LLM Mart Basic
@llm-mart · Joined Jun 2026
代码质量检查与自动修复
打印循环下一步应执行的命令(机器可读,供 loop 驱动)
收敛循环引擎(自动推进 tdd→implement→review 到 review_done 或 blocked)
新人引导 / 自动化生成用户手册
性能优化
创建 PRD 文档(自动化生成 + 自检 + handoff)
质量闸门——跑真实 check、对照质量目标、出可核对报告,由人签字放行
代码重构(保持外部行为不变,改善内部结构)
管理 feature 关系链(set/query/impact/orphans/rebuild/validate)
迭代复盘——读状态机历史出趋势报告
安全审计
交互式配置 PDLC(当前:状态栏 statusline 的启用/停用/展示项)
发布工作流(收评审通过的功能 → 跑测试 → bump VERSION → 更 CHANGELOG → tag)
管理 00_standards 规范型 surface 产物(add/edit/archive/index)
查看项目 PDLC 状态总览(读 docs/.pdlc-state/ 输出进度)
阶段内任务跟踪(创建/更新任务列表,附在工作流上)
TDD 测试先行(按设计文档生成失败的测试用例)
立测试地基(探测技术栈 → 验证并生成 test-commands.yml → 脚手架测试目录 → 接本地钩子)
UI/UX 设计
UI/UX 专业设计(PDLC 集成层,依赖 ui-ux-pro-max)
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
Use MCP Inspector to connect to local or remote servers, inspect capabilities, call tools, read resources, test prompts, and diagnose failures before release.
/python-scaffold
Python scaffold
Scaffold a Python project (FastAPI, Django, library, or CLI) with uv, type hints, testing, and dev tooling
/approve-review
Approve review
Open a review-action approval window by creating the ./.review-approved flag file. Takes an optional reason string that is recorded in the flag file and an unsigned approval log.
/list-pending
List pending
List the review actions that the review-governance policy blocked in this session. protect-mcp 0.7.4 writes no receipt for a denied call, so the list comes from the session, not from ./review-receipts/.
/compliance-check
Compliance check
Review software compliance controls, regulatory requirements, and audit readiness
/security-dependencies
Security dependencies
Scan dependencies for vulnerabilities and generate supply chain security evidence
/security-hardening
Security hardening
Orchestrate comprehensive security hardening with defense-in-depth strategy across all application layers
/security-sast
Security sast
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
/setup
Setup
Initialises the ShipMate pipeline in the current project. Creates the stories folder, sets up the pipeline state directory, and runs the initial codebase scan to generate project-doc.md and AGENTS.md.
/ship
Ship
Master pipeline entry point. Routes requirements from a story file through scan → orchestrate → architect → implement → review → QA → playwright stages. Use /ship stories/foo.md to start, /ship status to check progress, /ship resume to continue.
/business-case
Business case
Generate comprehensive investor-ready business case document with market, solution, financials, and strategy
/financial-projections
Financial projections
Create detailed 3-5 year financial model with revenue, costs, cash flow, and scenarios
/market-opportunity
Market opportunity
Generate comprehensive market opportunity analysis with TAM/SAM/SOM calculations
/rust-project
Rust project
Scaffold a Rust project (binary, library, workspace, or Axum web API) with Cargo, testing, and dev tooling
/tdd-cycle
Tdd cycle
Execute a comprehensive TDD workflow with strict red-green-refactor discipline
/tdd-green
Tdd green
Implement minimal code to make failing tests pass in TDD green phase
/tdd-red
Tdd red
Write comprehensive failing tests following TDD red phase principles
/tdd-refactor
Tdd refactor
Refactor code while keeping all tests green in TDD refactor phase
/issue
Issue
Resolve a GitHub issue from triage and root cause analysis through test-driven implementation and a pull request
/standup-notes
Standup notes
Generate async standup notes from git commits, Jira tickets, and Obsidian notes
/accessibility-audit
Accessibility audit
Audit UI code for WCAG compliance
Ultra-lightweight, open-source, self-hosted personal AI agent framework in Python with WebUI, tools, memory, MCP, multi-agent workflows, automation, and chat ap…
29 views 0 likesGovernance framework for AI coding agents. It runs them through a five-step workflow (plan, build, review, test, ship) where no step counts as done without evid…
17 views 0 likesUltimate Multi-Agent OS for Autonomous AI NPCs 2026
14 views 0 likesPersonal AI Agent Hub 2026 — Build Your 24/7 Autonomous Assistant
25 views 0 likesProven 2026 Multi-Agent AI Review System – Verdict-Driven Quality Control
28 views 0 likesSlash API Batch: Cut AI Costs by 50% in 2026
15 views 0 likesWeb dashboard for Hermes Agent — multi-platform AI chat, session management, scheduled jobs, usage analytics
17 views 0 likesAgent Skills for Solopreneurs
31 views 0 likesAirLLM dramatically reduces inference memory usage, letting 70B large language models run on a single 4GB GPU card
119 views 0 likesZero, your trustworthy AI teammate for real work.
16 views 0 likes一套 DSH runtime,Desktop、Web 与 TUI 三种开发体验。
11 views 0 likesOpen-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations.
16 views 0 likes⚙️ TypeScript Style Guide and Agent Skill. A concise set of conventions and best practices for consistent, maintainable code.
27 views 0 likesFramework for AI agents to build and maintain a digital brain through Obsidian wiki
16 views 0 likesApache Maka (Incubating) is a local-first AI agent workspace. Model messages, tool calls, tool results, permission decisions, and termination events are recorde…
24 views 0 likesNeo.mjs is a self-evolving software organism: a professional end-to-end AI engineering team whose cross-model swarm inhabits live apps via Neural Link, Active H…
24 views 0 likesAgentic development harness for Claude Code — SPEC-driven plan/run/sync, TRUST 5 quality gates, model+effort routing, and Claude×GLM multi-LLM cost control. Sin…
18 views 0 likesNocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of productio…
27 views 0 likesAn open-source AI coding agent that lives in your terminal.
28 views 0 likesPawWork — free, open-source desktop AI agent for macOS and Windows. Alternative to Codex App and Claude Cowork. BYOK with 75+ providers, ChatGPT OAuth, local mo…
14 views 0 likes