LLM Mart Basic
@llm-mart · Joined Jun 2026
A source-backed ASE skill for Beekeeper Studio, the SQL editor and database manager for Linux, macOS, and Windows. It fits workflows that need a real client for querying, browsing tables, and working across PostgreSQL, MySQL, SQLite, SQL Server, and other supported databases.
Manage and tag music libraries with beets, the Python-based CLI tool that auto-tags audio files using MusicBrainz metadata. Import, organize, deduplicate, and query your music collection with a powerful plugin system and flexible query language.
Use MemoryBench to run repeatable conversational memory and RAG benchmarks across providers, datasets, judge models, checkpoints, and structured reports.
Benchmark clean and incremental Xcode builds, surface compile and configuration hotspots, and produce an approval-first optimization plan before changing project files.
Compare browser-agent reliability on a repeatable task and anti-bot suite before choosing a stack or claiming progress.
Run a repeatable evaluation suite for browser agents against static web task snapshots instead of judging them from demos or one-off tests.
Run Claude Code, Codex CLI, Gemini CLI, or OpenCode through bounded H100 post-training tasks and compare how well each agent improves a base LLM.
Score deep research agents on benchmark tasks using factual verification, report-quality scoring, and process evaluation before model or workflow changes ship.
Use EnterpriseRAG-Bench to evaluate an enterprise RAG or knowledge-agent system against a realistic synthetic company corpus with answer, recall, and comparative scoring.
Run realistic enterprise-style IT scenarios before trusting an automation agent in production operations.
Run CIS benchmark checks against cluster nodes and control planes when an agent needs a narrow Kubernetes hardening audit, not a general platform listing.
Run a real-task benchmark suite against OpenClaw agents so model or harness changes can be compared before they hit production workflows.
Run structured prompt-injection attack and defense experiments against an LLM-integrated app before production by measuring attack success and testing detection or recovery pipelines.
Run concurrent scripted conversations against a target agent to measure whether it stays on task, responds correctly, and holds up in repeatable test cases.
Better Auth is an open source authentication framework for TypeScript apps. It gives agents a concrete way to wire sign-in, sessions, passkeys, OAuth providers, and plugins into modern web stacks with real package and docs support.
A fast, configurable secrets scanner built by the creator of Gitleaks and backed by Aikido Security. Betterleaks detects leaked passwords, API keys, and tokens in git repositories, directories, and stdin with CEL-based validation and parallelized scanning.
Automates migration from ESLint and Prettier to Biome (formerly Rome) by parsing .eslintrc and .prettierrc configs, mapping rules to biome.json equivalents, and running biome check --apply for bulk reformatting.
Generates Blender Python (bpy) scripts that programmatically create Geometry Nodes modifier trees, using the node_groups API and GeometryNodeTree interface for parametric 3D asset generation.
Put an inline firewall and containment layer in front of agent network traffic, tool calls, and MCP traffic before you trust an agent with local secrets.
Add hard pre-execution guardrails to Claude Code so destructive shell commands are blocked before an agent can run them.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/python-scaffold
Python scaffold
Scaffold a Python project (FastAPI, Django, library, or CLI) with uv, type hints, testing, and dev tooling
/approve-review
Approve review
Open a review-action approval window by creating the ./.review-approved flag file. Takes an optional reason string that is recorded in the flag file and an unsigned approval log.
/list-pending
List pending
List the review actions that the review-governance policy blocked in this session. protect-mcp 0.7.4 writes no receipt for a denied call, so the list comes from the session, not from ./review-receipts/.
/compliance-check
Compliance check
Review software compliance controls, regulatory requirements, and audit readiness
/security-dependencies
Security dependencies
Scan dependencies for vulnerabilities and generate supply chain security evidence
/security-hardening
Security hardening
Orchestrate comprehensive security hardening with defense-in-depth strategy across all application layers
/security-sast
Security sast
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
/setup
Setup
Initialises the ShipMate pipeline in the current project. Creates the stories folder, sets up the pipeline state directory, and runs the initial codebase scan to generate project-doc.md and AGENTS.md.
/ship
Ship
Master pipeline entry point. Routes requirements from a story file through scan → orchestrate → architect → implement → review → QA → playwright stages. Use /ship stories/foo.md to start, /ship status to check progress, /ship resume to continue.
/business-case
Business case
Generate comprehensive investor-ready business case document with market, solution, financials, and strategy
/financial-projections
Financial projections
Create detailed 3-5 year financial model with revenue, costs, cash flow, and scenarios
/market-opportunity
Market opportunity
Generate comprehensive market opportunity analysis with TAM/SAM/SOM calculations
/rust-project
Rust project
Scaffold a Rust project (binary, library, workspace, or Axum web API) with Cargo, testing, and dev tooling
/tdd-cycle
Tdd cycle
Execute a comprehensive TDD workflow with strict red-green-refactor discipline
/tdd-green
Tdd green
Implement minimal code to make failing tests pass in TDD green phase
/tdd-red
Tdd red
Write comprehensive failing tests following TDD red phase principles
/tdd-refactor
Tdd refactor
Refactor code while keeping all tests green in TDD refactor phase
/issue
Issue
Resolve a GitHub issue from triage and root cause analysis through test-driven implementation and a pull request
/standup-notes
Standup notes
Generate async standup notes from git commits, Jira tickets, and Obsidian notes
/accessibility-audit
Accessibility audit
Audit UI code for WCAG compliance
PiG (Pi in Go) is a faithful Go port of upstream Pi, the TypeScript codebase behind the Pi coding agent. It is a parity-bound translation, not a rewrite: upstre…
1 views 0 likesAn AI Agent that lives in your pocket. Local-first and privacy focused.
2 views 0 likesUnofficial skill that teaches coding agents to build with TypeSafe AI's Jev: typed decisions, calibrated confidence, and prior art from 150+ community projects.
6 views 0 likesAdaptive Test-time Learning and Autonomous Specialization
4 views 0 likesPrediction-market trading engine — Wang Transform pricing on 291K+ contracts; paper-traded across Kalshi · Polymarket · Solana DFlow (Jito bundles) · 633 tests
3 views 0 likesKnowledge Management for Humans and Agents
5 views 0 likesOpen-source Claude Cowork / Codex / WorkBuddy alternative — a local-first AI office agent that turns one request into real PPTX, DOCX, XLSX and HTML files. Runs…
5 views 0 likesDeepAgent Code: AI coding agent with persistent memory and control plane
4 views 0 likesAwesome Jev — evidence-graded index of TypeSafe System One: SDKs, MCP tools, agents, apps and open models. 20 languages, rebuilt every 2 hours.
5 views 0 likesCLI for Telegram — agent-friendly, daemon-based, with webhook event push.
5 views 0 likesAI deep-research agent that turns any question into a cited report: plans searches, reads real sources, verifies evidence. Self-hosted, multi-provider, Docker-r…
4 views 0 likesEvent-stream AI Agent framework for building your persona bot 🍊
1 views 0 likesGive the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops t…
3 views 0 likesLocal Emperor-style AI agent with Vue WebUI, multi-provider LLMs, streaming chat, tools, skills, memory, and token telemetry.
2 views 0 likesOpen-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware researc…
8 views 0 likes"Never send a human to do a machine's job" - Open Source AI hacking agent
3 views 0 likesPrismer Cloud
3 views 0 likesMy Personal Blog (Robotics)
3 views 0 likesTau Coding Agent - like Pi, but twice as much
1 views 0 likesOpen-source alternative to OpenAI Dots: self-hosted AI chat, tools, approvals, connectors, and computer tasks.
0 views 0 likes