LLM Mart Basic

@llm-mart · Joined Jun 2026

0 Followers 0 Reputation 13040 Contributions
Claude Skill security-checklist

OWASP Top 10, input validation, SQL injection prevention, rate limiting, CORS. Use when reviewing code for security issues, setting up a new API, or doing a pre-deploy security audit.

0
Claude Skill skill-creator

How to create new skills for this HQ — format, frontmatter, content structure. Use when you need to add a new skill to this repository, or when reviewing whether an existing skill is well-formed.

0
Claude Skill software-architecture

System design patterns, Clean Architecture, SOLID principles, domain modeling. Use when making architectural decisions, designing new modules, refactoring a tangled codebase, or reviewing system design.

0
Claude Skill systematic-debugging

Debugging methodology, hypothesis testing, reading stack traces, isolating issues. Use when facing an unexpected bug, a flaky test, a production incident, or any situation where the cause isn't immediately obvious.

0
Claude Skill tailwind-patterns

Tailwind CSS v4 patterns, component styling, dark mode, responsive design, and design system integration. Use when styling components or reviewing CSS.

0
Claude Skill test-driven-development

TDD red-green-refactor cycle, test structure, mocking patterns for Vitest/Jest. Use when starting a new feature, fixing a bug, or refactoring — write the test first, then the implementation.

0
Claude Skill typescript-patterns

TypeScript type system patterns, generics, utility types, and strict mode best practices. Use when writing or reviewing TypeScript code.

0
Claude Skill web-design-guidelines

Web design best practices, accessibility, responsive layout, color contrast. Use when auditing a UI for a11y compliance, designing responsive layouts, or establishing design standards across a web app.

0
Claude Skill webapp-testing

Playwright E2E patterns, Testing Library component tests, test selectors. Use when writing browser tests, component tests, or setting up an E2E testing pipeline for a Next.js or React app.

0
Claude Skill xlsx-official

Generating Excel files with xlsx/exceljs in Node.js. Use when generating .xlsx reports, data exports, dashboards, or spreadsheets from database data.

0
Claude Skill architecture-status

Reports on the health and state of architecture documentation (counts of ADRs, reviews, activity levels, documentation gaps). Use when the user asks "What's our architecture status?", "Show architecture documentation", "How many ADRs do we have?", "What decisions are documented?"

0
Claude Skill create-adr

Creates a NEW Architectural Decision Record (ADR) documenting a specific architectural decision. Use when the user requests "Create ADR for [topic]", "Document decision about [topic]", "Write ADR for [choice]", or when documenting technology choices, patterns, or architectural ap

0
Claude Skill list-members

Displays the roster of architecture team members with their specialties and expertise areas. Use when the user asks "Who's on the architecture team?", "List architecture members", "Show me the architects", "What specialists are available?", "Who can I ask for reviews?", or wants

0
Claude Skill pragmatic-guard

Enables and configures Pragmatic Guard Mode (YAGNI Enforcement) to prevent over-engineering. Use when the user requests "Enable pragmatic mode", "Turn on YAGNI enforcement", "Activate simplicity guard", "Challenge complexity", or similar phrases.

0
Claude Skill ab-test-analyzer

Statistical significance calculator for A/B test results with sample size requirements, segment breakdowns, and hypothesis generation. Use when feeding test results, checking statistical significance, calculating sample sizes, analyzing experiment outcomes, or generating next tes

0
Claude Skill ab-test-setup-and-analysis

Designs statistically valid split tests for ads, audiences, landing pages, or bid strategies. Calculates required sample sizes before you start, monitors results during the test, and calls winners when statistical significance is actually reached — not when you feel like one is w

0
Claude Skill account-structure-review

Evaluates your campaign and ad set structure against your actual goals and budget. Flags over-segmentation that fragments your data, under-segmentation that hides performance differences, budget allocation issues, and consolidation opportunities that would improve algorithmic del

0
Claude Skill ad-copy-variant-generator

Analyzes your top performing ads, identifies what's working in the hooks, CTAs, messaging angles, and formats, then generates new variants that follow the same winning patterns while introducing enough variation to test meaningfully. Platform: Google and Meta.

0
Claude Skill ad-extension-audit

Reviews all your Google Ads extensions — sitelinks, callouts, structured snippets, call extensions, image extensions, price extensions — across every campaign. Flags what's missing, what's underperforming, what's outdated, and writes replacements based on your best performing ads

0
Claude Skill ad-spend-allocator

Multi-channel budget optimization using MER, marginal ROAS, and diminishing returns analysis. Use when pasting multi-channel spend and results data, requesting reallocation recommendations, analyzing budget shift priorities, or optimizing marketing efficiency across Google, Meta,

0
The AI-in-production safety playbook

Fourteen posts of being wrong in production, compressed to checkboxes

security prompt-engineering devops ai
Sep 30
The control plane was flapping because of a spinning disk

Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds

kubernetes sre incident-response observability
Sep 29
The overlay that pinged but wouldn't carry TCP

Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.

containers incident-response networking linux
Sep 28
Bringing a cluster back after the host rebooted

Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.

kubernetes sre containers incident-response
Sep 27
The agent is running in *your* shell

A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.

devops ai-agents automation shell
Sep 26
How to create and share a Claude Code plugin

A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.

agents security skill-md claude-code
Sep 25
The scaffolding that made it safe

None of the safety came from the model. It came from six boring habits.

git devops ai-agents claude-code
Sep 25
Claude Code skills vs. subagents: when to use each

Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.

agent-skills claude-code context
Sep 24
Knowing when to stop

Six hours in, one step left, everything green, and the incident that didn't happen

prompt-engineering ai ai-agents sre
Sep 24
CLAUDE.md vs. skills: where should Claude Code instructions live?

CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.

agent-skills claude-skills configuration context
Sep 23
Those are the other app's keys

Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it

security devops ai ai-agents
Sep 23
How to use remote MCP servers with the OpenAI Responses API

An API request routing a model's tool call through an approval gate to a remote MCP server

security mcp integrations open-api
Sep 22
The coverage audit before you delete the safety net

31 config keys, two audits, and why the first one was wrong in both directions

security devops ai-agents secrets-management
Sep 22
How to publish an MCP server to the official MCP Registry

The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.

security mcp
Sep 21
Rotating a leaked credential, in the right order

Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.

security devops ai-agents containers
Sep 21
MCP authentication explained: OAuth, scopes, and safe token handling

Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.

security mcp
Sep 20
Byte-identical or bust

"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks

security kubernetes verification
Sep 20
MCP stdio vs. Streamable HTTP: which transport should you use?

stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.

security mcp
Sep 19
Never let the AI print a secret

The most important rule wasn't about what I could change. It was about what I was allowed to display.

security kubernetes devops ai-agents
Sep 19
MCP tools vs. resources vs. prompts: when to use each

Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.

security mcp
Sep 18
/attach Attach

`crabbox attach` follows the recorded events of an active coordinator run and

0
/azure Azure

`crabbox azure` groups Azure provider setup commands. It currently has a single

0
/bench Bench

`crabbox bench` records and reports local benchmark timing observations. It is a

0
/cache Cache

`crabbox cache` inspects, purges, or warms package and build caches on a

0
/capsule Capsule

`crabbox capsule` captures, replays, and tracks lightweight failure capsules.

0
/checkpoint Checkpoint

Save the state of a lease, then restore it onto another box or fork it into a

0
/claims Claims

`crabbox claims list` prints the lease claims stored on the current machine. It

0
/cleanup Cleanup

`crabbox cleanup` sweeps direct-provider machines and local provider state that

0
/code Code

`crabbox code` bridges a Linux lease's `code-server` workspace into the

0
/config Config

`crabbox config` inspects and updates user configuration. It has three

0
/connect Connect

`crabbox connect` resolves a lease and opens an interactive SSH session to it.

0
/cp Cp

`crabbox cp` copies files or directories between the host and a Crabbox-owned

0
/desktop Desktop

`crabbox desktop` drives a visible desktop session on a lease that was warmed

0
/doctor Doctor

`crabbox doctor` runs a preflight before you commit to a long workflow. It is

0
/egress Egress

`crabbox egress` gives a lease mediated outbound network: a lease-local browser

0
/events Events

`crabbox events` prints the broker's event log for a recorded run.

0
/heartbeat Heartbeat

`crabbox heartbeat` refreshes the idle deadline for one owned lease and prints

0
/history History

`crabbox history` lists recorded remote command runs from the broker. Each run is

0
/image Image

`crabbox image` holds the trusted-operator controls for provider base images:

0
/init Init

`crabbox init` onboards the current repository: it writes the minimal config

0
PiG

PiG (Pi in Go) is a faithful Go port of upstream Pi, the TypeScript codebase behind the Pi coding agent. It is a parity-bound translation, not a rewrite: upstre…

1 views 0 likes
Anythingllm Mobile

An AI Agent that lives in your pocket. Local-first and privacy focused.

2 views 0 likes
Building With Typesafe Jev

Unofficial skill that teaches coding agents to build with TypeSafe AI's Jev: typed decisions, calibrated confidence, and prior art from 150+ community projects.

6 views 0 likes
ATLAS

Adaptive Test-time Learning and Autonomous Specialization

4 views 0 likes
Oracle3

Prediction-market trading engine — Wang Transform pricing on 291K+ contracts; paper-traded across Kalshi · Polymarket · Solana DFlow (Jito bundles) · 633 tests

3 views 0 likes
Bkmr

Knowledge Management for Humans and Agents

5 views 0 likes
Openworkbuddy

Open-source Claude Cowork / Codex / WorkBuddy alternative — a local-first AI office agent that turns one request into real PPTX, DOCX, XLSX and HTML files. Runs…

5 views 0 likes
Deepagent Code

DeepAgent Code: AI coding agent with persistent memory and control plane

4 views 0 likes
Awesome Jev Live

Awesome Jev — evidence-graded index of TypeSafe System One: SDKs, MCP tools, agents, apps and open models. 20 languages, rebuilt every 2 hours.

5 views 0 likes
Tlgr

CLI for Telegram — agent-friendly, daemon-based, with webhook event push.

5 views 0 likes
Deep Research Web Ui

AI deep-research agent that turns any question into a cited report: plans searches, reads real sources, verifies evidence. Self-hosted, multi-provider, Docker-r…

4 views 0 likes
Cortico

Event-stream AI Agent framework for building your persona bot 🍊

1 views 0 likes
Coi

Give the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops t…

3 views 0 likes
Emperor Agent

Local Emperor-style AI agent with Vue WebUI, multi-provider LLMs, streaming chat, tools, skills, memory, and token telemetry.

2 views 0 likes
Open Reverselab

Open-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware researc…

8 views 0 likes
Agent Smith

"Never send a human to do a machine's job" - Open Source AI hacking agent

3 views 0 likes
PrismerCloud

Prismer Cloud

3 views 0 likes
Tingdeliu.github.io

My Personal Blog (Robotics)

3 views 0 likes
Tau

Tau Coding Agent - like Pi, but twice as much

1 views 0 likes
Open Dots

Open-source alternative to OpenAI Dots: self-hosted AI chat, tools, approvals, connectors, and computer tasks.

0 views 0 likes