LLM Mart Basic
@llm-mart · Joined Jun 2026
Build and evaluate RAG corpora - ingest, chunk, embed, index, and spot-check retrieval quality. Use when creating knowledge bases for agents.
Listed real-estate skill for the Trading Agent OS. REITs and foncières by country. No invented listing prices.
Assemble recurring or one-off business reports - data, charts, narrative, and formatted output (PDF/DOCX/Markdown) - from multiple sources. Use for weekly/monthly reports and study deliverables.
Respond to RFPs, RFQs, tenders, and cahiers des charges - compliance matrix, requirement mapping, and structured answers. Use for formal procurement responses.
Run RiskLens on any plan, launch, product, hire, strategy, or decision. Assumes it already failed 6 months from now and works backward to find every reason why. Produces a revised plan with blind spots exposed. Use for /risklens, "run risklens", "risklens this", "what could kill
Prepare salary and package negotiation for a specific offer - market range, anchors, counters, and email drafts. Use before answering a recruiter on compensation.
Generate sales offers, quotes, and commercial proposals with pricing options and decision-ready framing. Use when a qualified prospect asks "send me something".
Orchestrate any web scraping job to delivery - static, paginated, infinite-scroll, mass crawl, sitemap, JS pages via browser. Export datasets until done.
Write scrapers with the official Scrapling 0.4.14 API (Fetcher, StealthyFetcher, DynamicFetcher, sessions, Spider templates, adaptive CSS). Default framework in the Scraping module. Fall back to the scrape tool or browser only when Scrapling is the wrong tool.
Handle secrets safely via env vars, Vault, AWS Secrets Manager, or encrypted stores - never paste keys into chat, commits, or logs. Use when configuring APIs, CI, or cloud credentials.
Hunt for leaked credentials - hardcoded API keys, tokens, private keys, passwords and connection strings in code, config, logs and git history. Use for /unmask, pre-commit secret sweeps, or "did we leak a key?" questions.
Run a full application security audit - auth flows, input validation, secrets handling, injection surfaces, dependency risks, and hardening. Use for /fortify, pre-release security reviews, or "is this safe?" questions.
Recover from tool failures and flaky commands with intelligent retries, alternate tools, and clear fallbacks. Use when exec, network, or MCP calls fail mid-task.
Write search-optimized articles that read naturally - proper structure, intent match, and internal links, without keyword stuffing. Use for blog posts, guides, and landing page copy.
Pull real SEO metrics (search volume, keyword difficulty, SERP, backlinks) from DataForSEO or Semrush when API credentials are present. Use before inventing volumes; fall back to qualitative methods when keys are missing.
Track rankings, traffic signals, technical errors, and competitor changes over time, with scheduled checks and alerts. Use to maintain SEO performance after fixes.
Audit technical SEO - indexation, sitemap, robots.txt, Core Web Vitals hints, redirects, canonical tags, and crawl errors. Use when a site underperforms in search or before a relaunch.
Run shell commands with strict limits - prefer workspace sandbox, avoid privileged ops, and quote unsafe output. Use whenever exec is required.
Create or update AgentSkills. Use when designing, structuring, or packaging skills with scripts, references, and assets.
Audit a skill package before install or enable - permissions, network calls, credential access, obfuscation, and suspicious system commands. Use before trusting ClawHub or third-party SKILL.md files.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/icon-lookup
Icon lookup
Search for icons by name, or identify a PUA character
/add-skill
Add skill
Install a pinned skill extension on demand (/add-skill <id>), or list core packs and extensions
/build
Build
Implement an approved plan or issue in its own worktree, run the gate, open the pull request.
/close-out
Close out
Close a finished session: sweep for unfinished work, ask once, land, file the follow-ups, hand off, tell the sessions that depend on this one, then archive.
/handoff
Handoff
Write the repository handoff file for the next session, and record any durable learning.
/land
Land
Merge an approved pull request, clean up its worktree and branch, then check whether a release is due.
/plan
Plan
Turn a topic or issue into a plan the reviewer approves in the native plan pane.
/research
Research
Answer a research question with parallel read-only gatherers and one synthesized digest.
/review
Review
Review the branch's diff in two fresh contexts — scope against the spec, then quality — and report findings only.
/psql-query
psql-query
Run ad-hoc PostgreSQL analytics queries against dev/test database
/techdebt
techdebt
Find and report technical debt in the codebase
/pull
Pull
Refreshes local project state from a linked Supabase project or branch in one step, instead of running `config pull`, `db pull`, `migration fetch`, and `functions download` individually. It runs four steps, always in this order: pull config into `supabase/config.toml`, optionally
/minutes-x1-send-meeting
Minutes x1 send meeting
Send one of the user's own Minutes meetings to their X1 household for review. Use when the user wants a meeting's summary, decisions, action items, and open questions to reach X1 so they can confirm what belongs in their household record. X1 asks the user to approve the send, and nothing reaches the household record until they confirm each item. Never use it for a restricted meeting, a transcript, or someone else's meeting.
/minutes-x1-send-meeting
Minutes x1 send meeting
Send one of the user's own Minutes meetings to their X1 household for review. Use when the user wants a meeting's summary, decisions, action items, and open questions to reach X1 so they can confirm what belongs in their household record. X1 asks the user to approve the send, and nothing reaches the household record until they confirm each item. Never use it for a restricted meeting, a transcript, or someone else's meeting.
/init-skill
Init skill
> **Usage:** Create a new skill from the template.
/quality-gate
Quality gate
> **Usage:** Run before every commit to ensure code quality.
/validate-skill
Validate skill
> **Usage:** Validate skill files for correctness, completeness, and quality.
/optimize
Optimize
credo - Run the optimisation audit for this repo (opt-in, read-only scan, findings offered one by one)
/peer-lan
Peer lan
credo - Start, stop, or check the LAN peer relay (cross-machine peer messaging, no cloud)
/film-review
film-review
Measure a launch film (a reference to match, or your own render) at its native frame rate and review it against its register. Returns the launch-video-review rubric table plus a per-film JSON.
Open-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-model, multi-channel. Lightwei…
10 views 0 likesOpen-source AI browser agent for web automation: a web browsing agent and computer-use agent in plain English. Browser MCP for Claude Code and Gemini CLI.
9 views 0 likesAgent-native trading terminal built on DeepSeek Harness. Crypto, US, CN and HK in one three-column GUI, 19+ hot-swappable connectors, dry-run by default with hu…
11 views 0 likesOpen-source desktop and web coding agent with a first-party host and harness, durable sessions, model connections, streaming chat, and workspace tools.
8 views 0 likesOrcaReplay — Time travel for AI agents. Record, replay, fork, and debug any agent run with any model. Built by the OrcaRouter.ai team.
8 views 0 likesA complete toolkit for connecting R and LLMs
9 views 0 likesOpenSRE — the memory-first AI SRE. Self-hosted incident investigation with episodic memory, knowledge graph, web console, Slack & Teams. opensre.in
11 views 0 likesA desktop AI coding assistant that works with your local projects. Ally helps you understand code, edit files, search a workspace, manage tasks, and complete de…
9 views 0 likes【在线免费使用】 简单快速将SQL或DBML转换为美观的ER图(支持 Agent Skill)/ The best SQL to ER Diagram converter (Support Agent Skill).
11 views 0 likesOperation-bound protection for autonomous AI agents: contain and verify operations before committing changes, understand intent and risk across long-running wor…
8 views 0 likesLocal-first AI coding agent desktop: Electron + Rust host core + pi Agent Harness + user-installable plugins
10 views 0 likesLocal-only Go static analysis engine with a built-in MCP server. Gives AI coding agents deterministic structural awareness: call graphs, impact analysis, symbol…
18 views 0 likesSelf-hosted AI agent workspace with tool calling, MCP, multi-model routing, sandboxed execution, multi-agent workflows, and LLM-authored 3D character animation…
16 views 0 likesAutomated TDD enforcement for Claude Code
12 views 0 likesHigh-performance platform for building websites, e-commerce, and web applications—with Native AI, JavaScript development, and a marketplace for portable sites a…
13 views 0 likesAutonomous AI-agent orchestration engine for job discovery with decision traces, tool adapters, and production-grade run control.
9 views 0 likesToken efficient Claude Code full Python rebuild. AI Coding Agent in 310K LoC Python.
13 views 0 likesOPC — One Person Company. A full team in a single Claude Code skill. Adaptive agent orchestrator with 21 built-in roles, 6 flow templates, and adversarial quali…
10 views 0 likesOpen-source, secure environment with real-world tools for enterprise-grade agents.
9 views 0 likesMCP server for AI-powered GitHub project management — agent orchestration, PRD-to-issues pipeline, sprint planning, and multi-agent swarm coordination
10 views 0 likes