CLAUDE.md is for Claude Code, AGENTS.md for Codex-style clients, Cursor Rules for editor sessions. They are always-on constraints, not on-demand skills.
Keep the content from one source: path bans, language, test command, files not to touch. Copy the same bans. Do not forbid schema edits in one file and allow migrations in another.
Skills are for named playbooks. One-line reminders belong in these three files; long procedures belong in SKILL.md. See Cursor Rules vs skills and AGENTS.md vs skills on this site.
Maintain one source of truth and point the other two at it, or copy them in sync. After an edit, run the same small task in all three clients and watch who still crosses the ban.