agentleFS
Sign inSign up

Find the best CLAUDE.md, AGENTS.md and Claude skills

One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.

Best matchesWorked for most · soon
BankrBotSkill

Security

BankrBot/skills/ethskills-security/SKILL.md

Solidity vulnerabilities, defensive code patterns, and a pre-deployment audit checklist. Covers reentrancy, oracle manipulation, token decimals, SafeERC20, ERC-4626 inflation, infinite approvals, and MEV.

1.2k5mo agoDiscuss
boshu2Skill

security

boshu2/agentops/skills/security/SKILL.md

Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure needs assessment; never silently change policy.

4463mo agoDiscuss
TheBeardedBearSASSkill

security

TheBeardedBearSAS/claude-craft/.claude/skills/security/SKILL.md

Security guidelines and OWASP Top 10. Use when reviewing security, implementing authentication or authorization, hardening code, or discussing vulnerabilities.

1052mo agoDiscuss
ilang-aiSkill

security

ilang-ai/autocode/skills/security/SKILL.md

Auto-apply security basics and block deploys that would leak secrets. Never ask the user about security choices — just do it, and run a real secret scan before going live.

10310d agoDiscuss
davidmatousekSkill

security

davidmatousek/tachi/.claude/skills/security/SKILL.md

Claude-powered SAST and SCA security scan skill. Invoked automatically as the Security Scan step (Step 7) of /aod.build (after Design Quality Gate, before Code Simplification) or standalone via /security. Analyzes all code files and dependency manifests changed on the feature branch relative to main for OWASP Top 10 vulnerability patterns and known CVE findings. Produces a human-readable security-scan.md report and machine-readable .security/ compliance artifacts (scan-log.jsonl, vulnerabilities.jsonl, SARIF 2.1.0, CycloneDX 1.5 SBOM). Blocks build progression on CRITICAL/HIGH findings with an explicit acknowledgment gate. Use --no-security in /aod.build to skip. Invoke /security directly for standalone analysis outside the build pipeline.

9049d agoDiscuss
AsiaOstrichSkill

security

AsiaOstrich/universal-dev-standards/.claude/skills/security-assistant/SKILL.md

引導安全審查與弱點評估,遵循 OWASP 標準。 Use when: 安全稽核、弱點檢查、安全程式碼審查、威脅建模。 Not for: 自動化的相依套件、CVE 與機密掃描——請用 /scan;處理正在發生的資安事件——請用 /incident。 Keywords: security, OWASP, vulnerability, authentication, authorization, 資訊安全, 弱點, 認證, 授權, 威脅建模.

753d agoDiscuss
AsiaOstrichSkill

security

AsiaOstrich/universal-dev-standards/skills/security-assistant/SKILL.md

Guide security review and vulnerability assessment following OWASP standards. Use when: security audit, vulnerability check, secure coding review, threat modeling. Not for: automated dependency, CVE, and secret scanning — use /scan; handling a breach in progress — use /incident. Keywords: security, OWASP, vulnerability, authentication, authorization.

753d agoDiscuss
korchard333Skill

security

korchard333/claude-power-platform-community/.claude/skills/security/SKILL.md

Dataverse Security Model. Use when: designing security roles, column-level security, business units, teams (owner/access/AAD group), record sharing, hierarchy security, minimum viable privileges, security role management via Web API.

466mo agoDiscuss
galandoSkill

security

galando/piv-speckit/.claude/skills/security/SKILL.md

Enforces security best practices

288mo agoDiscuss
LazyIsEfficientSkill

security

LazyIsEfficient/agentic-os/.claude/skills/security/SKILL.md

Scan and redact PII and sensitive data (emails, phone numbers, SSNs, API keys, IP addresses, credentials, amounts, company/person names) from repository files. Includes a pre-commit hook to block commits containing PII. Use when asked to audit code for sensitive data, sanitize files before publishing, or install PII detection hooks. For application security hardening see security-engineering.

153mo agoDiscuss
manu14357Skill

security

manu14357/Zelaxy/.agents/skills/security/SKILL.md

Maintain and improve security across the Zelaxy platform. Use for: secret encryption boundaries, auth modes (session/API key/internal JWT/cron), CSP and middleware hardening, webhook verification, tenant isolation, and security test coverage.

154mo agoDiscuss
kpbraySkill

security

kpbray/power-bi-agent-skills/.github/skills/security/SKILL.md

Implements Row-Level Security (RLS) and Object-Level Security (OLS) for Power BI models. Use for data access control, dynamic security, and multi-tenant scenarios.

98mo agoDiscuss
prangishviliAbeSkill

security

prangishviliAbe/agent-skills/security/SKILL.md

Audit application code and architecture, investigate suspected vulnerabilities, threat-model sensitive features, and implement security fixes. Use for explicit security reviews, exploitability analysis, incident triage, or changes to authentication, authorization, secrets, tenant isolation, injection defenses, file handling, and privileged AI tools.

75d agoDiscuss
0xSeroSkill

security

0xSero/claude-skill-dir/security/SKILL.md

Security Analysis & Protection Expert Expert in security analysis, reverse engineering, intrusion detection, and system hardening. Specializes in using tools like Ghidra, forensics utilities, and security monitoring to ensure system safety

411mo agoDiscuss
daianepepes-labSkill

security

daianepepes-lab/claude-skills/security/SKILL.md

Audit and fix security vulnerabilities across web apps, APIs, databases, auth systems, and infrastructure. Use when asked to review security, fix vulnerabilities, implement auth, or harden a system.

46mo agoDiscuss
n-n-codeSkill

security

n-n-code/n-n-code-skills/.agents/skills/security/SKILL.md

Evidence-grounded threat modeling, vulnerability review, and secure implementation. Use for explicit security audits or primary risks involving authorization, untrusted input, external requests, parsers/uploads, secrets, sensitive data, isolation, or release integrity. Not for routine implementation or non-security red-teaming. Add `security-identity-access` for identity and tenant authorization.

425d agoDiscuss
plipowczanSkill

security

plipowczan/claude-piv-skeleton/.claude/skills/security/SKILL.md

Enforces security best practices

48mo agoDiscuss
zhaoxuya520Skill

api-security

zhaoxuya520/reverse-skill/skills/api-security/SKILL.md

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

38k9d agoDiscuss
zhaoxuya520Skill

llm-security

zhaoxuya520/reverse-skill/skills/llm-security/SKILL.md

Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.

38k9d agoDiscuss
bchoxSkill

security

bchox/agent-practices/skills/security/SKILL.md

Use when the change touches auth, secrets, trust boundaries, or sensitive data.

214d agoDiscuss
CLAUDE.md vs AGENTS.md

Agent instruction files

What are agent instruction files?

Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.

CLAUDE.md or AGENTS.md?

CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.

What is a skill?

A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.

Can I search my own team's files too?

Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.