SKILL.md

r3's Host/origin/auth guards, isolated artifact preview and closed network policy, local and remote daemon configuration, publisher-side harness credentials, byte/path guards, migration storage, and dependency cooldown. Use when changing authentication, artifact or preview routes, resource serving, exposure settings, remote transport, or reviewing security impact.

354d agoDiscuss
romaraytSkill

security-review

romarayt/raytsystem-public-os/.agents/skills/security-review/SKILL.md

Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. Use for SECURITY REVIEW, adversarial testing, recovery review, or approval-boundary validation; remain independent and read-only.

1403mo agoDiscuss
georgekhananaevSkill

owasp-security

georgekhananaev/claude-skills-vault/.claude/skills/owasp-security/SKILL.md

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).

284mo agoDiscuss
wulaosijiSkill

security-drill

wulaosiji/skills/security-drill/SKILL.md

AI Agent自动化安全演练与攻击模拟测试工具,运行定时攻击场景(prompt注入、社会工程学、命令绕过、信息泄露、模型降级),验证事件响应和加固控制有效性,输出通过/失败报告。 Use when: "安全演练", "攻防测试", "攻击模拟", "security drill", "attack simulation", "渗透测试", "incident response test", "red team exercise". 在隔离环境中模拟攻击,不修改真实系统,结果本地存储,支持每周定时执行。Cross-references: security-hardening, skill-security-audit, secure-key-manager. Built by UniqueClub 🌐 https://uniqueclub.ai

2822d agoDiscuss
henryvn27Skill

orca-security

henryvn27/orca-framework/skills/orca-security/SKILL.md

Review security-relevant behavior, install scripts, CI, data handling, and unsafe agent instructions.

56d agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.