LLM Mart Basic
@llm-mart · Joined Jun 2026
Authoring guide for creating a new skill in this plugin, matching the conventions the existing skills already use. Establishes the three decisions every skill must make before any prose is written: how it is invoked (entry point vs building block), how it acquires its input, and
Use when an adversarial code review is needed after implementation. Reviews with fresh context and no shared conversation history to prevent self-evaluation bias. Produces a hard-gating verdict — REQUEST CHANGES blocks shipping. Example triggers — "review my changes", "code revie
Use after research is complete to draft the approach before any code is written. Drafts a ~200-line design document covering current state, desired end state, patterns to follow, and decisions made. Resolves its own open questions autonomously, recording each as an explicit, audi
Use when you need to locate files in a codebase relevant to a specific area. Maps conceptual goals to actual file locations even when exact names are unknown. Operates from questions.md only, never the original task description.
Use when the implementation plan needs to be executed slice by slice. A seasoned coding expert that reads the plan, follows TDD discipline, executes one vertical slice at a time, and commits each slice atomically when its tests pass. Dispatched during the Implement phase.
Use after the structure is produced to create the tactical implementation plan. Translates each vertical slice in structure.md into precise file-level steps with acceptance test mappings. The plan is a tactical artifact for the implementer — neither the structure nor the plan is
Use as the first agent of the QRSPI pipeline. Decomposes a user's task description into a full task record (task.md) and neutral research questions (questions.md), plus conditional artifacts — a prd.md when the PRD criteria apply, and a repos.md listing the repos the topic touche
Use when codebase facts need to be gathered before any design or implementation work. Reads code, traces dependencies, documents patterns. Receives only the path to questions.md, never the original task description.
Use when a security review is needed after implementation. Applies OWASP-style checks with fresh context. Critical findings are a hard gate — they block shipping until resolved. Example triggers — "security review", "check for vulnerabilities", "audit this code for security issue
Use after the design review passes to break the work into vertical slices with verification checkpoints. Each slice is end-to-end (touches every layer needed to deliver one piece of functionality), independently testable, and atomically committable. Produces a ~2-page document th
Use after implementation to review whether project documentation needs updating. Reads the diff and compares against existing docs to identify gaps and stale content. Produces a structured report — does not rewrite docs itself. Example triggers — "check if docs need updating", "d
Use after the worktree is prepared to write all failing acceptance tests from the structure. Tests form the immutable scope fence for implementation. Operates inside the implement phase as a sub-step before the implementer runs.
Use when live application verification is needed after implementation. Boots the application, interacts with it as a user would, and evaluates the experience. For API-only projects, sends real HTTP requests. Example triggers — "verify the app works", "test the UI", "check the use
Use when comprehensive verification checks need to run before completion. Runs all available checks (format, lint, type check, build, tests) in speed order and produces an evidence-based report. Example triggers — "run all checks", "verify the build", "pre-flight checks", "does e
Extract and analyze writing improvements from GitHub PR review comments. Use when asked to show review feedback, style changes, or editorial improvements from a GitHub pull request URL. Handles both explicit suggestions and plain text feedback. Produces structured output comparin
Investigate fast-agent session and history files to diagnose issues. Use when a session ended unexpectedly, when debugging tool loops, when correlating sub-agent traces with main sessions, or when analyzing conversation flow and timing. Covers session.json metadata, history JSON
Run shell and filesystem tools in local, Docker, Hugging Face, or custom environments.
Attach files, MCP resources, and prompt files directly to agent conversations.
Shape agent behavior with reusable instructions and prompt files.
Add slash commands and post-turn displays to fast-agent.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/lookup-contact
Lookup contact
Search for Autotask contacts by name, email, phone, or company
/my-tickets
My tickets
List tickets currently assigned to you with optional filtering
/reassign-ticket
Reassign ticket
Reassign a ticket to a different resource or queue
/search-products
Search products
Search the Autotask product catalog for products, services, or inventory items
/search-tickets
Search tickets
Search for tickets in Autotask PSA by various criteria
/time-entry
Time entry
Log time against tickets or projects in Autotask PSA
/update-ticket
Update ticket
Update fields on an existing Autotask ticket (status, priority, queue, due date)
/device-lookup
Device lookup
Find a device in Datto RMM by hostname, IP address, or MAC address
/resolve-alert
Resolve alert
Resolve an open alert in Datto RMM
/run-job
Run job
Run a quick job on a device in Datto RMM
/site-devices
Site devices
List all devices at a site in Datto RMM
/edit-doc-sections
Edit doc sections
Read, edit, and restructure sections of an IT Glue document
/find-organization
Find organization
Find an organization in IT Glue by name
/get-password
Get password
Retrieve a password from IT Glue (with security logging)
/lookup-asset
Lookup asset
Find a configuration item (asset) in IT Glue by name, hostname, serial number, or IP address
/search-docs
Search docs
Search IT Glue documentation by keyword or phrase
/account-summary
Account summary
Get a security posture summary for a RocketCyber customer account
/search-incidents
Search incidents
Search RocketCyber security incidents by account, status, severity, verdict, and date range
/find-secret
Find secret
Locate a Keeper record by description and return its UID and metadata without revealing any credential
/scope-audit
Scope audit
Report exactly what the connected Keeper KSM application can reach - folders, record counts, and record types - reading no credential values
PiG (Pi in Go) is a faithful Go port of upstream Pi, the TypeScript codebase behind the Pi coding agent. It is a parity-bound translation, not a rewrite: upstre…
2 views 0 likesAn AI Agent that lives in your pocket. Local-first and privacy focused.
3 views 0 likesUnofficial skill that teaches coding agents to build with TypeSafe AI's Jev: typed decisions, calibrated confidence, and prior art from 150+ community projects.
6 views 0 likesAdaptive Test-time Learning and Autonomous Specialization
4 views 0 likesPrediction-market trading engine — Wang Transform pricing on 291K+ contracts; paper-traded across Kalshi · Polymarket · Solana DFlow (Jito bundles) · 633 tests
3 views 0 likesKnowledge Management for Humans and Agents
5 views 0 likesOpen-source Claude Cowork / Codex / WorkBuddy alternative — a local-first AI office agent that turns one request into real PPTX, DOCX, XLSX and HTML files. Runs…
5 views 0 likesDeepAgent Code: AI coding agent with persistent memory and control plane
4 views 0 likesAwesome Jev — evidence-graded index of TypeSafe System One: SDKs, MCP tools, agents, apps and open models. 20 languages, rebuilt every 2 hours.
5 views 0 likesCLI for Telegram — agent-friendly, daemon-based, with webhook event push.
5 views 0 likesAI deep-research agent that turns any question into a cited report: plans searches, reads real sources, verifies evidence. Self-hosted, multi-provider, Docker-r…
4 views 0 likesEvent-stream AI Agent framework for building your persona bot 🍊
1 views 0 likesGive the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops t…
3 views 0 likesLocal Emperor-style AI agent with Vue WebUI, multi-provider LLMs, streaming chat, tools, skills, memory, and token telemetry.
2 views 0 likesOpen-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware researc…
8 views 0 likes"Never send a human to do a machine's job" - Open Source AI hacking agent
3 views 0 likesPrismer Cloud
3 views 0 likesMy Personal Blog (Robotics)
3 views 0 likesTau Coding Agent - like Pi, but twice as much
1 views 0 likesOpen-source alternative to OpenAI Dots: self-hosted AI chat, tools, approvals, connectors, and computer tasks.
0 views 0 likes