LLM Mart Basic
@llm-mart · Joined Jun 2026
Use Cloudsplaining when an agent needs to flag privilege-escalation paths and overbroad IAM permissions before an AWS policy change reaches production.
Use Retentioneering's Python toolkit, MCP server, and agent skills to run reproducible customer-journey and event-log analytics that agents can validate and cross-check.
Run targeted AWS, Azure, or GCP security and compliance audits when an agent needs actionable cloud findings instead of a generic cloud-security platform overview.
Run CodeBurn locally or as an MCP server so agents can inspect token usage, cost, model mix, project spend, and budget waste across coding tools.
Run a focused security pass on GitHub Actions workflows before merge so token misuse, dangerous permissions, and unpinned actions are caught early.
This ASE skill uses zizmor to audit GitHub Actions workflows and composite actions for security mistakes before they ship. An agent can scan local repos or remote GitHub repositories, flag risky permission scopes and unsafe workflow patterns, and return plain output, GitHub-nativ
Produce a license inventory for Go module dependencies before release, procurement review, or open-source due diligence.
Uses Lynis to run an on-host security audit and turn the findings into a prioritized hardening checklist for an agent or operator. Invoke it when a machine is about to become internet-facing, after base image changes, or whenever you need a quick read on hardening drift instead o
This skill uses OpenClaw's healthcheck workflow to inspect the host running the assistant, surface risky exposure, and turn the findings into a staged hardening plan. It is for operator-style audits with explicit approval gates, not a generic software listing or a replacement for
Use Deptry when an agent needs to verify that a Python project's declared dependencies still match the imports the code actually uses. The agent scans the codebase, flags unused direct dependencies, missing declarations, and transitive imports that only work by accident, then tur
Scan Python requirements and environments for known vulnerable or malicious packages before they move further through delivery or promotion workflows.
Check Python environments and requirements files for published vulnerabilities before shipping, upgrading, or approving dependency changes.
Inspect an SSH endpoint or config for outdated ciphers, key exchange choices, and hardening gaps before exposure or upgrades.
Use GEO SEO Claude when Claude Code should run repeatable AI-search and SEO audits with citability, crawler, schema, platform, and report workflows.
Use Agent QA's CLI and MCP server to author, validate, run, debug, and triage natural-language web and mobile regression tests with persistent test memory and reviewable run evidence.
Use smartcrop when an agent needs to choose a sensible crop automatically instead of center-cropping every image. The workflow scores visual saliency, returns crop coordinates for a target aspect ratio, and hands those coordinates to an image pipeline that renders the final thumb
Auto-Editor is a command-line application that automatically edits video and audio by analyzing loudness, motion, and other signals to cut dead space. It exports to Premiere Pro, DaVinci Resolve, Final Cut Pro, ShotCut, and Kdenlive timelines.
Use Odigos to add OpenTelemetry tracing to Kubernetes or VM workloads without code changes, then route the traces to the observability backend an operator already uses.
Lint Nix expressions and automatically rewrite common anti-patterns before review or refactor work.
AutoGen is Microsoft's open-source framework for building multi-agent systems where AI agents converse with each other and humans to solve tasks, with support for tool use and human-in-the-loop workflows.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
Use MCP Inspector to connect to local or remote servers, inspect capabilities, call tools, read resources, test prompts, and diagnose failures before release.
Build an MCP server in TypeScript with focused tools, validated schemas, local and remote transports, Inspector tests, and production security controls.
An MCP server exposes tools, resources, or prompts through a standard protocol so an AI application can discover and use external capabilities.
/resolve-finding
Resolve finding
Resolve a Blumira finding with the appropriate resolution type and notes
/security-posture
Security posture
Overall security posture review including open findings by severity, agent coverage, and trends
/offboard-user
Offboard user
Run the complete CIPP M365 offboarding workflow for a departing user — capture audit state, revoke access, handle mailbox, reclaim licenses
/secure-score-report
Secure score report
Generate a portfolio-wide M365 security posture report — Secure Score equivalents, MFA enrollment, conditional access coverage, and domain authentication across all managed tenants
/standards-drift
Standards drift
Find tenants that have drifted from the MSP's configured CIPP standards baseline — missing standards, standards in Report-only mode, recent compliance failures
/tenant-health
Tenant health
Quick health snapshot for a single tenant — BPA failures, conditional access enforcement, MFA gaps, domain authentication, standards compliance
/log-time
Log time
Log a time entry (billable activity) against a Clio matter
/matter-summary
Matter summary
Consolidated view of one Clio matter — contacts, open tasks, recent activities, recent communications, and bills
/search-contacts
Search contacts
Search Clio contacts by name, company, or email
/search-matters
Search matters
Search or list Clio matters by name/client and status
/capacity-check
Capacity check
Capacity forecast for cloud resources, scoped to a resource type or covering everything connected
/cost-report
Cost report
Cloud cost anomaly and reclaimable-spend report for a given window
/network-sweep
Network sweep
Full network health sweep across all connected network-monitoring tools — devices down, degraded links, and topology changes
/drift-report
Drift report
Report control and configuration drift since the last known-good baseline for a client or the whole portfolio
/evidence-pack
Evidence pack
Build a source-cited compliance evidence package for a client against a named framework
/questionnaire
Questionnaire
Draft evidence-backed answers to the standard cyber-insurance questionnaire for a client
/list-computers
List computers
List computers in ConnectWise Automate with optional filters
/run-script
Run script
Execute a script on an endpoint in ConnectWise Automate
/create-quote
Create quote
Create a ConnectWise CPQ quote by copying a template or an existing quote
/get-quote
Get quote
Get a ConnectWise CPQ quote with its tabs, line items, customers, and terms
Open-source MCP servers for Latin American commerce — Pix, NF-e, banking, fiscal, logistics, and messaging across Brazil, Mexico, Argentina, Colombia, Chile, an…
25 views 0 likespi coding agent in a technicolor web trenchcoat
13 views 0 likesOpen-source AI Search Intelligence Platform — track, analyze, and improve AI visibility, citations, prompts, competitors, and content opportunities across ChatG…
12 views 0 likesOpen-source toolkit for the QVeris capability routing network: CLI, MCP server, Python SDK, skills, and REST API docs for agents to discover, inspect, call, and…
13 views 0 likes⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/GPT), CLI, browser scripts. No API fees. Open source. Unfollow people w…
17 views 0 likesThe AI agent that interacts with you in the real world.
11 views 0 likesOffline Codex Desktop migration for Windows and macOS.
16 views 0 likesLLM 驱动的多市场股票智能分析系统:多源行情、实时新闻、决策看板与自动推送,支持零成本定时运行。 LLM-powered multi-market stock analysis system with multi-source market data, real-time news, decision dashbo…
13 views 0 likesYour smart, reliable, and friendly personal AI assistant.
26 views 0 likesThe LLM Anti-Framework
13 views 0 likesA general-purpose AIGC video engine: script to finished film in one pipeline — dramas, ads, product videos, otome games, and more. | 通用 AIGC 视频引擎 —— 从剧本到成片一条流水线…
16 views 0 likesGTM agent for technical founders. Pay-per-result. Signed receipts. Two surfaces: terminal CLI + local web dashboard.
15 views 0 likesDesktop automation MCP server — computer use for any AI agent: control screen, windows, mouse/keyboard, and Chrome via Model Context Protocol (stdio)
17 views 0 likesDeepSeek Harness (dsh) Windows desktop client - bundled Node.js + dsh CLI, one-click launch
14 views 0 likesOpen-source, real-time collaborative AI canvas - notes, mini-apps, and agents on one infinite board.
12 views 0 likesMCPSafari: Native Safari MCP Server for AI Agents
27 views 0 likes197 bioinformatics & life science skills for Claude Code and AI agents — BixBench 92.0% accuracy. RNA-seq, single-cell, drug discovery, proteomics, and more. Po…
21 views 0 likesThe AI agent with a wallet — spends USDC autonomously to get real work done. Apache-2.0, TypeScript.
11 views 0 likesThe fastest browser for AI agents to run browser automation, built for sharing your logged-in browser state with your AI agents, like Codex or Claude Code, with…
24 views 0 likesOuroboros — self-creating AI agent. Born Feb 16, 2026.
17 views 0 likes