LLM Mart Basic
@llm-mart · Joined Jun 2026
Apply better-data's security discipline when touching Secret, EncryptionEngine, #[Sensitive], #[Encrypted], MetaKeyRegistry::register, RequestSource guards, or user_pass handling. Loud-over-silent — missing key throws, tampered ciphertext throws, unknown strict-whitelist field th
Add a new sink to better-data — code that writes
Add a new source adapter to better-data — code that reads from a WordPress data store the library doesn't cover yet (comments, attachments, transients, custom tables). Mirror the canonical shape PostSource / UserSource / TermSource use — a non-final class with static hydrate(int|
Add a new validation rule to better-data — implement
Configure better-route 1.1 AtomicIdempotencyMiddleware for side-effectful POST, PUT, PATCH, or DELETE routes where concurrent duplicate execution must be prevented. Use for WpdbAtomicIdempotencyStore, lease-aware reservations, reservation_token schema migration, Idempotency-Key v
Configure Better Route 1.1 audit events and safe enrichment. Use when logging route outcomes, authenticated identity, hashed idempotency keys, trusted client IPs, domain action metadata, or ensuring telemetry failures cannot change API behavior.
Configure Better Route 1.1 authentication with JWT, custom bearer tokens, WordPress Application Passwords, or cookie nonces. Use when protecting routes, mapping verified claims to WordPress users, enforcing scopes, or consuming the shared AuthContext identity.
Configure better-route 1.1 CORS for browser, mobile, and embedded WordPress REST clients. Use for CorsPolicy, CorsMiddleware, WordPressCorsBridge, allowed origins/methods/headers, credentials, OPTIONS preflight, Authorization, X-WP-Nonce, Idempotency-Key, If-Match, If-None-Match,
Use Better Route 1.1 cryptographic helpers for secure random tokens, Hex/Base64/Base64URL encoding, strict Base64URL decoding, and constant-time secret comparison. Use when implementing nonces, state, PKCE, opaque tokens, or signature comparisons.
Produce and consume better-route 1.1 structured errors. Use for ApiException, Response, ErrorNormalizer, ResponseNormalizer, WP_Error conversion, OAuth RFC 6749 error_format, status/code/details/headers, Retry-After, validation_failed, idempotency/rate/optimistic-lock/Woo errors,
Add better-route 1.1 ETag and If-None-Match handling to GET or HEAD routes. Use for ETagMiddleware, strong or weak validators, custom etagResolver, WP_REST_Response preservation, comma-separated validators, wildcard matching, 304 responses, Cache-Control, proxy-stripped ETag trou
Configure Better Route 1.1 HMAC authentication for webhooks and server-to-server REST requests. Use when signing request timestamps, methods, paths, raw bodies, optional query strings, rotating key IDs, or consuming the shared HMAC AuthContext identity.
Configure better-route 1.1 replay-cache idempotency with IdempotencyMiddleware and Idempotency-Key. Use for ArrayIdempotencyStore, TransientIdempotencyStore, WpdbIdempotencyStore, installSchema, identity-aware canonical keys, body fingerprints, key conflicts, replay headers, key
Install better-route from Packagist or migrate a WordPress integration to better-route 1.1. Use when adding better-route/better-route, changing the Composer constraint to ^1.1, upgrading from 1.0 or pre-1.0 releases, diagnosing new 403 route responses, migrating atomic idempotenc
Configure Better Route 1.1 RS256 or ES256 JWT verification from a local or HTTPS JWKS. Use when integrating OIDC/OAuth bearer tokens, selecting keys by kid, validating issuer/audience/lifetime, or operating JWKS caching and refresh behavior safely.
Configure Better Route 1.1 trusted-proxy client IP resolution and CIDR allowlists. Use behind Cloudflare, nginx, load balancers, or reverse proxies when authorization, rate limiting, or audit data depends on the real client IP.
Generate or serve better-route 1.1 OpenAPI 3.1 documents from Router/Resource/Woo contracts. Use for OpenApiExporter, OpenApiRouteRegistrar, contracts, contractsFromSources, route args to parameters, explicit parameter overrides, custom responses, OPTIONS 204, strictSchemas, comp
Configure Better Route 1.1 optimistic locking for REST writes with If-Match or version parameters and an atomic per-resource critical section. Use when preventing stale updates, lost writes, or two cooperating Better Route requests from passing the same version check concurrently
Add Better Route 1.1 ownership authorization to raw routes and Resource DSL endpoints. Use when authenticated users may access only their own records, orders, profiles, memberships, tokens, or subscriptions.
Configure better-route 1.1 RateLimitMiddleware with atomic fixed-window storage. Use for WpObjectCacheRateLimiter, TransientRateLimiter, persistent external object cache checks, wp_cache_incr, MySQL named locks, identity/native WordPress/IP keys, trusted proxies, Retry-After and
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/proposal
Proposal
Create a multi-page funding proposal with your organization's branding
/report
Report
Create a program report or annual report with your organization's branding
/slides
Slides
Create HTML presentation slides with your organization's branding
/update
Update
Check for updates and install the latest version
/hotpatch
Hotpatch
Sandboxed pre-install scan plus cooldown bypass for urgent npm/bun installs. Use when a package must ship despite the cooldown.
/diff-review
Diff review
Generate a visual HTML diff review, before/after architecture comparison with code review analysis
/fact-check
Fact check
Verify the factual accuracy of a document against the actual codebase, correct inaccuracies in place
/generate-slides
Generate slides
Generate a stunning magazine-quality slide deck as a self-contained HTML page
/generate-visual-plan
Generate visual plan
Generate a visual HTML implementation plan, detailed feature specification with state machines, code snippets, and edge cases
/generate-web-diagram
Generate web diagram
Generate a beautiful standalone HTML diagram and open it in the browser
/plan-review
Plan review
Generate a visual HTML plan review, current codebase state vs. proposed implementation plan
/project-recap
Project recap
Generate a visual HTML project recap, rebuild mental model of a project's current state, recent decisions, and cognitive debt hotspots
/share-page
Share page
Deploy a generated visual-explainer HTML page and return a live Vercel URL
/methodology
methodology
View your cognitive methodology profile and reasoning patterns
/preflight
preflight
Diagnostique l'environnement Cortex et guide la réparation (DB, extensions, modèles)
/why
why
Resolve the ⟦rcpt:id⟧ injection markers in context into presence-in-context evidence (blame path)
/commit
Commit
Please summarize your current changes, generate a commit message in English, then add and commit.
/tag
Tag
Create an annotated git tag with an auto-generated summary of changes since the last tag.
/delegate-review
Delegate review
Run OCR in delegation mode — OCR handles file selection and rules, the host agent performs the actual review.
/review
Review
Run OpenCodeReview (OCR) to review code changes and autonomously apply fixes.
Open-source, self-hosted AI media server. One server replaces your entire media stack, with a web app, native iPhone app, and an AI agent that gets things done.…
3 views 0 likesA curated list of tools built for Jev — TypeSafe AI's System One model for typed decisions.
3 views 0 likes🦦 Crayotter: A Multimodal AI-Agent for Video-Editing, Video-Composing, and Video Production. Powered by Multimodal LLMs for autonomous Text-to-Video agentic fr…
3 views 0 likesWebextension tool for Odoo
3 views 0 likes基于多模态视觉感知与 LLM Agent 的 macOS 微信自动化框架 | Visual RPA for WeChat
0 views 0 likesThe operational superset of Pi Coding Agent — everything Pi, plus observability, governance, recovery, evaluation and multi-agent orchestration. Pi Coding Agent…
0 views 0 likesMetrik 可以集中查看本机多个 Agent 的配额余量和 Token 消耗,目前支持 ChatGPT、Claude、GLM、Kimi 等主流 AI 服务。
0 views 0 likesAn AI agent with a real self — soul she wrote, desires that drive her, a heartbeat for autonomous action, dreams she processes when you're away. Capability supe…
0 views 0 likesProduction-ready open source terminal coding agent with readable, layered code: permission rules, OS sandboxing, MCP, skills, sub-agents, and Anthropic, OpenAI-…
0 views 0 likesAnswer me with HTML — an agent skill that answers hard questions with a one-page HTML you can actually read. 让 AI Agent 用一页 HTML 回答复杂问题。
1 views 0 likesPrompt packs that make any AI agent a LaTeX expert — fix errors, polish writing, format for venues, read papers, recover source
1 views 0 likesClaude Code plugin: universal radial-tree exploration engine. One tree skill + swappable presets (brainstorm / attack / design / code-audit) for divergent ideat…
1 views 0 likesClaude Code + OpenClaw + Codex + WorkBuddy 中文教程 | 50篇完整教程 + 1张速查卡 | 80万+内容量 | 1500+实操示例 | AI Coding / Agent 四线学习路径(编程+助手+Agent+办公)
1 views 0 likesSmartLabelBench 2026: LLM-Powered Auto Annotation and Dataset Builder for Everything
1 views 0 likes从零开始玩转OpenClaw:最全面的中文教程,涵盖安装、配置、实战案例和避坑指南(github版)
1 views 0 likesNative Android GUI for running AI coding agents locally on-device. No terminal or PC required.
0 views 0 likes基于 LangChain/LangGraph 的 ReAct Agent ,结合 RAG、工具调用与 Streamlit 界面,面向智能客服与报告生成场景。
0 views 0 likesAn open-source, local-first AI learning workbench
2 views 0 likesOpen-source coding agent for your terminal, built in Rust and on a journey of continuous community improvement. Issues and PRs welcome.
2 views 0 likesMatt Pocock 技能集的中文翻译版 — 地道中文,原汁原味的技术术语。基于 mattpocock/skills 复刻。每日中午12点钟同步
2 views 0 likes