cybersecurity instructions files

126 tagged cybersecurity, measured the same way as everything else here.

Browse within: ai-security 20blue-team 14devsecops 12model-context-protocol 9saas 9agentic 8mitre-attack 8incident-response 7compression 6ctf 6cyberchef 6data-analysis 6osint 6detection-engineering 5

cve-mcp CLAUDE.md

49

badchars/cve-mcp

Instructions file

Claude Code instructions for badchars/cve-mcp, covering cve mcp, project context, neden mcp?, hedef kullanim and veri kaynaklari.

not rated 23 yesterday A 845 tokens original MIT

gromhacks/bonsai-ninja

Instructions file CodexOpenCode

AGENTS.md instructions for gromhacks/bonsai-ninja, covering bonsai-ninja, map a codebase, optional explicit semantic sidecar prewarm, explicit spelling for default syntax/construct indexing and optional during active editing.

not rated 21 changed today A 6,071 tokens original MIT

mct2032 CLAUDE.md

51

webdevtodayjason/mct2032

Instructions file

Claude Code instructions for webdevtodayjason/mct2032, covering mct2032 - mini cyber tool 2032, claude code project instructions, 🎯 project overview, πŸ› οΈ required mcp tools and πŸ“‹ dart task management protocol.

not rated 20 1y ago A 1,545 tokens

doublegate/CyberChef-MCP

Instructions file GitHub Copilot

Copilot instructions for doublegate/CyberChef-MCP, covering github copilot custom instructions for cyberchef mcp, quick start for copilot, project overview, key architecture points and core components.

not rated 19 changed today A 1,937 tokens GPL-3.0

doublegate/CyberChef-MCP

Instructions file

Claude Code instructions for doublegate/CyberChef-MCP, a project described as: Model Context Protocol server for CyberChef β€” exposes GCHQ's "Cyber Swiss Army Knife" as AI-agent tools: 504 operations across encryption, encoding, compression and forensics, on MCP protocol revision 2026-07-28.

not rated 19 changed today A 3 tokens GPL-3.0

Evaluris-Solutions/claude-active-directory

Instructions file

Claude Code instructions for Evaluris-Solutions/claude-active-directory, covering claude active directory β€” plugin guide, what's here, commands (13 slash commands β€” same filenames), agents (7) and rules (always active).

not rated 16 4mo ago A 1,208 tokens

dfirtnt/Huntable-CTI-Studio

Instructions file CodexOpenCode

AGENTS.md instructions for dfirtnt/Huntable-CTI-Studio, covering agents.md, orientation, local context, prompt-injection alerting and change-type quick reference.

not rated 11 changed today A 3,836 tokens original MIT

dfirtnt/Huntable-CTI-Studio

Instructions file

Claude Code instructions for dfirtnt/Huntable-CTI-Studio, covering claude.md, authoritative instructions, change discipline, important reminders and test execution.

not rated 11 today A 502 tokens original MIT

MingyiSecLab/Mingyi-Atlas

Instructions file CodexOpenCode

AGENTS.md instructions for MingyiSecLab/Mingyi-Atlas, covering repository guidelines, project structure & module organization, build, test, and development commands, coding style & naming conventions and testing guidelines.

not rated 11 2mo ago A 3,930 tokens original Apache-2.0

MingyiSecLab/Mingyi-Atlas

Instructions file

Claude Code instructions for MingyiSecLab/Mingyi-Atlas, covering claude.md, project overview, common commands, architecture and modes and prompts.

not rated 11 2mo ago A 2,060 tokens original Apache-2.0

aaearon/mcp-privilege-cloud

Instructions file

Claude Code instructions for aaearon/mcp-privilege-cloud, covering πŸ€– llm development guidelines, πŸ“š mandatory: context7 documentation usage, required context7 usage patterns, context7 mcp tool usage for this project and use context7 mcp tools to get library documentation.

not rated 10 2mo ago A 5,769 tokens

secs AGENTS.md

61

EvilFreelancer/secs

Instructions file CodexOpenCode

Instructions for EvilFreelancer/secs, covering agents.md - information security assistant, golden rules (non-negotiable, read first), operating modes, authorization and rules of engagement (mandatory gate) and local practice lab: connection details are gated.

not rated 10 25d ago A 4,000 tokens original Apache-2.0

secs CLAUDE.md

62

EvilFreelancer/secs

Instructions file

Instructions for EvilFreelancer/secs: The agent guardrails and operating rules for this information-security assistant live in AGENTS.md. Claude Code does not read AGENTS.md automatically, so it is imported here. Keep the substance in AGENTS.md; keep this file a thin import.

not rated 10 25d ago A 71 tokens original Apache-2.0

dinosn/security-knowledge-base

Instructions file CodexOpenCode

Instructions for dinosn/security-knowledge-base, covering security knowledge base agent contract, purpose and boundary, authority and trust, required startup sequence and agent permissions.

not rated 9 23d ago A 1,327 tokens original MIT

dinosn/security-knowledge-base

Instructions file

Instructions for dinosn/security-knowledge-base, a project described as: Local-first, evidence-led security knowledge base with a model-neutral JSON CLI, immutable sources, and human-reviewed proposals.

not rated 9 23d ago A 36 tokens original MIT

dinosn/security-knowledge-base

Instructions file Gemini CLI

Instructions for dinosn/security-knowledge-base, a project described as: Local-first, evidence-led security knowledge base with a model-neutral JSON CLI, immutable sources, and human-reviewed proposals.

not rated 9 23d ago A 38 tokens copy Β· 88% MIT

tsm CLAUDE.md

66

tashian/tsm

Instructions file

Instructions for tashian/tsm, covering tsm β€” notes for claude, layout, build & test, daemon (swift, run from tsmd/) and cli (go, run from repo root).

not rated 9 3mo ago A 2,333 tokens original MIT

unworldly CLAUDE.md

67

DilawarShafiq/unworldly

Instructions file

Instructions for DilawarShafiq/unworldly, covering claude code rules β€” unworldly, project context, source layout, key rules and task context.

not rated 9 1mo ago A 2,892 tokens original MIT

jayelbotvibe-web/hermes-pentest-lab

Instructions file

Instructions for jayelbotvibe-web/hermes-pentest-lab, covering claude.md β€” hermes-pentest-lab, commands, the authorization model β€” read before changing anything, client-data boundary β€” non-negotiable and architecture.

not rated 9 9d ago A 1,683 tokens original MIT

MadaBurns/bv-mcp

Instructions file GitHub Copilot

Copilot instructions for MadaBurns/bv-mcp, covering project guidelines, build and test, runtime and code style, architecture and project conventions.

not rated 8 today A 909 tokens

Security Context

70

MadaBurns/bv-mcp

Instructions file GitHub Copilot

Use when performing security audits, reviewing code for vulnerabilities, triaging findings, or assessing OWASP compliance in this repository.

not rated 8 today A 1,343 tokens

bv-mcp CLAUDE.md

71

MadaBurns/bv-mcp

Instructions file

Claude Code instructions for MadaBurns/bv-mcp, covering claude.md, what is this?, commands, tech and architecture.

not rated 8 today A 8,424 tokens

aplaceforallmystuff/mcp-threatintel

Instructions file CodexOpenCode

Instructions for aplaceforallmystuff/mcp-threatintel, covering agents.md - mcp-threatintel, tech stack, architecture, development commands and environment variables.

not rated 7 22d ago A 532 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page β€” the rest are on their repository pages: