LLM Mart Basic
@llm-mart · Joined Jun 2026
Finance (CFO). Owns plugins/finance/** and nothing else. Delegate work in this department's remit here.
Corporate IT. Owns plugins/it-operations/** and nothing else. Delegate service desk, systems and network administration, endpoints, assets, identity lifecycle, and backup work here.
Reviewer-class. Read-only review of what other departments commit to — contract terms, privacy and data handling, risk acceptance, and compliance findings. Holds no write surface. Its findings are not overrulable by the department under review.
Legal & Risk (CLO/CCO). Owns plugins/legal-risk/** and nothing else. Delegate work in this department's remit here.
Marketing (CMO). Owns plugins/marketing/** and nothing else. Delegate work in this department's remit here.
Operations (COO). Owns plugins/operations/** and nothing else. Delegate work in this department's remit here.
People (CHRO). Owns plugins/people/** and nothing else. Delegate work in this department's remit here.
Enterprise PMO. Owns plugins/pmo/** and nothing else. Delegate portfolio governance, program and project delivery, delivery risk, benefits and adoption work here.
Product (CPO). Owns plugins/product/** and nothing else. Delegate work in this department's remit here.
Repository scaffolding — docs, CI, scripts, plugin manifests, and the README. Owns everything outside plugins/. Delegate structural and documentation work here.
Revenue (CRO). Owns plugins/revenue/** and nothing else. Delegate work in this department's remit here.
Reviewer-class. Read-only security review of what other departments build — authorization, data handling, secrets, dependencies, and designs that create exposure. Holds no write surface. Blocking findings are not overrulable by the department under review.
Security (CISO). Owns plugins/security/** and nothing else. Delegate threat modeling, security architecture, incident response, vulnerability management, and identity work here.
Technology (CTO/CIO). Owns plugins/technology/** and nothing else. Delegate work in this department's remit here.
Keeps the engagement record for client work. Use when they name a client or stakeholder. Use when they debrief a meeting or paste notes. Use when they ask what was agreed. Use when they run a POC, change the client's codebase, prove it on their staging, go live, or need evals bef
Imported from nitinjain999/platform-skills/assets/agents/navigator.template.md.
코드·설정·프리셋 변경 뒤 문서를 현행화한다. "문서 현행화", "README 갱신", "문서 최신화" 요청 시, 그리고 동작·경로·버전·수치를 바꾼 PR 을 올리기 직전에 사용. 문서의 주장을 실제 코드·명령 출력·공식문서와 대조해 정정하고, 다국어 짝 파일을 함께 갱신한다.
이 파일을 복제해 프로젝트 스킬을 만든다. 트리거 조건을 description 에 구체적으로 적을 것.
사용자가 /grill-me 를 호출하거나 아이디어·기능 요청·스펙을 구현 전에 굽고(grill)·압박 검증하고·심문해 달라고 할 때 사용. superpowers:brainstorming 의 opt-in 대체재 — 작업마다 사용자가 둘 중 하나를 고른다.
에이전트 영속 메모리를 실제 소스와 대조 — 각 메모리의 핵심 단언을 코드·DB·이슈 트래커·파일시스템에 대조해 stale 을 정정하고 dead 를 아카이브 후보로 리포트. 메모리가 30개를 넘거나, 스택/인프라 큰 변경(라이브러리 교체·버전 업그레이드·서버 이전·스키마 DROP) 직후, 메모리끼리 모순돼 보일 때, 또는 "메모리 정리/감사" 요청 시 사용.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/python-scaffold
Python scaffold
Scaffold a Python project (FastAPI, Django, library, or CLI) with uv, type hints, testing, and dev tooling
/approve-review
Approve review
Open a review-action approval window by creating the ./.review-approved flag file. Takes an optional reason string that is recorded in the flag file and an unsigned approval log.
/list-pending
List pending
List the review actions that the review-governance policy blocked in this session. protect-mcp 0.7.4 writes no receipt for a denied call, so the list comes from the session, not from ./review-receipts/.
/compliance-check
Compliance check
Review software compliance controls, regulatory requirements, and audit readiness
/security-dependencies
Security dependencies
Scan dependencies for vulnerabilities and generate supply chain security evidence
/security-hardening
Security hardening
Orchestrate comprehensive security hardening with defense-in-depth strategy across all application layers
/security-sast
Security sast
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
/setup
Setup
Initialises the ShipMate pipeline in the current project. Creates the stories folder, sets up the pipeline state directory, and runs the initial codebase scan to generate project-doc.md and AGENTS.md.
/ship
Ship
Master pipeline entry point. Routes requirements from a story file through scan → orchestrate → architect → implement → review → QA → playwright stages. Use /ship stories/foo.md to start, /ship status to check progress, /ship resume to continue.
/business-case
Business case
Generate comprehensive investor-ready business case document with market, solution, financials, and strategy
/financial-projections
Financial projections
Create detailed 3-5 year financial model with revenue, costs, cash flow, and scenarios
/market-opportunity
Market opportunity
Generate comprehensive market opportunity analysis with TAM/SAM/SOM calculations
/rust-project
Rust project
Scaffold a Rust project (binary, library, workspace, or Axum web API) with Cargo, testing, and dev tooling
/tdd-cycle
Tdd cycle
Execute a comprehensive TDD workflow with strict red-green-refactor discipline
/tdd-green
Tdd green
Implement minimal code to make failing tests pass in TDD green phase
/tdd-red
Tdd red
Write comprehensive failing tests following TDD red phase principles
/tdd-refactor
Tdd refactor
Refactor code while keeping all tests green in TDD refactor phase
/issue
Issue
Resolve a GitHub issue from triage and root cause analysis through test-driven implementation and a pull request
/standup-notes
Standup notes
Generate async standup notes from git commits, Jira tickets, and Obsidian notes
/accessibility-audit
Accessibility audit
Audit UI code for WCAG compliance
Ultra-lightweight, open-source, self-hosted personal AI agent framework in Python with WebUI, tools, memory, MCP, multi-agent workflows, automation, and chat ap…
29 views 0 likesGovernance framework for AI coding agents. It runs them through a five-step workflow (plan, build, review, test, ship) where no step counts as done without evid…
17 views 0 likesUltimate Multi-Agent OS for Autonomous AI NPCs 2026
15 views 0 likesPersonal AI Agent Hub 2026 — Build Your 24/7 Autonomous Assistant
26 views 0 likesProven 2026 Multi-Agent AI Review System – Verdict-Driven Quality Control
29 views 0 likesSlash API Batch: Cut AI Costs by 50% in 2026
16 views 0 likesWeb dashboard for Hermes Agent — multi-platform AI chat, session management, scheduled jobs, usage analytics
19 views 0 likesAgent Skills for Solopreneurs
31 views 0 likesAirLLM dramatically reduces inference memory usage, letting 70B large language models run on a single 4GB GPU card
140 views 0 likesZero, your trustworthy AI teammate for real work.
16 views 0 likes一套 DSH runtime,Desktop、Web 与 TUI 三种开发体验。
12 views 0 likesOpen-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations.
17 views 0 likes⚙️ TypeScript Style Guide and Agent Skill. A concise set of conventions and best practices for consistent, maintainable code.
28 views 0 likesFramework for AI agents to build and maintain a digital brain through Obsidian wiki
17 views 0 likesApache Maka (Incubating) is a local-first AI agent workspace. Model messages, tool calls, tool results, permission decisions, and termination events are recorde…
25 views 0 likesNeo.mjs is a self-evolving software organism: a professional end-to-end AI engineering team whose cross-model swarm inhabits live apps via Neural Link, Active H…
25 views 0 likesAgentic development harness for Claude Code — SPEC-driven plan/run/sync, TRUST 5 quality gates, model+effort routing, and Claude×GLM multi-LLM cost control. Sin…
19 views 0 likesNocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of productio…
27 views 0 likesAn open-source AI coding agent that lives in your terminal.
29 views 0 likesPawWork — free, open-source desktop AI agent for macOS and Windows. Alternative to Codex App and Claude Cowork. BYOK with 75+ providers, ChatGPT OAuth, local mo…
16 views 0 likes