LLM Mart Basic
@llm-mart · Joined Jun 2026
Merge multiple partial requirements YAML files from different readers into one consolidated req.yaml. Detects field conflicts between sources, identifies critical gaps, and produces a gap report. Run after all readers, before the gap-filling interview in arch-requirements.
Architecture committee review. Evaluates a diagram or design document against enterprise standards with structured scoring per dimension. Produces a gate decision: APPROVED / APPROVED WITH CONDITIONS / REJECTED. Use when: preparing for architecture review board, requesting commit
Deep-dive security audit of a technical architecture diagram. Focused exclusively on authentication, authorization, credential protection, network boundaries, and data classification. Does NOT score overall quality — produces a prioritized security finding list. Use after arch-va
Validate a technical architecture diagram image against enterprise architecture standards. Scores six dimensions (10 pts total), outputs structured JSON + text report. Use when: reviewing a draw.io export, checking a new design before committee review, or running CI validation on
Pipeline gatekeeper that enforces the mandatory ArchHarness stage order (requirements -> design -> draw -> validate -> enforce -> security/review -> optimize -> report). Uses the executable `archharness workflow` state machine — checks recorded manifests and gate decisions before
Use when establishing branching strategies, implementing Conventional Commits, creating or reviewing PRs, resolving PR review comments, merging PRs (including CI verification, auto-merge queues, and post-merge cleanup), managing PR review threads, merging PRs with signed commits,
Set up, evolve, or operate a hraness/wordcell local-first Markdown knowledge base for coding-agent memory. Use when a user asks to design Wordcell conventions or a recurring Wordcell ritual; search or query a Wordcell or Obsidian vault; load or recover repository context, plans,
End-to-end reviewer for a completed multi-phase feature at the end of a phase-orchestrator run. Use after all requested phases are finalized: inspects the whole feature against the plan and PRD/spec, hunting integration bugs across phase boundaries, missing acceptance criteria, s
Implements exactly one phase of a multi-phase plan during a phase-orchestrator run. Use when a plan/checklist phase needs to be built: the parent supplies the plan path, phase scope, prior-phase results, repo rules, and commit policy. Edits files directly; never commits unless co
Orchestrates phase-based implementation plans using the host's todo tracker and subagents for implementation, review, validation, default phase commits, plan finalization, and a final end-to-end review. Delegates work through the companion phase-implementer, phase-reviewer, and p
Reviews and fixes a just-implemented phase of a multi-phase plan during a phase-orchestrator run. Use after a phase's implementation and initial validation: checks the phase against the plan, PRD/spec, repo conventions, security, tenancy/data ownership, migrations, and test cover
Writes or restructures an implementation plan in the format the phase-orchestrator skill consumes: dependency-ordered phases with explicit scope, acceptance criteria, validation commands, and status/log conventions. Use when the user asks to write a plan for phase orchestration,
Build a complete account sheet before a meeting - company, people, news, tech, pains, and talking angles. Use before any important prospect or client interaction.
Produce complete ad creative sets - concepts, hooks, copy, AI-generated images and videos declined per platform and format. Use for Meta, Google, LinkedIn, TikTok campaigns and product launches.
Choose the right depth of reasoning for the task - shallow for routine edits, deep for architecture, security, or ambiguous bugs. Use when work quality depends on thinking harder (or intentionally less).
Read OpenAPI specs, call APIs, validate responses, and draft connectors. Use for integration work, contract testing, and client generation.
Audit the web/API attack surface - authn/authz on endpoints, CORS, CSRF, SSRF, security headers, rate limiting, mass assignment, and OWASP API Top 10. Use for /perimeter, API reviews, or exposed-surface hardening.
Track job applications - statuses, follow-ups, interviews, and reminders - in a structured pipeline. Use to keep a job search organized.
Default Navin skill for architecture and technical diagrams. Create polished, validated architecture, workflow, sequence, data-flow, and lifecycle diagrams as explorable HTML with inline SVG (PNG/SVG/WebM export). Use for system architecture, infrastructure topology, PPT/deck dia
Score CV-to-job-offer match, identify missing keywords, and check ATS parseability. Use before submitting any application.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/attach
Attach
`crabbox attach` follows the recorded events of an active coordinator run and
/azure
Azure
`crabbox azure` groups Azure provider setup commands. It currently has a single
/bench
Bench
`crabbox bench` records and reports local benchmark timing observations. It is a
/cache
Cache
`crabbox cache` inspects, purges, or warms package and build caches on a
/capsule
Capsule
`crabbox capsule` captures, replays, and tracks lightweight failure capsules.
/checkpoint
Checkpoint
Save the state of a lease, then restore it onto another box or fork it into a
/claims
Claims
`crabbox claims list` prints the lease claims stored on the current machine. It
/cleanup
Cleanup
`crabbox cleanup` sweeps direct-provider machines and local provider state that
/code
Code
`crabbox code` bridges a Linux lease's `code-server` workspace into the
/config
Config
`crabbox config` inspects and updates user configuration. It has three
/connect
Connect
`crabbox connect` resolves a lease and opens an interactive SSH session to it.
/cp
Cp
`crabbox cp` copies files or directories between the host and a Crabbox-owned
/desktop
Desktop
`crabbox desktop` drives a visible desktop session on a lease that was warmed
/doctor
Doctor
`crabbox doctor` runs a preflight before you commit to a long workflow. It is
/egress
Egress
`crabbox egress` gives a lease mediated outbound network: a lease-local browser
/events
Events
`crabbox events` prints the broker's event log for a recorded run.
/heartbeat
Heartbeat
`crabbox heartbeat` refreshes the idle deadline for one owned lease and prints
/history
History
`crabbox history` lists recorded remote command runs from the broker. Each run is
/image
Image
`crabbox image` holds the trusted-operator controls for provider base images:
/init
Init
`crabbox init` onboards the current repository: it writes the minimal config
Atom Agent, Open-Source Governed AI Agent Platform for Self-Hosted Automation
12 views 0 likesThe agent engineering intelligence harness, optimized tools, memory system, subagents and mixture of models packages ⚚
16 views 0 likesSesori iOS/Android app and the Sesori Bridge CLI — drive Claude, Codex, OpenCode, Cursor, Pi, OMP, Hermes coding sessions from your phone
14 views 0 likes🧠 RepoBrain (formerly Antigravity) — Give your repo a brain. ChatGPT for your codebase: works in Claude Code, Cursor, Codex, Windsurf & more.
14 views 0 likesUse ChatGPT (Codex), Claude, and Grok (X Premium) subscriptions as DeepSeek Harness LLM providers — OAuth login in the web UI, no API keys
15 views 0 likesLatitude is the open-source AI monitoring platform.
16 views 0 likesOpen-source AI browser agent for Chrome and Firefox (monorepo) 🧠
16 views 0 likesOfficial Model Studio CLI(阿里云百炼 CLI)built for AI Agent frameworks, exposing models, search, multimodal, and workflow capabilities as structured tool calls.
15 views 0 likesCurated DeepSeek Harness (DSH) plugins, extensions, tools, skills, clients, runtimes, integrations, and verified references — English and Chinese.
16 views 0 likesTurn papers, code, and docs into presentation-ready, natively editable PPTX in Codex / Claude Code. Native charts and equations, speaker notes, click-build anim…
14 views 0 likesGrix : Work with agents like talking to people.
25 views 0 likesLocal First Ai Agent. Optimized for Local Ai models. Long context window. Proper tools callings. Runs privately on your device.
26 views 0 likesModel Context Protocol server that integrates AgentQL's data extraction capabilities.
15 views 0 likesAI that ships your tickets.
14 views 0 likesMetadata-driven CLI for AI Agent Bots — 48 operations across 7 domains, structured JSON envelope I/O, zero interactive prompts.
12 views 0 likesAn open-source, extensible, self-hosted agent workspace with multi-runtime support for Codex, Claude Code, and more, plus reusable local apps for custom interfa…
14 views 0 likesOpen-source Windows desktop client and GUI for DeepSeek Harness — zero-setup installer with Codex, plugins, skills, SSH, mobile remote access, and 11 skins.
12 views 0 likesThe open-source AI workbench for scientific research
15 views 0 likesDeepSeek-native AI coding agent for your terminal. Engineered around prefix-cache stability — leave it running.
15 views 0 likesA Fully free agentic browser driver for AI , few tools, full control, real stealth, top-tier token efficiency.
12 views 0 likes