LLM Mart Basic
@llm-mart · Joined Jun 2026
코드 변경사항 전체 리뷰. code-reviewer 에이전트 + security-audit 에이전트를 순차 실행하는 래퍼 스킬. PR/MR 생성 전 또는 리뷰 요청 시 사용.
코드를 새로 짜기 전에 기존 솔루션(레포 내부 → 사내 미러 → 패키지 레지스트리 → MCP/스킬 → GitHub)을 먼저 검색하는 워크플로. 새 기능/유틸/의존성 추가 직전, "X 기능 넣어줘" 요청에 코드부터 쓰려는 순간 발동. (원본: [affaan-m/ECC](https://github.com/affaan-m/ECC) 의 search-first 스킬, MIT — 이식·번안)
외부 보안팀 코드 검사 전 자체 사전점검. security-audit 에이전트(+ 설정돼 있으면 SonarQube 보안 핫스팟)를 돌려 P0/P1/P2로 정리하고, 발견사항을 이슈로 쪼개 병렬 서브에이전트로 고친다. "보안 검사", "보안 점검", "코드 감사" 언급 시 사용.
스킬 실행 후 피드백을 받아 해당 SKILL.md를 자동 개선하는 메타 스킬. 스킬이 틀렸거나 누락이 있을 때, 또는 새로 배운 함정을 기록할 때 사용.
프로젝트 상태 한눈에 보기. Git 상태·빌드·테스트·최근 이슈·브랜치 현황을 한 번에 조회. 작업 시작 전 또는 상태 점검 시 사용.
Bring documentation back in line with the code after changes to behavior, paths, versions, or generated output. Use on "update the docs", "refresh the README", "docs are stale", and right before opening a PR that changed any of those. Checks each documented claim against the actu
Duplicate this file to create a project skill. Write the trigger condition concretely in the description.
Use when the user invokes /grill-me or asks to have an idea, feature request, or spec grilled, stress-tested, interrogated, or challenged before implementation. Opt-in alternative to superpowers:brainstorming — the user picks one or the other per task.
Fact-check an agent's persistent memory against ground truth — verify each memory's load-bearing claims against code, database, issue tracker and filesystem, correct the stale ones, and report dead ones as archive candidates. Use when memory grows past ~30 files, right after a bi
Full review of code changes. A wrapper skill that runs the code-reviewer agent and the security-audit agent in sequence. Use before creating a PR/MR or when a review is requested.
A workflow that searches for an existing solution (this repo → internal mirrors → package registries → MCP/skills → GitHub) before writing new code. Triggers right before adding a new feature/utility/dependency, or the moment a "add feature X" request tempts you to jump straight
Self-run security pre-check ahead of an external security-team code audit. Runs the security-audit agent (plus SonarQube security hotspots when configured), grades findings P0/P1/P2, splits them into issues, and fixes them with parallel subagents. Use on "security check", "securi
A meta-skill that takes feedback after a skill runs and automatically improves the corresponding SKILL.md. Use when a skill was wrong or incomplete, or to record a newly discovered gotcha.
See project status at a glance. Checks Git status, build, tests, recent issues, and branch status all at once. Use before starting work or when checking on status.
Imported from leeyudok/agents-scaffold/.claude/agents/README.md.
다른 서브에이전트를 실제로 써본 후 피드백을 받아 해당 agents/*.md를 자동 개선하는 메타 에이전트. 에이전트가 틀렸거나, 결과가 부실하거나, description이 실제 동작과 안 맞을 때, 또는 새로 배운 함정을 기록할 때 호출.
머지 전 코드 변경을 버그·보안·품질 관점으로 리뷰. CRITICAL 발견 시 차단 권고.
DB 스키마 변경 안전성 검증. ALTER TABLE 전 위험도 평가·롤백 SQL 생성·FK 정합성 체크. 마이그레이션 파일 추가·수정 시 호출.
기획서/이슈 기준 최소 스코프 구현 전담. 테스트 작성·실행은 하지 않음(sdlc-tester 담당). /sdlc-cycle 커맨드의 개발 단계 서브에이전트.
이슈의 AC/TC 기준 테스트 코드 작성 전담. 구현 코드 수정·테스트 실행은 하지 않음(sdlc-verifier 담당). /sdlc-cycle 커맨드의 테스트 단계 서브에이전트.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/skillopt-sleep
Skillopt sleep
Use the bundled `skillopt-sleep` skill to run or manage SkillOpt-Sleep for the
/git-ops
Git ops
Git + worktree orchestrator entry point. /git-ops --landall surveys every branch/worktree and batch-lands the ones that are done; bare /git-ops runs a status survey. Thin router over the git-ops skill.
/save
Save
Save session state - persist tasks (via TaskList), plan content, and git context. Complementary to /sync.
/sync
Sync
Session bootstrap - read project context, restore saved state, show status. Quick orientation with optional deep dive.
/models
Models
Query AI Gateway models (list, filter by provider/tag, get details)
/icon-lookup
Icon lookup
Search for icons by name, or identify a PUA character
/add-skill
Add skill
Install a pinned skill extension on demand (/add-skill <id>), or list core packs and extensions
/build
Build
Implement an approved plan or issue in its own worktree, run the gate, open the pull request.
/close-out
Close out
Close a finished session: sweep for unfinished work, ask once, land, file the follow-ups, hand off, tell the sessions that depend on this one, then archive.
/handoff
Handoff
Write the repository handoff file for the next session, and record any durable learning.
/land
Land
Merge an approved pull request, clean up its worktree and branch, then check whether a release is due.
/plan
Plan
Turn a topic or issue into a plan the reviewer approves in the native plan pane.
/research
Research
Answer a research question with parallel read-only gatherers and one synthesized digest.
/review
Review
Review the branch's diff in two fresh contexts — scope against the spec, then quality — and report findings only.
/psql-query
psql-query
Run ad-hoc PostgreSQL analytics queries against dev/test database
/techdebt
techdebt
Find and report technical debt in the codebase
/pull
Pull
Refreshes local project state from a linked Supabase project or branch in one step, instead of running `config pull`, `db pull`, `migration fetch`, and `functions download` individually. It runs four steps, always in this order: pull config into `supabase/config.toml`, optionally
/minutes-x1-send-meeting
Minutes x1 send meeting
Send one of the user's own Minutes meetings to their X1 household for review. Use when the user wants a meeting's summary, decisions, action items, and open questions to reach X1 so they can confirm what belongs in their household record. X1 asks the user to approve the send, and nothing reaches the household record until they confirm each item. Never use it for a restricted meeting, a transcript, or someone else's meeting.
/minutes-x1-send-meeting
Minutes x1 send meeting
Send one of the user's own Minutes meetings to their X1 household for review. Use when the user wants a meeting's summary, decisions, action items, and open questions to reach X1 so they can confirm what belongs in their household record. X1 asks the user to approve the send, and nothing reaches the household record until they confirm each item. Never use it for a restricted meeting, a transcript, or someone else's meeting.
/init-skill
Init skill
> **Usage:** Create a new skill from the template.
Claude Code skills for Chinese-narration recaps from supported video files, with optional editable JianYing/CapCut draft export. | 用 Claude Code skills 为支持的视频文件…
10 views 0 likesDrive the Unity Editor from an AI agent or the terminal. The Editor serves MCP itself over HTTP, so there is no second process to run, and the isuzu-unity-cli c…
4 views 0 likes面向企业的数字员工构建与运行平台:把专业员工的经验、流程与判断标准,固化为可随时上岗、可配置、可审批、可观测的 AI 数字员工。
2 views 0 likesA local-first, Pi-powered AI agent workspace for Desktop, WebUI, and CLI
2 views 0 likes660+ muapi-hosted generative-media models plus community-submitted third-party API tools (SEO, enrichment, social, scraping) — one YAML file per entry, browsabl…
6 views 0 likesA compounding agent OS for recursive agents. Also an open source alternative to Grok Bot and Meta's Muse.
6 views 0 likesIndependent desktop client for OpenCode 2. Manage projects, sessions, parallel agents, requests, and changes on Linux and macOS.
9 views 0 likesProduction agent skills for Claude Code, Cursor, and any SKILL.md harness — Codex fleets, video pipeline, monorepo review bundles, multi-chain explorer.
11 views 0 likesSee and manage what your coding assistants load — skills, commands, subagents, plugins and MCP servers, with real usage.
11 views 0 likesAn Enterprise-Grade Full-Stack RBAC Permission Management System Built with Go + React
10 views 0 likesCreate AI Agents in a No-Code Visual Builder or TypeScript SDK with full 2-way sync. For shipping AI assistants and multi-agent AI workflows.
10 views 0 likes基于 DeepSeek Harness(DSH)的稳定桌面端,集成Git、内置浏览器与记忆功能 | DeepSeek Harness desktop GUI with local workspaces, Git, browser and memory.
9 views 0 likes⚡ Control Apache Airflow with natural language via MCP. Chat with your workflows using Claude, GPT, or any LLM — no REST API calls needed. Supports Airflow 2.x…
4 views 0 likesOpen-source CLI, schemas, resolver, and DSH agent tools for DSH Plugin Hub
2 views 0 likesPi Coding Agent 中文学习蓝皮书:从安装与第一个可验收任务开始,逐步掌握 Session、Context、Skill、Extension、Subagent 与长期 Agent 工作流。
2 views 0 likesSelf-hosted framework for orchestrating fleets of specialist AI agents — ensemble reasoning and a full agentic coding pipeline, model-agnostic and local-friendl…
4 views 0 likesSelf-hosted, vendor-neutral control plane for your local coding agents (Claude Code & Codex). Run your agents, on any plane.
2 views 0 likesA practical AI agents handbook covering agent systems, agentic workflows, LangGraph, MCP/A2A, context engineering, agent memory, evaluation, observability, and…
5 views 0 likesVibe Coding 从入门到精通教程|AI 结对编程工作流|Prompt、Skill、Workflow、上下文管理、codex实战指南
3 views 0 likesStatic security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 51 rules mapped to OWASP Agentic Top 10 (2026). Works with LangC…
2 views 0 likes