LLM Mart Basic
@llm-mart · Joined Jun 2026
Find footguns in code that already exists: swappable arguments, silent fallbacks, unguarded deletes, signatures that are easy to misuse. Use when someone asks "what could bite us here", "what is easy to misuse", "poka-yoke this repo", or wants a diff or PR reviewed for ways to ge
Multi-tenant isolation, IDOR and row-level security. Use to find every path where one tenant could read or write another tenant data: "we forgot to filter by org_id", "can users see each other data", "audit these endpoints for cross-tenant leaks", "make an unscoped query impossib
Pipelines, warehouses, dbt models and metrics, where failure is silently wrong numbers rather than a crash. Use when "the dashboard is wrong", "the numbers do not match", "add data quality checks", "safe backfill", or an upstream schema change broke a join. Covers freshness, row-
Design APIs, schemas, types and state machines so misuse cannot be expressed. Use when writing a new interface and someone asks "what should the types look like", "make invalid states unrepresentable", "so callers cannot screw it up", or wants illegal state transitions rejected.
Pre-commit hooks, CI gates, lint rules, database constraints and branch protection. Use when a rule needs enforcing rather than documenting: "set up enforcement", "unformatted or untyped code must not get merged", "gate this in CI", "we agreed to X and people still do not", "stop
AI features you ship to users: structured output, tool schemas, prompt injection, evals. Use when "the model returns bad JSON", "it hallucinates", "stop it calling the wrong tool", "add evals", or an LLM feature can trigger refunds, emails or writes. Covers schema-constrained out
Deploys, schema migrations, rollback and infrastructure. Use when "can I ship this on Friday", "this migration is scary", "what is the blast radius", "prevent accidental deletion of the database", or a change drops a column. Covers expand/contract, canary rollout, kill switches,
Mistake-proofing for anything: code, config, a schema, a process, a runbook, a form. Use when someone says "poka-yoke this", "mistake-proof it", "make this harder to get wrong", or runs /poka-yoke with no mode named. Applies Shigeo Shingo's method directly to any subject, and han
Turn a bug, outage or repeated mistake into a device that makes the whole class impossible. Use when something already broke: "make sure this never happens again", "this is the third time", "postmortem", "how did this get through". Root-causes to the missing constraint, then swee
Forms, destructive actions and flows users get wrong. Use when "users keep deleting the wrong thing", "add a confirmation dialog", "this flow is error-prone", or building a delete, bulk action, checkout or settings page. Covers undo over confirmation, type-to-confirm, safe defaul
Reviewing code that already exists for structural problems: responsibilities that have drifted together, names that no longer describe what they name, dependencies pointing the wrong way, and duplication that has hardened into divergence.
Permission and access-control code. Structure, clarity and testability of authorisation logic: where the decision lives, how it is named, and keeping it separable from the code that acts on it.
Software quality review and design guidance for any code: naming, cohesion, coupling, duplication, function size, dependency direction, and testability. Use when someone asks to improve, review, refactor, or design code, or asks what good structure looks like here. Routes to the
Designing a new interface, module, schema or type. Naming, cohesion, parameter shape, dependency direction and testability, decided before the thing has callers.
Something broke. Deciding what to change in the code so the class of problem is less likely, and writing it up so the next person understands the reasoning rather than just the outcome.
Forms, flows and screens. Structure, naming and clarity of user-facing interaction code: component boundaries, state ownership, and keeping presentation separable from the rules behind it.
Reviewing existing code for unchecked inputs, unguarded dereferences, unhandled failure paths, swallowed exceptions, missing timeouts and absent limits: the places where an unexpected value becomes an unhandled failure.
Defensive programming for any code: validating inputs at every boundary, checking for null and absent values, supplying safe fallbacks, catching and logging exceptions, and degrading gracefully rather than failing. Use when someone asks to make code robust, resilient, safer, or h
Designing a new interface, module, schema or type together with its validation and failure behaviour: what each input accepts, what happens when it does not, and what the caller gets back when something goes wrong.
微信读书读后感写作助手。帮助用户基于某本书或某个章节,生成一篇带有个人见解的读后感,正文严格控制原文摘抄,附录完整保留所有划线内容及即时感想。底层依赖 weread-skills(微信读书原子 API)和 huashu-weread-advisor(微信读书高阶顾问工作流)。当用户说「写一篇读后感」「帮我整理笔记写感想」「这本书/这章我想写篇公众号文章」时触发。
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/sector-overview
Sector overview
Sector overview — TAM estimation, competitive concentration (HHI), regulatory landscape
/supply-chain
Supply chain
Supply-chain map — supplier/customer dependency, geographic concentration, bottleneck identification
/currency-analysis
currency-analysis
Currency Analysis — macro strategy analysis
/macro-regime
macro-regime
Macro Regime — macro strategy analysis
/rate-cycle
rate-cycle
Rate Cycle — macro strategy analysis
/3-statement
3 statement
3-statement integrated financial model — IS/BS/CFS triangulation, 5 historical + 5 forecast years
/audit-xls
Audit xls
Audit an Excel workbook — formula errors, hardcoded cells, calculation arc cross-validation
/comps
Comps
Trading comps analysis — peer-group selection, trading-multiple triangulation, implied-valuation range
/dcf
Dcf
DCF valuation model — 5-10 year projection, WACC construction, sensitivity tables
/earnings-preview
Earnings preview
Earnings preview presentation — 4-6 slide deck with consensus estimates, historical surprises, forward catalysts
/lbo
Lbo
LBO model — sources & uses, debt schedule, exit-multiple analysis, sponsor IRR sensitivity
/pitch-deck
Pitch deck
Investment thesis pitch deck — 12-16 slide presentation with sourced footers
/sotp-valuation
Sotp valuation
Sum-of-the-parts valuation — segment-level multiples, conglomerate discount analysis
/xlsx-financials
Xlsx financials
XBRL-to-Excel — proper number formatting, frozen headers, named ranges, calculation arc cross-validation
/income-strategies
income-strategies
Income Strategies — options and derivatives analysis
/options-foundations
options-foundations
Options Foundations — options and derivatives analysis
/technical-execution
technical-execution
Technical Execution — options and derivatives analysis
/volatility-trading
volatility-trading
Volatility Trading — options and derivatives analysis
/long-short-equity
long-short-equity
Long Short Equity — portfolio strategy analysis
/portfolio-hedging
portfolio-hedging
Portfolio Hedging — portfolio strategy analysis
Open‑WebUI Tools is a modular toolkit designed to extend and enrich your Open WebUI instance, turning it into a powerful AI workstation. With a suite of over 15…
26 views 0 likesThe token-efficient agentic coding workbench. Built for a future where every token counts — it optimizes token usage at the agent-loop level, saving 70%+ on lon…
16 views 0 likesMCP server for controlling a real iPhone via macOS iPhone Mirroring...and any MacOs app. Screenshot, tap, swipe, type — from any MCP client.
10 views 0 likesOne desktop for all your AI coding Agent — Claude Code, Codex CLI & Gemini CLI. Auto-detect, one-click install, unified chat, file explorer, terminal & editor.…
21 views 0 likesPi — A cross-platform AI coding agent, bringing the Claude Code experience to your desktop. No environment setup, no terminal commands. Download and start codin…
12 views 0 likesDeepSeek Harness Desktop (dsh-desktop). EAC: Embracing All Creation (揽尽万象). Bundled Node.js runtime with full dsh-CLI kernel, one-click startup, 10 built-in UI…
13 views 0 likesA telegram bot for searching and auto-saving.
13 views 0 likes金蝶云星空 K3Cloud MCP Server,让 AI 助手(Claude Desktop、Claude Code、Cursor、Cline、Cherry Studio、Openclaw 等任意支持 MCP 协议的客户端)通过自然语言查询和操作金蝶 ERP 系统。
19 views 0 likesRewrite frontier research using allegorical structural mapping.
13 views 0 likesFree4Chat is a temporary collaboration fabric for Humans and Agents.
11 views 0 likesGive any AI agent a full desktop — it sees the screen, clicks, types, and runs apps like a human. Automate anything with a UI: browsers, legacy software, intern…
11 views 0 likesA personal AI agent that can work safely on your machine, remember useful context, and keep its data under your control.
11 views 0 likesA framework for AI-driven economic activity. Declarative, composable, observable, deterministic.
12 views 0 likesOpen-source, self-hosted customer support desk in a single binary. A lightweight alternative to Intercom, Zendesk, Chatwoot.
13 views 0 likes54 rigorous skills for Codex, OpenCode, and Pi: code review, security audit, feature development, frontend design, MCP tools, Hugging Face ML/training, and more…
18 views 0 likesA wonderful list of Game Development resources.
11 views 0 likesOpen Science Desktop — local-first, model-agnostic AI research workbench for macOS, Windows & Linux. Open-source Claude Science desktop alternative built on Tau…
11 views 0 likesLexora — Personal AI workspace built around Desktop / 以 Desktop 为核心的个人 AI 工作台
11 views 0 likesOpen-source, AI-native Evernote alternative with native MCP. Zero-cost on Cloudflare or self-hosted with Docker.
11 views 0 likesFull job-hunt Claude skill bundle — Job Description decoder + Resume builder (11 templates) + Behavioral Interview / story bank. Three self-contained sub-skills…
11 views 0 likes