Security instructions files

1,256 tagged Security, measured the same way as everything else here.

Browse within: ai-security 64model-context-protocol 61cybersecurity 52copilot 39devsecops 34AI Safety 33claude-code-plugin 32bug-bounty 28code-quality 25appsec 24ai-coding 21agent-security 20llm-security 19go 18

cai-layer/cai

Instructions file GitHub Copilot

Instructions for cai-layer/cai, covering cai — copilot review instructions, basics (merge-blocking), 🔴 security & privacy (merge-blocking), never interpolate untrusted text into a shell invocation and never interpolate untrusted text into applescript source.

not rated 56 +1 10d ago A 2,143 tokens original MIT

prowler-cloud/prowler-studio

Instructions file CodexOpenCode

Instructions for prowler-cloud/prowler-studio, covering agent development guide, system architecture, project structure, agents and checkreatoragent flow.

not rated 55 1mo ago A 6,255 tokens original Apache-2.0

arcasilesgroup/ai-engineering

Instructions file

Claude Code instructions for arcasilesgroup/ai-engineering, a project described as: Turn any repo into a governed AI workspace. Quality gates, security scanning, and risk management — enforced locally via git hooks. Works with Claude Code, GitHub Copilot, Cursor, Gemini & Codex.

not rated 54 2d ago A 6 tokens copy · 100% Apache-2.0

wangbooth/Claude-Code-Guardrails

Instructions file

Instructions for wangbooth/Claude-Code-Guardrails, covering claude.md, architecture, hook scripts (claude/hooks/), hook configuration (claude/settings.json) and installation system.

not rated 54 11mo ago E 1,171 tokens original MIT

cybozu/prompt-hardener

Instructions file CodexOpenCode

AGENTS.md instructions for cybozu/prompt-hardener, covering prompt hardener, project overview, supported agent types, core workflow and architecture.

not rated 54 3d ago A 1,188 tokens original Apache-2.0

cybozu/prompt-hardener

Instructions file

Claude Code instructions for cybozu/prompt-hardener, a project described as: Prompt Hardener analyzes prompt-injection-originated risk in LLM-based agents and applications.

not rated 54 3d ago A 4 tokens copy · 100% Apache-2.0

stringer CLAUDE.md

272

davetashner/stringer

Instructions file

Claude Code instructions for davetashner/stringer, covering claude.md — stringer, git workflow, secret safety, beads backlog and decision records.

not rated 53 2d ago A 923 tokens original MIT

CTF-Solver CLAUDE.md

273

foxibu/CTF-Solver

Instructions file

Claude Code instructions for foxibu/CTF-Solver, covering claude.md - ai assistant guide for mcp kali server, project overview, purpose, key features and architecture.

not rated 54 +1 5mo ago C 7,734 tokens

deepsecure CLAUDE.md

274

DeepTrail/deepsecure

Instructions file

Instructions for DeepTrail/deepsecure, covering claude.md, project overview, development commands, environment setup and install development dependencies.

not rated 52 7mo ago A 1,603 tokens original Apache-2.0

CuriousLearnerDev/Online_Tools-AI

Instructions file

A project-specific instruction file for Claude Code, an AI coding assistant. It covers an authorised web console for AI-assisted penetration testing, along with required authorisation statements and audit-report rules.

not rated 52 +1 1mo ago A 344 tokens

solanabr/auditor-skill

Instructions file CodexOpenCode

Instructions for solanabr/auditor-skill, covering auditor-skill — agent orchestration, flow (full audit) and trail of bits (vendored submodule).

not rated 52 +2 1mo ago A 890 tokens original MIT

SquidSec/SquidC5

Instructions file GitHub Copilot

Instructions for SquidSec/SquidC5, a project described as: Security-first AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination) for authorized red team & pentest. Built by SquidSec.

not rated 51 14d ago A 120 tokens original MIT

SquidC5 AGENTS.md

278

SquidSec/SquidC5

Instructions file CodexOpenCode

Instructions for SquidSec/SquidC5, covering agents.md - instructions for ai agents working on squidc5, classification & mission, project stack, non-negotiable security rules and hardened defaults (do not casually reverse).

not rated 51 14d ago A 5,242 tokens original MIT

ndif CLAUDE.md

279

ndif-team/ndif

Instructions file

Claude Code instructions for ndif-team/ndif, covering claude.md — ndif agent guide, what ndif is, top-level layout, architecture at a glance and security sandbox (the highest-stakes area).

not rated 51 yesterday A 4,885 tokens original MIT

Kilntainers CLAUDE.md

281

Kiln-AI/Kilntainers

Instructions file

Instructions for Kiln-AI/Kilntainers, covering kilntainers: secure agent sandboxes, specs and commands & tools.

not rated 50 6mo ago A 345 tokens original MIT

jonathan-vella/apex-accelerator

Instructions file GitHub Copilot

Copilot instructions for jonathan-vella/apex-accelerator, covering apex - copilot instructions, azure defaults (canonical), default regions, required tags (azure policy enforced) and security baseline + avm mandate.

not rated 50 2d ago A 1,889 tokens original MIT

babyworm/rtl-agent-team

Instructions file

Claude Code instructions for babyworm/rtl-agent-team, covering language rule, important — project identity, why agentic coding for silicon ip, plugin runtime vs. development context (critical) and plugin architecture: dynamic prompt injection.

not rated 50 11d ago A 7,644 tokens original MIT

zscaler/zscaler-mcp-server

Instructions file

Instructions for zscaler/zscaler-mcp-server, covering zscaler mcp server, architecture overview, core components, request flow and service architecture.

not rated 50 10d ago A 37,325 tokens original MIT

zscaler/zscaler-mcp-server

Instructions file Gemini CLI

Instructions for zscaler/zscaler-mcp-server, covering zscaler mcp server, tool naming & discovery, critical gotchas, write operations — safety rules and zdx filtering.

not rated 50 10d ago A 2,152 tokens original MIT

nightshift AGENTS.md

286

orwa-mahmoud/nightshift

Instructions file CodexOpenCode

AGENTS.md instructions for orwa-mahmoud/nightshift: AI-assisted contributions are welcome. The same correctness, security, licensing, testing, and quality standards apply regardless of which tools are used.

not rated 51 yesterday A 193 tokens original MIT

sebastienrousseau/pain001

Instructions file GitHub Copilot

Enterprise-grade Release Architect. Enforces 95%+ coverage, security-hardened XML, resilient release orchestration, and zero-trust quality model.

not rated 49 3d ago B 5,335 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: