incident response instructions

25 tagged incident response, measured the same way as everything else here.

Browse within: cybersecurity 7ai-security 5dfir 5forensics 5

AiSOC AGENTS.md

03

beenuar/AiSOC

Instructions file CodexOpenCode

Instructions for beenuar/AiSOC, covering learned user preferences and learned workspace facts.

2.4k 8d ago A 6,497 tokens original MIT

attackgen AGENTS.md

04

mrwadams/attackgen

Instructions file CodexOpenCode

AGENTS.md instructions for mrwadams/attackgen, covering agents.md, project overview, development commands, running the application and installing dependencies.

1.2k 10d ago A 3,508 tokens GPL-3.0

attackgen CLAUDE.md

05

mrwadams/attackgen

Instructions file

Claude Code instructions for mrwadams/attackgen, covering claude.md, project overview, development commands, running the application and installing dependencies.

1.2k 10d ago A 3,882 tokens GPL-3.0

YanpengQi7/ai-reliability-copilot

Instructions file CodexOpenCode

AGENTS.md instructions for YanpengQi7/ai-reliability-copilot: This version has breaking changes — APIs, conventions, and file structure may all differ from your training data. Read the relevant guide in nodemodules/next/dist/docs/ before writing any code. Heed deprecation notices.

83 2mo ago A 74 tokens

YanpengQi7/ai-reliability-copilot

Instructions file

Claude Code instructions for YanpengQi7/ai-reliability-copilot, covering ai reliability copilot — agent context, 30-second orientation, architecture at a glance, where things live and common tasks — what to touch.

83 2mo ago C 4,424 tokens

depalmar/ai-dfir-toolkit

Instructions file

Instructions for depalmar/ai-dfir-toolkit, covering project context, what this is, commands, rules that are not negotiable and what a restricted runner cannot verify.

23 10d ago A 6,013 tokens original Apache-2.0

puck-security/puck-scout

Instructions file

Instructions for puck-security/puck-scout, covering claude.md — puck scout, 1. what puck is, 2. architectural invariants, 3. repository structure and 4. language and tooling conventions.

23 1mo ago A 1,649 tokens original MIT

vigil CLAUDE.md

11

vigil-agency/vigil

Instructions file

Claude Code instructions for vigil-agency/vigil, covering 1. plan node default, 2. subagent strategy, 3. self-improvement loop, 4. verification before done and 5. demand elegance (balanced).

18 3mo ago A 580 tokens AGPL-3.0

sift-mcp AGENTS.md

12

AppliedIR/sift-mcp

Instructions file CodexOpenCode

Instructions for AppliedIR/sift-mcp, covering valhuntir — forensic investigation platform, getting started, available mcp servers, malware analysis escalation and investigation recording.

15 3mo ago A 2,318 tokens original MIT

Juwon1405/agentic-dart

Instructions file CodexOpenCode

Instructions for Juwon1405/agentic-dart, covering agents.md — agent guide for agentic-dart, project summary, repository map, preferred commands and full suite — every test must pass.

9 2mo ago A 1,035 tokens original MIT

Juwon1405/agentic-dart

Instructions file

Instructions for Juwon1405/agentic-dart, covering claude.md — ai assistant guide for agentic-dart, what this project is, repository map, run modes (know which one you are touching) and non-negotiables (do not break these).

9 2mo ago A 1,506 tokens original MIT

HieuAnh87/sentry-selfhosted-mcp

Instructions file CodexOpenCode

Instructions for HieuAnh87/sentry-selfhosted-mcp, covering selfhosted-sentry-mcp, commands, install deps, build typescript to ./build and set executable bit and watch mode during source edits.

8 3mo ago A 512 tokens original MIT

kismatkunwar89/SAVVYDFIR-MCP

Instructions file

Instructions for kismatkunwar89/SAVVYDFIR-MCP, covering savvydfir-mcp - dfir investigation framework, what this is, critical rules, forensic knowledge in tool responses and investigation workflow (7 phases).

4 2mo ago A 10,844 tokens original MIT

haporfirio/cyberskills-hub

Instructions file

Instructions for haporfirio/cyberskills-hub, covering cyberskills documentation hub, instrucao de routing, role context, top-50 keywords and domain lookup.

2 5mo ago A 1,452 tokens original MIT

pypi AGENTS.md

19

resq-software/pypi

Instructions file CodexOpenCode

AGENTS.md instructions for resq-software/pypi, covering resq pypi packages — agent guide, mission, stack, repo map and commands.

1 yesterday C 706 tokens original Apache-2.0

pypi CLAUDE.md

20

resq-software/pypi

Instructions file

Claude Code instructions for resq-software/pypi, covering resq pypi packages — agent guide, mission, stack, repo map and commands.

1 yesterday A 589 tokens original Apache-2.0

frli4797/crowdsec-mcp

Instructions file CodexOpenCode

AGENTS.md instructions for frli4797/crowdsec-mcp, covering agent instructions, mission, boundaries, safety rules and development workflow.

0 14d ago A 945 tokens

Wave-Engineering/mcp-server-wtf

Instructions file

Claude Code instructions for Wave-Engineering/mcp-server-wtf, covering project instructions for claude code, platform detection, project configuration, github-specific: projects and milestones and project structure.

0 26d ago A 5,942 tokens original MIT

gitmoru AGENTS.md

23

gitmoru/gitmoru

Instructions file CodexOpenCode

Development instructions for the gitmoru repository, including what to read before different kinds of work and which actions are forbidden. The repository examines code that may be malicious.

0 9d ago A 791 tokens original MIT

gitmoru CLAUDE.md

24

gitmoru/gitmoru

Instructions file

Project instructions for working on gitmoru, a tool that examines repositories that may contain malicious code. They point agents to the documents and safety rules to read before making changes.

0 9d ago A 84 tokens original MIT