LLM Mart Basic
@llm-mart · Joined Jun 2026
Use this skill when you need evidence-bounded safety policy, abuse categories, refusal/redirect behavior, privacy, escalation, and Human risk decisions; triggers include AI 安全 and AI safety.
Use this skill when you need to verify API contract compatibility, consumer expectations, and schema change risk; triggers include API contract testing.
Use this skill when an API, OpenAPI, or consumer contract needs a quality review before implementation or versioning; triggers include API design review, contract readiness review, and consumer compatibility audit.
Use this skill when you need to review API error shape, status, code, and disclosure behavior against sourced contracts; triggers include API 错误契约测试 and API error contract testing.
Use this skill when you need to assess API retry and duplicate-request behavior against sourced side-effect evidence; triggers include API 幂等性测试 and API idempotency testing.
Use this skill when you need to design evidence-bounded API failure and rejection scenarios; triggers include API 负向测试 and API negative testing.
Use this skill when you need to design API pagination scenarios from ordered data and cursor or offset evidence; triggers include API 分页测试 and API pagination testing.
Use this skill when you need to design evidence-bounded API quota, burst, and recovery scenarios; triggers include API 限流测试 and API rate limit testing.
Use this skill when you need to compare API schemas with sourced request and response evidence; triggers include API Schema 校验 and API schema validation.
Use this skill when you need evidence-bounded api-security-testing analysis and validation preparation; triggers include API 安全测试 and api-security-testing.
Use this skill when you need to parse multi-format API definitions and generate Bruno collections for executable regression; triggers include Bruno collections and Bruno API testing.
Use this skill when you need to design Postman collections, environments, scripts, and Newman-ready API regression plans; triggers include Postman API testing, API testing, and api-test-postman.
Use this skill when you need to parse multi-format API definitions and generate Pytest API automation; triggers include Pytest API tests and API automation with Pytest.
Use this skill when you need to parse multi-format API definitions and generate Rest Assured Java test classes; triggers include Rest Assured, RestAssured, and Java API automation.
Use this skill when you need to parse multi-format API definitions and generate executable Supertest scripts; triggers include Supertest, Node.js API testing, and Supertest automation.
Use this skill when you need to assess API version compatibility from old-client, new-server, and deprecation evidence; triggers include API 版本兼容性测试 and API version compatibility testing.
Use this skill when you need evidence-bounded authentication-testing analysis and validation preparation; triggers include 身份认证测试 and authentication-testing.
Use this skill when you need evidence-bounded authorization-testing analysis and validation preparation; triggers include 授权测试 and authorization-testing.
Use this skill when you need evidence-bounded automation candidates, build/run/maintenance costs, benefit assumptions, time horizon, and sensitivity; triggers include 自动化投资回报 and automation ROI.
Use this skill when you need to design automation testing approaches using patterns like POM, data-driven testing, or BDD; triggers include automation testing and test automation strategy.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/sonar
sonar
SonarQube 정적분석 실행 및 결과 조회. 코드 품질·보안 핫스팟·커버리지 확인 시 사용.
/fix-issue
fix-issue
GitHub 이슈 #$ARGUMENTS 를 처리한다(이슈 우선 워크플로):
/sdlc-cycle
sdlc-cycle
이슈/기획서 기준 SDLC 한 사이클(이슈→개발→테스트→검증→PR)을 사람 개입 없이 자동 실행.
/fix-issue
fix-issue
GitLab 이슈 #$ARGUMENTS 를 처리한다(이슈 우선 워크플로):
/sdlc-cycle
sdlc-cycle
이슈/기획서 기준 SDLC 한 사이클(이슈→개발→테스트→검증→MR)을 사람 개입 없이 자동 실행.
/README
README
Invoke a repeated task with `/name`. File name = command name (`fix-issue.md` → `/fix-issue`).
/fix-issue
fix-issue
Handle issue #$ARGUMENTS (issue-first workflow):
/knowledge-graph
Knowledge graph
Renders the connection structure of the AGENTS.md ecosystem
/sdlc-cycle
sdlc-cycle
Automatically runs one SDLC cycle (issue → development → testing → verification → PR/MR) based on an issue or spec, without human intervention.
/sonar
sonar
Run SonarQube static analysis and check the results. Use to check code quality, security hotspots, or coverage.
/fix-issue
fix-issue
Handle GitHub issue #$ARGUMENTS (issue-first workflow):
/sdlc-cycle
sdlc-cycle
Automatically runs one SDLC cycle (issue → development → testing → verification → PR) based on an issue or spec, without human intervention.
/fix-issue
fix-issue
Handle GitLab issue #$ARGUMENTS (issue-first workflow):
/sdlc-cycle
sdlc-cycle
Automatically runs one SDLC cycle (issue → development → testing → verification → MR) based on an issue or spec, without human intervention.
/plan-status
Plan status
Show Hermes planning-with-files status for the current project.
/plan
Plan
Start Hermes planning-with-files workflow in the current project.
/plan-ar
Plan ar
بدء تخطيط الملفات بنمط Manus. إنشاء task_plan.md و findings.md و progress.md للمهام المعقدة.
/plan-attest
Plan attest
Lock the current task_plan.md content with a SHA-256 attestation. Hooks then refuse to inject plan content if the file diverges from the attested hash, blocking silent tampering. Use --show to print the stored hash, --clear to remove the attestation. Available since v2.37.0.
/plan-de
Plan de
Starte Manus-artige Dateiplanung. Erstelle task_plan.md, findings.md, progress.md für komplexe Aufgaben.
/plan-doctor
Plan doctor
Self-check for the planning-with-files mechanisms that fail silently: plan resolution, hook injection, canonicalizer path shape, attestation state, install surfaces, and per-fire hook latency. Run it whenever hooks seem quiet or after installing on a new machine. Available since v3.6.0.
AI agent orchestration kit for Windows, Linux/MacOS with Codex skills, hooks, routing rules and profiles for Claude, OpenCode, Cursor, Gemini and Windsurf.
1 views 0 likesSkills & reviewer agents for AI-first climate science — built and used by a PhD atmospheric scientist
3 views 0 likes出行路书工作流 skill:联网实查 + 多源交叉验证,产出可核验、能执行的旅行攻略。覆盖吃住行游拍避全维度,附美食情报卡、基准骨架与校验工具,支持一键部署在线版。
3 views 0 likesSelf-hosted AI code reviewer with indexed PR reviews, walkthroughs, vulnerability scanning, dependency graphs, custom rules, and a learning loop.
3 views 0 likes🧬 Extend EvoScientist with Installable Skill & Knowledge Packs
2 views 0 likesGive the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops t…
2 views 0 likesAutomatic memory consolidation for OpenClaw agents — like sleep for your AI. Powered by MyClaw.ai
0 views 0 likes🗂 The essential checklist for modern web development, for humans and AI agents
1 views 0 likesDistribb CLI, Claude, Codex, Hermes, OpenClaw skill for AI-powered SEO. Write content with your own AI, publish through Distribb's backlink network.
2 views 0 likesOpen-source AI browser agent — type plain-language commands and Bah operates the web for you. Works with cloud AI (DeepSeek, Mistral, NVIDIA) or local Ollama mo…
3 views 0 likesDeepSeek Harness Desktop (dsh-desktop). EAC: Embracing All Creation (揽尽万象). Bundled Node.js runtime with full dsh-CLI kernel, one-click startup, 10 built-in UI…
2 views 0 likesUse your ChatGPT / Codex subscription with DeepSeek Harness via OAuth, with model access, usage quotas, search, and image generation — no API key or Codex CLI r…
3 views 0 likesLocal-first A-share research workbench for DeepSeek Harness: market dashboards, watchlists, valuation, four investor agents, versioned reports, and continuous p…
2 views 0 likesOpen-source video pipeline (clipper, AI video & more) — scout trends, clip long videos, generate captioned shorts, design motion graphics. Local-first, BYOK. AG…
3 views 0 likesDesktop app for the pi coding agent: streaming timeline, Git review with hunk staging, session tree, native UI for pi extensions. Windows · macOS · Linux. pi 编程…
4 views 0 likesZero-dependency browser video editor that AI agents can drive — JSON timeline, MCP + REST, live-reloading UI
0 views 0 likesPersonal Context Manager for Claude Code. Your life in walnuts.
0 views 0 likesFast way to switch between Claude Code configuration profiles
4 views 0 likesAutoClip|一个链接,一键出片。开源 AI 视频剪辑桌面工具,将播客、访谈、课程等长视频自动剪成短视频,生成字幕、封面和发布文案,适配抖音、小红书、TikTok、Reels 与 YouTube Shorts。Open-source AI video clipping & content repurposing.
3 views 0 likes