LLM Mart Basic
@llm-mart · Joined Jun 2026
State-of-the-art secrets management for building and auditing software. Use whenever a task involves creating, storing, injecting, rotating, or scanning for credentials — or reviewing code/infrastructure for secret leaks and misuse. BUILD mode: implementing secrets handling; AUDI
State-of-the-art security & compliance engineering (2026) for the cybersecurity control frameworks and product-security regulations that drive architecture, code, and CI gates — not the organizational policy binder. Use when work must satisfy or be audited against NIST CSF 2.0, S
State-of-the-art shell scripting (bash-focused, defensive) for writing and auditing shell scripts, CI scripts, init/deploy scripts, container entrypoints, and Makefile recipes — and, just as much, for the ad-hoc commands you run yourself: a grep/find/rg sweep whose result you are
State-of-the-art software testing strategy and practice (2026) for designing test strategy, writing unit/integration/e2e tests, or auditing test suites. Covers suite shape (pyramid/trophy/honeycomb), test design quality (behavior-first, AAA, determinism, smells), test doubles (mo
State-of-the-art threat modeling for both designing new systems and auditing existing ones. Use when designing a feature, service, integration, or architecture that touches untrusted input, new trust boundaries, sensitive data, or third-party dependencies (BUILD mode), and when r
State-of-the-art UX writing and product-copy guidance (2026) covering voice and tone systems, plain language (ISO 24495-1), microcopy (buttons, labels, empty states, onboarding, notifications), error and feedback message craft, and the accessibility and localization of interface
State-of-the-art engineering rules (2026) for the JavaScript SSR meta-frameworks: React 19 + Next.js (App Router, React Server Components, Server Actions) and Vue 3 + Nuxt 4 (Nitro server routes, composables) — plus the cross-cutting concerns of server rendering: hydration correc
Give this repo's CLAUDE.md / AGENTS.md a checkup — size vitals vs official guidance, dead references, dead commands, stale claims — then backtest every rule against the repo's own Claude Code session history to see which rules were actually followed, ignored, or never used, and p
Example skill loaded from resources_discover
Creates implementation plans from context and requirements
Code review specialist for quality and security analysis
Fast codebase recon that returns compressed context for handoff to other agents
General-purpose subagent with full capabilities, isolated context
Git-backed control plane for AI-agent skills, tools, context, permissions, and identity. Self-hosted and MCP-native.
在 WorkBuddy 中下载并配置 dsh-plugin-garmin-connect npm 包,通过 MCP 工具分析 Garmin 活动、睡眠、步数、心率、体重、训练库、跑步趋势和有限的恢复信息,也可按用户要求创建 Garmin 训练或下载活动 FIT 文件。适用于 Garmin 配置、回顾、比较和明确授权的写操作;不用于医疗诊断。
GitHub Actions, required checks, TestMu, OS matrix, and merge gates for Skill Doctor. Use when editing workflows, adding CI jobs, deciding what runs on every commit, or wiring crates/npm publish.
Skill Doctor CLI UX, flags, exit codes, text/JSON/SARIF reports. Use when changing clap, printers, GitHub Action inputs, or CI gate flags.
SD-11 scanner-mediated injection — neutralize untrusted skill bytes before any model; additive-only scoring. Use when touching L2, MCP, prompts, envelopes, or scoring merge.
Skill Doctor product and architecture context. Use at the start of a session, when deciding where code lives, when the user asks how the scanner works, or before any non-trivial change.
Pre-publish and publish path for crates.io, npm installer, GitHub Releases, SBOM. Use when cutting versions, editing release.yml, or adding publish steps. Never publish from a feature branch.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/show-ticket
Show ticket
Display comprehensive ticket information including history, actions, and related entities
/sla-dashboard
Sla dashboard
View SLA status across tickets, including approaching breaches and at-risk tickets
/update-ticket
Update ticket
Update fields on an existing HaloPSA ticket including status, priority, and assignment
/create-deal
Create deal
Create a new deal in HubSpot with company association
/log-activity
Log activity
Log a note or create a task on a HubSpot contact, company, or deal
/lookup-company
Lookup company
Find a HubSpot company by name or domain and show associated contacts and deals
/pipeline-summary
Pipeline summary
Summarize the HubSpot deal pipeline - deals per stage, total value, and expected close dates
/search-contacts
Search contacts
Search HubSpot contacts by name, email, or company
/search-deals
Search deals
Search HubSpot deals by name, stage, or company
/find-company
Find company
Find a company in Hudu by name
/get-password
Get password
Retrieve a password from Hudu (with security logging)
/lookup-asset
Lookup asset
Find an asset in Hudu by name, hostname, serial number, or IP address
/search-articles
Search articles
Search Hudu knowledge base articles by keyword or phrase
/agent-inventory
Agent inventory
List and filter Huntress agents across organizations
/billing-report
Billing report
Generate a Huntress billing summary for a period
/incident-triage
Incident triage
Triage open Huntress incidents by severity
/investigate-incident
Investigate incident
Deep dive investigation into a specific Huntress incident with remediations
/org-health
Org health
Organization health check covering agents, incidents, and escalations
/resolve-escalation
Resolve escalation
Review and resolve a Huntress escalation
/compliance-report
Compliance report
Generate an ImmyBot software-compliance scorecard for a tenant or the whole fleet
Ultra-lightweight, open-source, self-hosted personal AI agent framework in Python with WebUI, tools, memory, MCP, multi-agent workflows, automation, and chat ap…
29 views 0 likesGovernance framework for AI coding agents. It runs them through a five-step workflow (plan, build, review, test, ship) where no step counts as done without evid…
17 views 0 likesUltimate Multi-Agent OS for Autonomous AI NPCs 2026
15 views 0 likesPersonal AI Agent Hub 2026 — Build Your 24/7 Autonomous Assistant
26 views 0 likesProven 2026 Multi-Agent AI Review System – Verdict-Driven Quality Control
29 views 0 likesSlash API Batch: Cut AI Costs by 50% in 2026
16 views 0 likesWeb dashboard for Hermes Agent — multi-platform AI chat, session management, scheduled jobs, usage analytics
19 views 0 likesAgent Skills for Solopreneurs
31 views 0 likesAirLLM dramatically reduces inference memory usage, letting 70B large language models run on a single 4GB GPU card
144 views 0 likesZero, your trustworthy AI teammate for real work.
16 views 0 likes一套 DSH runtime,Desktop、Web 与 TUI 三种开发体验。
12 views 0 likesOpen-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations.
17 views 0 likes⚙️ TypeScript Style Guide and Agent Skill. A concise set of conventions and best practices for consistent, maintainable code.
28 views 0 likesFramework for AI agents to build and maintain a digital brain through Obsidian wiki
17 views 0 likesApache Maka (Incubating) is a local-first AI agent workspace. Model messages, tool calls, tool results, permission decisions, and termination events are recorde…
25 views 0 likesNeo.mjs is a self-evolving software organism: a professional end-to-end AI engineering team whose cross-model swarm inhabits live apps via Neural Link, Active H…
25 views 0 likesAgentic development harness for Claude Code — SPEC-driven plan/run/sync, TRUST 5 quality gates, model+effort routing, and Claude×GLM multi-LLM cost control. Sin…
19 views 0 likesNocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of productio…
27 views 0 likesAn open-source AI coding agent that lives in your terminal.
29 views 0 likesPawWork — free, open-source desktop AI agent for macOS and Windows. Alternative to Codex App and Claude Cowork. BYOK with 75+ providers, ChatGPT OAuth, local mo…
16 views 0 likes