LLM Mart Basic
@llm-mart · Joined Jun 2026
A fast, configurable secrets scanner built by the creator of Gitleaks and backed by Aikido Security. Betterleaks detects leaked passwords, API keys, and tokens in git repositories, directories, and stdin with CEL-based validation and parallelized scanning.
Automates migration from ESLint and Prettier to Biome (formerly Rome) by parsing .eslintrc and .prettierrc configs, mapping rules to biome.json equivalents, and running biome check --apply for bulk reformatting.
Generates Blender Python (bpy) scripts that programmatically create Geometry Nodes modifier trees, using the node_groups API and GeometryNodeTree interface for parametric 3D asset generation.
Put an inline firewall and containment layer in front of agent network traffic, tool calls, and MCP traffic before you trust an agent with local secrets.
Add hard pre-execution guardrails to Claude Code so destructive shell commands are blocked before an agent can run them.
Use CC Safety Net when coding-agent CLIs need pre-execution hooks that block destructive commands, secret access, and unsafe file operations before tools run.
Scan staged changes, commits, or repositories for secrets before they leave the workstation or CI job, instead of relying on a later platform-side catch.
Add a runtime guard that evaluates agent actions, blocks dangerous commands or secret exposure, and audits new skills before they run.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
Use MCP Inspector to connect to local or remote servers, inspect capabilities, call tools, read resources, test prompts, and diagnose failures before release.
Build an MCP server in TypeScript with focused tools, validated schemas, local and remote transports, Inspector tests, and production security controls.
An MCP server exposes tools, resources, or prompts through a standard protocol so an AI application can discover and use external capabilities.
/agent-audit
Agent audit
Audit agents spawned in the current/last run against the agent-selection taxonomy
/agent-diversity-review
Agent diversity review
Run the Agent Diversity Review gate and emit the result table
/audit-cron-arc
audit-cron-arc
Meta-analyze the effectiveness of a /loop arc — per-iteration metrics, LOC delta trend, saturation detection, and a keep/lengthen/delete recommendation.
/audit-doctrine
Audit doctrine
Audit the rules/ directory for missing foundational principles; output gap list with priority and justification
/audit-hook-wiring
Audit hook wiring
Validate ~/.claude/settings.json hooks block — event names, file existence, executability, matcher syntax; --fix repairs common issues
/audit-mcp-error-semantics
Audit mcp error semantics
Catch Resend-class bug (isError: false on HTTP 4xx/5xx) across all MCP server tool handlers
/audit-mcp-fleet
Audit mcp fleet
Healthcheck + drift detect + rotation-reminder across all MCP servers in ~/.claude/mcp-registry.json
/audit-mcp-mock-drift
Audit mcp mock drift
Catch mock/live divergence in MCP eval golden tests (anti-pattern #2 from eval-mock-mode-discipline)
/audit-prune-completeness
Audit prune completeness
Catch the github-mcp class of bug — CallTools handlers that exist but are invisible to Claude because ListTools never advertises them (orphaned), or ListTools entries that have no handler (zombies)
/audit-router
Audit router
Validate _router.md — check every referenced skill file exists; surface stale entries + orphan files; --fix prunes or stubs
/audit-tool-surface
Audit tool surface
List every active tool across all MCP servers and flag cross-MCP duplicates and semantic overlaps
/create-specialist-agent
Create specialist agent
Scaffold a new spawnable specialist agent def and register it in the agent taxonomy
/customer-changelog-check
Customer changelog check
Audit whether user-visible changes in the current session have matching CHANGELOG.md entries; report MISSING with suggested lines; --fix auto-appends
/dashboard-cockpit
Dashboard cockpit
Repeatable pass upgrading an Angular admin dashboard into a compact black-and-cyan developer-cockpit PWA
/deploy-forged-mcp
Deploy forged mcp
Deploy an MCP server generated by forge-from-openapi --target=mcp-server; detect transport, deploy, smoke-test, print .claude.json snippet
/drift-check
Drift check
Run the drift-detection checklist (incl. agent-drift signals); report + fix in-turn
/execute-prp
Execute prp
Execute a PRP — TodoWrite breakdown, parallel implementation, validate every gate, deploy, prove on prod
/final-review
Final review
Orchestrate the final review fan-out (integration + diversity + risk + release readiness)
/forge-from-openapi
Forge from openapi
Auto-generate a Claude Code skill (commands + types + client) from any OpenAPI 3.x spec URL or file path
/forge-graphql-skill
Forge graphql skill
Scaffold a complete Claude Code skill (commands + types + client) from a GraphQL endpoint or local schema file
The fastest way to put Volcengine Ark in your terminal and your AI agent — go from prompt to generated media, multimodal answer, or deployed endpoint in a sin…
12 views 0 likes本地私有、开源的自进化跨平台 AI 内容发现 Agent:先理解你,再主动从 B站、小红书、抖音、YouTube、X、知乎、Reddit、微博等平台与开放 Web 寻找内容。(支持 deepseek harness 插件) | Local-first open-source cross-platform AI cont…
13 views 0 likesPersistent memory for AI coding agents — one verified kb_search replaces the grep/find/ls orientation loop. Cross-repo, CPU-only, zero token spend.
13 views 0 likesAI 时代的伯克希尔:基于 Claude Code / Codex 的价值投资研究框架。巴菲特·芒格·段永平·李录四大师方法论 + 多Agent并行研究。| AI-era Berkshire: a value investing research framework built for Claude Code / Co…
13 views 0 likesThe batteries-included, No-Code FinOps automation platform, with the AI you trust.
14 views 0 likesOpen-source 3D AI agent framework — GLB/glTF avatars with LLM brains, memory, emotions, and autonomous payments. MCP server · x402 · Solana/EVM · Three.js. Embe…
27 views 0 likesXLSX parser for LLMs, RAG, LangChain, LangGraph, CrewAI, Claude, MCP — turns Excel (.xlsx) into citation-ready JSON with formulas, charts, dependency graphs, an…
24 views 0 likesHermes-Relay — Your Hermes AI agent, in your pocket — chat, voice, and control.
14 views 0 likesA minimalist, terminal-native coding agent written in C.
13 views 0 likesAI-powered OSINT agent with interactive REPL, MCP server, and CLI. 19 tools. Works with Claude, GPT-4, or local models. For authorized security research only.
12 views 0 likesAI pair programming in your terminal — one static binary, sub-ms startup, any model
11 views 0 likesWhere data access meets operational intelligence
11 views 0 likesBuild your own security agents. Open-source framework for agents with live, read-only access to your infrastructure, with no path to widen it. Reasons across AW…
11 views 0 likesMulti-workspace terminal aggregator with Claude Code AI integration
15 views 0 likesGo implementation of AI coding agent
13 views 0 likesHarness engineering beginner tutorial, from 0 to 1
15 views 0 likesGenerate images directly in DeepSeek Harness chats
26 views 0 likesA smarter, self-hosted AI assistant — multi-user, multi-agent.
15 views 0 likesTurn any research paper into a commercialization report — 6 AI agents, TRL/MRL scoring, patent landscape, market intelligence, verified citations. DeepSeek / Op…
14 views 0 likesPower BI CLI - semantic models (.NET TOM) and PBIR reports for token-efficient AI agent usage, built for Claude Code
14 views 0 likes