LLM Mart Basic
@llm-mart · Joined Jun 2026
本Skill内置从学到装|装修课堂知识库,专门帮业主审核装修合同、识别预算陷阱、防范定金套路、避免增项偷项、看懂报价单、判断售后保障。适合准备签装修合同、拿到报价单不知怎么看、被要求交定金、遇到中途加钱的等场景使用。触发场景包括"装修合同怎么签""报价单怎么看""定金能退吗""套餐能签吗""装修增项怎么办""怎么选装修公司"等涉及装修合同审核的所有问题。
【装修最怕加钱必看】你担心装修中途不断加钱吗?报价单看不懂、增项防不住、水电开工后翻倍、拆除冒出各种刺客?这个Skill专治各种加钱套路——问增项、问加钱、问报价单、问隐形消费、问偷项漏项、问预算超了,全部覆盖。适合拿到报价单、准备签合同、担心中途被加价的业主。
【拿到报价单必看】你拿到装修报价单了吗?看不懂、怕被坑、不知道价格合不合理?这个Skill内置装修课堂知识库,直接帮你审核报价单——问报价单怎么看、问预算陷阱、问单价猫腻、问隐形消费、问水电估价、问半包全包区别、问厨卫费用,全部覆盖。适合拿到报价单不知怎么看、比较多家报价不知怎么选、被低价吸引担心有坑的业主。
【装修方案拿不准必看】你的装修方案合理吗?不知道布局对不对、收纳够不够、风格怎么选、户型能不能改?这个Skill内置装修课堂381篇文章,直接诊断你的方案——问设计布局、问户型改造、问收纳规划、问风格搭配、问翻车避坑、问设计师怎么选,全部覆盖。适合正在确认方案、担心布局不合理、想优化空间利用的业主。
【装修隐蔽工程必看】水电是装修第一步、最容易被坑的环节——绕路加米数、不估价坐地起价、进口水管忽悠、水电包死偷工、走顶多花钱、横平竖直当质量、验收一堆专业名词看不懂?这个Skill专治各种水电套路,覆盖水电规划、计费方式、估价谈判、验收标准、常见坑点。适合拿到水电报价、准备交底、担心被加价、想自己看懂水电的业主。
【第一次装修必看】你是第一次装修吗?不知道从哪下手、不清楚下一步该做什么、担心被工长忽悠、想搞清楚装修全流程?这个Skill内置装修课堂知识库,直接教你装修全流程——问收房验房、问开工交底、问拆除砌墙、问水电改造、问瓦工防水、问木工吊顶、问油漆墙面、问安装验收、问工期管理,全部覆盖。适合第一次装修、想搞清楚每一步该做什么的业主。
【装修环保必看】你担心装修污染吗?怕甲醛超标、不知道环保材料怎么选、被甲醛治理公司忽悠、搞不懂E0/ENF级?这个Skill内置装修课堂知识库,直接教你环保真相——问甲醛、问板材环保、问乳胶漆、问壁纸壁布、问甲醛治理、问通风方法,全部覆盖。适合担心装修污染、有孩子/老人要入住、想装出健康家的业主。
【装修翻车必看】你家装修翻车了吗?瓷砖空鼓、墙面开裂、漏水、尺寸错了、插座不够、灯偏了?这个Skill内置装修课堂知识库,直接教你怎么补救——问翻车怎么办、问补救方法、问修复成本、问能不能自己搞定,全部覆盖。适合装修已经翻车、不知道怎么办、返工成本太高想找替代方案的业主。
【装修小白必看】你是第一次装修的小白吗?什么都不知道、不知道问什么、怕被坑又不知道坑在哪?这个Skill覆盖装修全流程——问找公司、问签合同、问施工、问选材、问设计、问布局、问家具家电,一站式解答你的装修疑问。适合装修小白、第一次装修、不知道从哪下手的业主。
【算装修要花多少钱】输入户型/面积/新房旧房/装修档次,一键估算装修预算——半包施工费、主材费、定制柜、间接费全算清,并告诉你预算单怎么看、容易超在哪。适合想知道"我家装修大概多少钱""半包全包差多少""预算怎么做才不超"的业主。
【儿童房装修必看】家里有小孩、正准备要孩子、或想给儿童房做环保安全装修?这个 Skill 内置装修课堂知识库,专门讲"适童化"——儿童是最易受甲醛伤害的人群,儿童房必须实木/ENF/控总量。问儿童房怎么装环保、问儿童房墙面地面用什么、问儿童家具选实木还是人造板、问孩子学习/游戏专区怎么规划、问有娃家庭怎么防磕碰防污染,全部覆盖。适合家里有娃、备孕婚房、想装出健康儿童房的业主。
Automate creating Legado reading source files by analyzing websites with AI to generate valid JSON for efficient source development.
Web accessibility end to end - WCAG 2.2 conformance, legal obligations (EAA, ADA Title II), auditing with automated + keyboard + screen-reader passes, and the failures that appear on most sites. Triggers on: accessibility, a11y, WCAG, WCAG 2.2, AA conformance, EAA, European Acces
Author, index, and lint Architecture Decision Records — append-only memory that recovers the WHY behind a system's shape. Triggers on: adr, architecture decision record, decision log, record this decision, supersede an adr, why was this decided, adr template, next adr number.
API design patterns for REST, gRPC, and GraphQL. Use for: api design, REST, gRPC, GraphQL, protobuf, schema design, api versioning, pagination, rate limiting, error format, OpenAPI, API authentication, JWT, OAuth2, API gateway, webhook, idempotency.
Astro framework patterns, islands architecture, content collections, rendering strategies, and deployment. Use for: astro, islands architecture, content collections, astro cloudflare, view transitions, partial hydration, astrojs, SSG, SSR, hybrid rendering, astro adapter.
ASUS router config and hardening: Asuswrt-Merlin, security hardening, encrypted DNS (DoT/DoH), VPN (WireGuard/OpenVPN), guest networks, VLAN/IoT isolation, AiMesh, AiProtection. Triggers on: asus router, asuswrt, merlin, wireguard router, AiProtection, AiMesh, nvram, jffs, IoT is
Atom of Thoughts (AoT) reasoning - decompose complex problems into atomic units with confidence tracking and backtracking. For genuinely complex reasoning, not everyday questions. Triggers on: atomise, complex reasoning, decompose problem, structured thinking, verify hypothesis.
Authentication and authorization patterns - JWT, OAuth2, sessions, RBAC, ABAC, passkeys, MFA, identity-aware proxies, and Better Auth. Use for: authentication, jwt, oauth2, session, login, rbac, abac, passkey, mfa, totp, api key, token, cookie, csrf, bearer token, refresh token,
Evaluate current session for skill-worthy workflows and create reusable skills. Triggers on: auto-skill, create skill from session, save workflow, capture this as a skill.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/observability
observability
Instrument services with structured logging, Prometheus metrics, and OpenTelemetry tracing. Build Grafana dashboards, write Prometheus alerting rules, run k6 load tests, and plan infrastructure capacity.
/opa
opa
Generate, test, validate, explain, and debug OPA (Open Policy Agent) Rego policies and Conftest configurations. Covers deny/warn/violation rules, unit tests, regal linting, conftest fmt, namespace design, input shape analysis, and GitHub Actions integration. Use when asked to "write a policy", "test a rego file", "validate policies", "explain this rego", or "why is my policy not firing".
/openshift
openshift
OpenShift SCC diagnosis and hardening, Route TLS patterns, OpenShift GitOps app delivery, and cluster upgrade validation.
/pr-review
pr-review
Comprehensive PR review across six dimensions — cost impact, environment drift, ownership gaps, SOC 2 compliance, deprecated API / version hygiene, and rollback feasibility. Each mode inspects the diff and current file state, reports findings with severity, and recommends concrete fixes. Use when preparing a PR for merge, conducting a pre-deployment readiness check, or performing a post-merge risk assessment.
/preflight
preflight
Production-readiness preflight check for a directory, repo, or single file. Auto-detects file types (Kubernetes manifests, Terraform, GitHub Actions workflows, Helm values/charts, Flux Kustomizations/HelmReleases, Dockerfiles, shell scripts) and applies type-specific checks across the whole scope. Returns a per-file summary table and aggregated verdict. Use before deploying, merging, or applying a folder of config. For PR diffs spanning multiple files use /platform-skills:pr-review instead. For deep Helm chart work use /platform-skills:helmchart instead.
/product
product
Apply product thinking to platform work — DevEx audits, friction analysis, RFC/ADR drafting, incident communication, post-mortems, capacity planning, cost optimisation, and platform health review.
/renovate
renovate
Generate renovate.json covering all dependency file types used in a repo, emit a GitHub Actions workflow that validates renovate.json on every PR, or generate a pre-commit hook for local validation.
/runtime-security
runtime-security
Detect and respond to in-container threats at the syscall level using Falco (eBPF-based, CNCF, open-source, no license cost). Covers Falco installation on EKS/GKE with eBPF driver, custom rule authoring, alert routing via Falcosidekick, rule debugging, and bridging Falco runtime signals to Kyverno admission enforcement. Use when asked to "detect privilege escalation in containers", "set up runtime threat detection", "write a Falco rule", "route Falco alerts to Slack", or "debug why my Falco rule is not firing".
/secrets
secrets
Secrets strategy, External Secrets Operator scaffolding, Sealed Secrets seal/rotate/backup, rotation runbooks, and Kubernetes-side secrets audit.
/self-improve
self-improve
Bootstrap and operate a self-improving agent workspace. Scaffolds .learnings/ and memory/ directories, captures errors and learnings during a session, detects recurring patterns, recalls verified lessons, and promotes stable entries to scoped rule files (.claude/rules/ or ~/.claude/rules/). Also implements the Proactive Agent pillars — WAL protocol, working buffer, SESSION-STATE, daily notes, VBR, VFM scoring, ADL decision logic, heartbeat, and reverse prompting. Use when asked to "remember this lesson", "set up agent memory", "log that error", "what did we learn about X", "promote learnings", "revoke that rule", "capture session state", or "enable proactive mode".
/setup-agents
setup-agents
Scaffold a multi-agent AI setup for any repo. Scans the codebase, interviews the developer, generates agent configs for whichever AI tools the repo uses (Copilot, Claude Code, Cursor, Codex, Windsurf). Use when asked to "set up agents", "scaffold Copilot agents", or "create an AGENTS.md".
/supply-chain
supply-chain
Secure the software supply chain from source to running container. Covers Cosign keyless image signing (Sigstore/Rekor), SBOM generation and attestation (Syft), vulnerability scanning with severity gates (Trivy/Grype), SLSA Level 2 provenance, and Kyverno/OPA admission enforcement. All open-source, no license cost. Use when asked to "sign my image", "generate an SBOM", "scan for CVEs", "attest build provenance", "enforce image signatures in Kubernetes", or "implement SLSA".
/terraform
terraform
Runs through the full Terraform validation pipeline — fmt, validate, tflint, security scan — and reviews a module or plan for blast radius, IAM risk, and state impact.
/triage
triage
Triages a PR comment — from a bot (Copilot, CI) or a human reviewer. Routes to the `triage_helper.py` helper for identity checks, thread snapshotting, isolated-worktree fixes, and publish/reply/resolve mechanics; you classify the finding and apply a justified fix. `--dry-run` is fully read-only (investigation and a printed plan, zero mutations). `--no-resolve` runs the full fix/reply workflow but never resolves a thread. Run from inside the repo.
/trivy
trivy
Scan container images, filesystems, git repos, and existing SBOMs for CVEs, secrets, and license violations using Trivy. Covers local CLI, CI severity gates with SARIF upload, and continuous monitoring via Trivy Operator (Flux HelmRelease). Use when asked to "scan my image", "check for CVEs", "scan this repo for secrets", "scan an SBOM", or "set up continuous cluster vulnerability monitoring". IaC misconfig → /platform-skills:checkov. Admission posture → /platform-skills:kyverno. Image signing/SBOM generation → /platform-skills:supply-chain.
/zizmor
zizmor
Audit GitHub Actions workflows, composite actions, Dependabot configs, and pre-commit configs for security findings using zizmor — template injection, credential persistence, unpinned uses, over-broad permissions, impostor commits. Covers local CLI, auto-fix, zizmor.yml policy, severity-based CI gates, SARIF upload, and pre-commit. Use when asked to "audit my workflows", "run zizmor", "is this workflow safe", "check for template injection", "pin my actions", or "set up a zizmor CI gate". Workflow syntax and shell errors → /platform-skills:github-actions (actionlint). IaC misconfig → /platform-skills:checkov. Image and dependency CVEs → /platform-skills:trivy. Keeping SHA pins fresh → /platform-skills:renovate.
/README
README
반복 작업을 `/이름` 으로 호출. 파일명 = 커맨드 이름(`fix-issue.md` → `/fix-issue`).
/fix-issue
fix-issue
이슈 #$ARGUMENTS 를 처리한다(이슈 우선 워크플로):
/knowledge-graph
Knowledge graph
AGENTS.md 생태계(rules·memory·agents·skills·commands·workflows)의 연결 구조를
/sdlc-cycle
sdlc-cycle
이슈/기획서 기준 SDLC 한 사이클(이슈→개발→테스트→검증→PR/MR)을 사람 개입 없이 자동 실행.
PiG (Pi in Go) is a faithful Go port of upstream Pi, the TypeScript codebase behind the Pi coding agent. It is a parity-bound translation, not a rewrite: upstre…
1 views 0 likesAn AI Agent that lives in your pocket. Local-first and privacy focused.
3 views 0 likesUnofficial skill that teaches coding agents to build with TypeSafe AI's Jev: typed decisions, calibrated confidence, and prior art from 150+ community projects.
6 views 0 likesAdaptive Test-time Learning and Autonomous Specialization
4 views 0 likesPrediction-market trading engine — Wang Transform pricing on 291K+ contracts; paper-traded across Kalshi · Polymarket · Solana DFlow (Jito bundles) · 633 tests
3 views 0 likesKnowledge Management for Humans and Agents
5 views 0 likesOpen-source Claude Cowork / Codex / WorkBuddy alternative — a local-first AI office agent that turns one request into real PPTX, DOCX, XLSX and HTML files. Runs…
5 views 0 likesDeepAgent Code: AI coding agent with persistent memory and control plane
4 views 0 likesAwesome Jev — evidence-graded index of TypeSafe System One: SDKs, MCP tools, agents, apps and open models. 20 languages, rebuilt every 2 hours.
5 views 0 likesCLI for Telegram — agent-friendly, daemon-based, with webhook event push.
5 views 0 likesAI deep-research agent that turns any question into a cited report: plans searches, reads real sources, verifies evidence. Self-hosted, multi-provider, Docker-r…
4 views 0 likesEvent-stream AI Agent framework for building your persona bot 🍊
1 views 0 likesGive the agent a machine. Just not yours. Each AI coding agent gets its own isolated machine with root, Docker, and systemd - active defense detects and stops t…
3 views 0 likesLocal Emperor-style AI agent with Vue WebUI, multi-provider LLMs, streaming chat, tools, skills, memory, and token telemetry.
2 views 0 likesOpen-source AI reverse-engineering agent platform and MCP server for Ghidra, Frida, x64dbg and Rizin — automated PE/APK/binary analysis, CTF and malware researc…
8 views 0 likes"Never send a human to do a machine's job" - Open Source AI hacking agent
3 views 0 likesPrismer Cloud
3 views 0 likesMy Personal Blog (Robotics)
3 views 0 likesTau Coding Agent - like Pi, but twice as much
1 views 0 likesOpen-source alternative to OpenAI Dots: self-hosted AI chat, tools, approvals, connectors, and computer tasks.
0 views 0 likes