agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matchesWorked for most · soon
affaan-mSkill

security-review

affaan-m/ECC/.agents/skills/security-review/SKILL.md

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

246k30d agoReads credentialsDiscuss
MicrosoftSkill

security-report-check

microsoft/TypeScript/.github/skills/security-report-check/SKILL.md

Are you doing security research on this repo? This document covers what guarantees and non-guarantees are provided. Consult this document before reporting a security issue or conducting security research.

111k2y agoDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/golang-security.md

Go security extending common rules

246k30d agoReads credentialsDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/kotlin-security.md

Kotlin security extending common rules

246k30d agoReads credentialsDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/php-security.md

PHP security extending common rules

246k30d agoDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/python-security.md

Python security extending common rules

246k30d agoReads credentialsDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/swift-security.md

Swift security extending common rules

246k30d agoReads credentialsDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/typescript-security.md

TypeScript security extending common rules

246k30d agoReads credentialsDiscuss
affaan-mCursor rule

ECC / rules

affaan-m/ECC/.cursor/rules/common-security.md

Security: mandatory checks, secret management, response protocol

246k30d agoDiscuss
garrytanSkill

cso

garrytan/gstack/cso/SKILL.md

Security audit: supported static findings; qualified profiles add reproduction and repair candidates. (gstack)

134k6d agoDiscuss
GoogleSkill

critique

google-gemini/gemini-cli/tools/gemini-cli-bot/.gemini/skills/critique/SKILL.md

Expertise in auditing and fixing repository scripts and GitHub Actions workflows to ensure technical robustness and security.

107k5mo agoDiscuss
NousResearchSkill

requesting-code-review

NousResearch/hermes-agent/skills/software-development/requesting-code-review/SKILL.md

Pre-commit review: security scan, quality gates, auto-fix.

250k6mo agoDiscuss
Significant-GravitasSkill

pr-review

Significant-Gravitas/AutoGPT/.claude/skills/pr-review/SKILL.md

Review a PR for correctness, security, code quality, and testing issues. TRIGGER when user asks to review a PR, check PR quality, or give feedback on a PR.

188k19d agoDiscuss
n8n-ioSkill

n8n:human-like-code-review

n8n-io/n8n/.agents/skills/human-like-code-review/SKILL.md

Reviews a GitHub pull request like a thoughtful human reviewer and writes the feedback to a markdown file. Prioritizes context, architecture fit, solution complexity, bugs, security edge cases, and missing tests. Use when given a PR URL to review, or when the user says /human-like-code-review.

206k19d agoDiscuss
SupabaseSkill

safe-sql-execution

supabase/supabase/.agents/skills/safe-sql-execution/SKILL.md

Use whenever code will build, return, fetch, or execute SQL that runs against a user's real Postgres database — even when the request reads like an ordinary feature or bug fix and never says "security," "injection," or "SafeSqlFragment." This covers: writing or editing any pg-meta function, query builder, or endpoint that builds/returns SQL for database objects (tables, views, functions, DB triggers, indexes, RLS policies); interpolating a schema/table/column/search/route-param value into SQL text; storing, fetching, or re-running SQL that round-trips from the database (a policy's definition, a function/view definition, a snippet's saved content); and any "Run"/"Apply"/"Execute" action that sends SQL to a project's database (SQL editor run-selection, policy editor apply, snippet runner). Load this BEFORE writing such code, not only when reviewing a finished diff. Skip only for changes that never touch SQL text or execution — styling, unrelated data hooks, non-SQL form validation, or UI layout work.

111k8d agoDiscuss
obraSkill

executing-plans

obra/superpowers/skills/executing-plans/SKILL.md

Use when executing an implementation plan in the current session as the implementer yourself — your human partner chose inline execution, or no subagent tool is available

292k3mo agoDeletes or force-pushesDiscuss
obraSkill

receiving-code-review

obra/superpowers/skills/receiving-code-review/SKILL.md

Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation

292k3mo agoDiscuss
obraSkill

subagent-driven-development

obra/superpowers/skills/subagent-driven-development/SKILL.md

Use when executing implementation plans with independent tasks in the current session

292k3mo agoDeletes or force-pushesDiscuss
obraSkill

systematic-debugging

obra/superpowers/skills/systematic-debugging/SKILL.md

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes

292k3mo agoDiscuss
NousResearchAGENTS.md

hermes-agent

NousResearch/hermes-agent/AGENTS.md

Testing). - **E2E validation, not just green unit mocks.** Anything touching resolution chains, config propagation, security boundaries, remote backends, or file/network I/O must exercise the real path with real imports against

250k6mo agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.