LLM Mart Basic
@llm-mart · Joined Jun 2026
缺陷修复方法论唯一入口:口喷 bug 定位直修;implement-test-review 循环内的反馈修复也走本 skill(循环内分支,原 impl worker 执行)。触发:修 bug / 有个 bug / 报错了 / 行为不对 / fix / /eo-fix。 NOT FOR: 明确的业务变更(走 /eo-change)。
在 /clear 之前生成最小可恢复快照到 tmp/eo/handoff/<topic>.md,让下一个会话载入这一个文件就能从当前节点继续。优先记录任务状态、关键口径、下一步分叉,主动丢弃探索过程。触发:handoff / 存一下进度 / 我要 clear / /eo-handoff。 NOT FOR: 机械压缩对话流(用内置 /compact)。
按 change.md 的 TODO 分批落地代码,批末自验对应 AC。触发:实现 / 写代码 / implement / /eo-implement。 NOT FOR: bug 与反馈修复(口喷 bug 与 test/review/acceptance 循环内反馈一律走 /eo-fix);变更起草(走 /eo-change)。
eo 流程总控:按用户意图圈一段(入口节点 → 出口节点 → 收敛标准),把 eo-change / eo-implement / eo-archive 及可选闸门(eo-change-review / eo-test / eo-review)派发到可插拔执行基底上推进至收敛,窗口化汇报进度。触发:eo-loop / 串起来跑 / 循环推进到收敛 / 总控调度 / /eo-loop。 NOT FOR: 单点动作(直接调对应 eo-* skill);派出去不再监督的完全交接(orca-cli full handoff);bug 口喷(/eo-fix)。
eo-skills 在当前仓库的总入口:生成 .eo-project.json、初始化项目管理侧(roadmap)和代码侧最小骨架(eo-doc/),以及 agent 配置注入。触发:启动项目 / 初始化项目 / 新建项目 / /eo-project-init。
项目记忆的统一写入口:经验教训(lessons/)与关键决策(decisions/),带 INDEX 与检索锚点,供 eo-change / eo-fix / eo-recall 消费。通过 .eo-project.json 定位。触发(仅用户明确要求记录时):把这个坑记下来 / 记条经验 / lesson learned / 把这个决策记下来 / 记录决策 / reindex lessons / reindex decisions / /eo-project-record。NOT FOR: 对话提到踩坑或决策但用户未要求记录;待办类(走 /eo-bac
只读的回忆与解释入口,分层作答带出处。触发:这个功能当时怎么设计的 / 这段逻辑怎么实现的 / 当初为什么这么定 / 帮我回忆 / recall / /eo-recall。 NOT FOR: 修 bug(/eo-fix)、发起变更(/eo-change)、维护文档(/eo-doc-manager)。
按需代码审查:风险信号命中或用户点名时,对已实施代码做 AC 逐条核对 + 代码质量审查,产简版 review.md(P0/P1/P2)。触发:review / 代码审查 / 再找双眼睛看看 / /eo-review。 NOT FOR: change 方案审查(/eo-change-review,代码还没写时用);默认主路(无信号时不强制)。
按需独立测试视角:风险信号命中或用户点名时,对已实现 change 做测试审计、补缺与重验证,产简版 test.md。严禁修改业务代码。触发:找双新眼睛跑测试 / 独立验证 / 给这个 change 补测试 / /eo-test。 NOT FOR: 与 change 无关的日常跑测试或补单测(直接做即可,不产报告);默认主路的自验(归 eo-implement)。
接口级测试时使用——从 OpenAPI/Swagger 文档或用例 Schema 中可自动化的接口用例出发,覆盖参数、边界、鉴权、幂等、并发、错误响应与数据一致性,产出可执行的 API 测试脚本与运行结果;含接口压测承接(k6,类型矩阵轴 1 执行层)。不用于:Web UI 流程(automated-e2e-testing)、手动用例编写(test-case-writing)。
将手动测试用例转为 Playwright E2E 测试并执行时使用;含写自动化前的业务熟悉踩点、Page Object/Helper 编写、执行中的 Bug 证据收集与报告条目记录。不用于:纯 API 接口测试(api-testing)、以理解系统为目的的独立探索会话(exploratory-testing)、已确认 Bug 的根因分析(bug-analysis)。
对已确认的 Bug 做根因定位、影响分析、回归建议时使用——复现 → 读代码定位根因 → 影响五面分析 → 回归建议,条目(根因/影响/Severity 依据/修复建议)追加进测试报告。不用于:仅收集 Bug 证据(automated-e2e-testing / api-testing)、疑似未定性缺陷(test-case-writing 的 Cx 记录)。
qa-skills 共享知识库,安装依赖单元(非触发 skill):承载被其余 10 个 skill 以相对路径引用的方法、规则、模板与脚本(可执行性标准、证据分级、风险模型、类型决策矩阵等)。仅在 qa-skills 系列 skill 工作流中被引用读取;任何具体测试任务都不要独立触发本 skill,独立使用无意义。通过 npx skills 等安装器单独安装其他 qa-skills skill 时,必须同时安装本 skill,否则引用路径断裂。
需求不完整、系统陌生、文档不足时,发起以理解系统/发现风险为目的的独立探索式测试会话时使用——charter 驱动(目标 → 探索 → 记录),产出探索笔记(系统理解/风险清单/测试想法)作为需求建模输入或独立交付。不用于:为写自动化踩点的小规模探索(automated-e2e-testing 工作流零)、按既有用例执行(执行类 skill)。
端到端测试的唯一入口:用户说"帮我测试这个需求/功能"、"把这个功能完整测一遍"时,编排需求理解→测试策略(风险与类型决策)→用例→审查→执行→Bug 分析→回归→报告的完整流水线,产出落盘、可断点续跑。只要单阶段产出(如"帮我审一下这份用例")→ 直接用对应阶段 skill,不用本 skill。
代码变更(diff/Bug 修复/需求变更)后判断应回归哪些测试时使用——沿"改动文件 → 改动函数 → 受影响功能 → 受影响用例"分析链,基于用例 Schema 的追溯映射产出分级回归清单。不用于:用例文件本身的增量修改(test-case-writing)、长期回归策略(test-strategy)。
系统性建模某个需求/系统时使用——从 PRD、设计/API 文档、Bug、Issue、代码中提炼目标、范围、角色、规则、异常、依赖与不明确项,产出结构化需求模型(含澄清记录与用户裁决)。不用于:已有需求模型直接写用例(test-case-writing)、"怎么测"的策略决策(test-strategy)、端到端流水线(qa)。
审查已有测试用例(存量资产、他人编写、AI 产出)的覆盖与可执行性时使用——先建可测点基准,再独立评估覆盖、可执行性与正确性,直接修订用例文件并留审查记录。不用于:从零写用例(test-case-writing)、写时自审(其阶段四)、端到端流水线(qa)。
从需求文档、API 文档、Bug 报告或代码仓库产出可执行的手动测试用例(markmap)时使用——代码优先:索取仓库、先代码审查找潜在 bug 再写用例,并抽取机器可读 Schema。不用于:需求建模(requirement-analysis)、测试策略(test-strategy)、独立审查(test-case-review)、自动化脚本(automated-e2e-testing / api-testing)。
回答"这个功能应该怎么测"时使用——风险评级挂证据(Risk Map),翻译成功能域+类型域两域范围与深度:类型域十轴全轴必答(脚本扫描信号+预填修订),include挂信号、exclude挂理由、full有预算上限。不用于:已有策略直接写用例(test-case-writing)、需求建模(requirement-analysis)、端到端流水线(qa)。
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/dashboard-cockpit
Dashboard cockpit
Repeatable pass upgrading an Angular admin dashboard into a compact black-and-cyan developer-cockpit PWA
/drift-check
Drift check
Run the drift-detection checklist (incl. agent-drift signals); report + fix in-turn
/final-review
Final review
Orchestrate the final review fan-out (integration + diversity + risk + release readiness)
/improve-lint
improve-lint
Run the AI-augmented lint self-improvement loop on the current project. Scans `.lint-history/` for recurring violation patterns (≥3 hits in 30d window), drafts a Claude-ready prompt to author a new semgrep rule for the top candidate, and surfaces the proposal under `.lint-history/proposals/<ts>.md`. Non-blocking analysis. See rules/lint-doctrine.md § Self-improving.
/install-lint-stack
install-lint-stack
Bootstrap industry-leading lint+autofix+commit-hygiene stack on the current project. Drops in lefthook, oxlint, ESLint, Prettier, Stylelint, markdownlint, ruff, shellcheck, shfmt, yamllint, hadolint, actionlint, jscpd, knip, semgrep, gitleaks, commitizen + git-cz-emoji (emoji-mandatory commits), and semantic-release. Idempotent — re-runs upgrade safely. See rules/lint-doctrine.md.
/list-arcs
list-arcs
Surface all retrospective documents with key shape metrics; compare arcs deliberately.
/multimedia-enrich
Multimedia enrich
Progressive multimedia enrichment pass — add high-value audio/video/image/interactive to a site, run again and again
/plan-execute-verify-repair
Plan execute verify repair
Run the autonomous-engineering operating loop on a task (plan→implement→verify→repair→report)
/post-arc-retrospective
Post arc retrospective
Capture the cumulative output of a /loop arc into a single auditable retrospective document; scans the heymegabyte-claude-skills plugin for modified files, categorizes by directory, counts LOC delta, extracts tool counts from MCP servers, and writes a timestamped report to retrospectives/
/prepare-multi-file-brief
prepare-multi-file-brief
Turn a comma-separated list of file paths into a fully structured Pattern A agent brief — ordered writes, per-file schemas, and a verification step baked in.
/prepare-skeleton-brief
prepare-skeleton-brief
Turn Pattern B from agent-resilience-discipline into a one-keystroke agent brief for a single-file deliverable < 300 lines.
/process
Process
Chain the full Superpowers process flow — brainstorm → plan → worktree → build → review → finish — on one slash command
/retro
Retro
Generate a timestamped arc retrospective from the past 7 days of git history in `~/.agentskills`.
/review-global-prompts
Review global prompts
Review ~/.claude/CLAUDE.md + rules for contradictions, stale guidance, duplication; consolidate
/run-evals
Run evals
Batch-run all LLM eval cases in tools/evals/cases/*.json; aggregate pass/fail, cost, regression vs last run; exit nonzero in CI mode
/saas
Saas
One-line SaaS — from a description, scaffold a complete CF-native multi-tenant SaaS (Hono + D1 + Drizzle + Better Auth + Stripe + shadcn) deployed to a real URL
/security-supply-chain
security-supply-chain
Unified supply-chain audit. Checks GitHub Actions SHA-pinning (`sha-pin:check`), package.json git+https deps (per `no-gitlab-megabytelabs-deps` semgrep), gitleaks scan, and trufflehog verified-only sweep. Surfaces any tag-mutable, git-URL, or secret-exposed surface. Per rules/ai-agent-security.md § Supply chain.
/self-improve
Self improve
Run a learning pass after a major run; fold reusable lessons into global config
/session-recap
session-recap
Summarize recent CHANGELOG.md entries for context restoration. Parses the canonical heading shape `## YYYY-MM-DD — pass-N — summary`. Filters: last N (default 10), YYYY-MM date prefix, or "today". Supports --json for machine-readable output.
/skill-health
Skill health
Run quality-scores + token-budget + dep-graph, interpret results, flag missing budgets, orphans, and oversize skills
PiG (Pi in Go) is a faithful Go port of upstream Pi, the TypeScript codebase behind the Pi coding agent. It is a parity-bound translation, not a rewrite: upstre…
2 views 0 likesAn AI Agent that lives in your pocket. Local-first and privacy focused.
3 views 0 likesUnofficial skill that teaches coding agents to build with TypeSafe AI's Jev: typed decisions, calibrated confidence, and prior art from 150+ community projects.
6 views 0 likesAdaptive Test-time Learning and Autonomous Specialization
4 views 0 likesPrediction-market trading engine — Wang Transform pricing on 291K+ contracts; paper-traded across Kalshi · Polymarket · Solana DFlow (Jito bundles) · 633 tests
3 views 0 likesKnowledge Management for Humans and Agents
5 views 0 likesOpen-source Claude Cowork / Codex / WorkBuddy alternative — a local-first AI office agent that turns one request into real PPTX, DOCX, XLSX and HTML files. Runs…
5 views 0 likesDeepAgent Code: AI coding agent with persistent memory and control plane
4 views 0 likesAwesome Jev — evidence-graded index of TypeSafe System One: SDKs, MCP tools, agents, apps and open models. 20 languages, rebuilt every 2 hours.
5 views 0 likesCLI for Telegram — agent-friendly, daemon-based, with webhook event push.
5 views 0 likesAI deep-research agent that turns any question into a cited report: plans searches, reads real sources, verifies evidence. Self-hosted, multi-provider, Docker-r…
4 views 0 likesEvent-stream AI Agent framework for building your persona bot 🍊
1 views 0 likesGive the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops t…
3 views 0 likesLocal Emperor-style AI agent with Vue WebUI, multi-provider LLMs, streaming chat, tools, skills, memory, and token telemetry.
2 views 0 likesOpen-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware researc…
8 views 0 likes"Never send a human to do a machine's job" - Open Source AI hacking agent
3 views 0 likesPrismer Cloud
3 views 0 likesMy Personal Blog (Robotics)
3 views 0 likesTau Coding Agent - like Pi, but twice as much
1 views 0 likesOpen-source alternative to OpenAI Dots: self-hosted AI chat, tools, approvals, connectors, and computer tasks.
0 views 0 likes