LLM Mart Basic
@llm-mart · Joined Jun 2026
Investigate a codebase, compare tools or approaches, verify current external or library facts, and research failures before making a substantive technical recommendation. Use for sufficiency and gap reviews; ordinary edits with settled requirements do not need a research stage.
Review authorized application code, configuration, designs or artifacts for concrete authorization, data exposure, injection, secret, dependency and LLM/tool security risks. Use for a requested security review or a change affecting a trust boundary.
Write, revise or review an agent skill (SKILL.md package).
Use when explaining System V AMD64, ARM AAPCS, RISC-V psABI, stack frames, variadic calls, or FFI register rules. Not for the Rust FFI binding layer: use rust-ffi.
Use when the user wants to classify abstractions as useful, bad, or busy and keep one shallow level. Not for tasks requiring source or remote-system changes.
Use when configuring ADC sampling time, DMA-driven ADC, calibration, or DAC channel setup on bare-metal MCUs. Not for the DMA stream itself: use dma-baremetal.
Use when creating AF_XDP sockets, configuring UMEM and XSK rings, writing an XDP redirect program, or choosing copy versus zero-copy mode. Not for full kernel bypass: use dpdk.
Use when a completed session needs an agent-environment retrospective. Not for an engineering retrospective from telemetry: use engineering-retrospective.
Use when asked to audit or repair agent surfaces (plugins, agents, skills, CLAUDE.md/AGENTS.md, docs, prompts, commands, hooks) or improve one skill at depth. Not for agent grading: use skill-doctor.
Use when a redacted, trimmed agent transcript must be appended to a GitHub PR or issue body, with human approval and preview. Not for automated or model-initiated insertion.
Use when the user describes an AI workflow gap or uses an ambiguous cross-session reference such as 'the PR Bob mentioned'. Not for tasks that require source or remote-system changes.
Use when the user requests a deep dive, exploratory analysis, or data analysis on BigQuery. Not for credential, publish, deploy, or irreversible changes.
Use when asked to design or change a public API, route, CLI flag, or module boundary. Not for remote, credential, publish, deploy, or irreversible changes.
Use when non-trivial code needs a design, codebase design or architecture needs improving, or one module needs targeted interface narrowing, seams, or testability. Not for diagrams, deploy, or irreversible changes.
Use when writing or porting AArch64 SIMD to SVE or SVE2: arm_sve.h intrinsics, predicates, vector-length-agnostic loops, auto-vectorization, or SVE registers in GDB. Not for NEON: use simd-intrinsics.
Use when the user knows what they mean but cannot express it completely or clearly. Not for discovery, ideation, or style-only editing: use unslop for style.
Use when asked to run /artifact-arena to generate and judge competing artifact implementations. Not for remote, credential, publish, deploy, or irreversible changes.
Use when eliciting intent/scope/referents or gating long/bundled/high-stakes/hard-to-undo work: exhaustive/collaborative/adversarial/gate/batch/interview/scan/proposal. Not for one fork: use decide.
Use when reading or writing AArch64 or AArch32 Thumb assembly, inline asm in C, AAPCS64 register roles, or NEON and SVE vector code. Not for ABI detail across ISAs: use abi-and-calling-conventions.
Use when reading or writing RV32/RV64 assembly, inline asm in C, the RISC-V psABI, IMAFD extension naming, compressed instructions, or QEMU RISC-V debugging.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/show-ticket
Show ticket
Display comprehensive ticket information including history, actions, and related entities
/sla-dashboard
Sla dashboard
View SLA status across tickets, including approaching breaches and at-risk tickets
/update-ticket
Update ticket
Update fields on an existing HaloPSA ticket including status, priority, and assignment
/create-deal
Create deal
Create a new deal in HubSpot with company association
/log-activity
Log activity
Log a note or create a task on a HubSpot contact, company, or deal
/lookup-company
Lookup company
Find a HubSpot company by name or domain and show associated contacts and deals
/pipeline-summary
Pipeline summary
Summarize the HubSpot deal pipeline - deals per stage, total value, and expected close dates
/search-contacts
Search contacts
Search HubSpot contacts by name, email, or company
/search-deals
Search deals
Search HubSpot deals by name, stage, or company
/find-company
Find company
Find a company in Hudu by name
/get-password
Get password
Retrieve a password from Hudu (with security logging)
/lookup-asset
Lookup asset
Find an asset in Hudu by name, hostname, serial number, or IP address
/search-articles
Search articles
Search Hudu knowledge base articles by keyword or phrase
/agent-inventory
Agent inventory
List and filter Huntress agents across organizations
/billing-report
Billing report
Generate a Huntress billing summary for a period
/incident-triage
Incident triage
Triage open Huntress incidents by severity
/investigate-incident
Investigate incident
Deep dive investigation into a specific Huntress incident with remediations
/org-health
Org health
Organization health check covering agents, incidents, and escalations
/resolve-escalation
Resolve escalation
Review and resolve a Huntress escalation
/compliance-report
Compliance report
Generate an ImmyBot software-compliance scorecard for a tenant or the whole fleet
Offline-first Python AI agent that runs a tiny research business: quotes each job against its own costs, collects via Stripe, fulfils with NVIDIA Nemotron, pays…
0 views 0 likesDSH 插件 · 注入式优化器 0.8(主线):你照常说话,它在你发送后,AI接收前把"这一轮到底要什么"理清楚,再把这份理解交给工作 AI(上下文注入) —— 原话不改写,条条带逐字依据。含控制界面(档位/权限/模型/上下文/只读工具)、拦截浮层(思维层+产出层)与真实 token 用量。可明显提升大多数模型的发挥稳…
0 views 0 likesReliable AI Skill + MCP toolkit for agent-driven desktop CAD automation.
0 views 0 likesCurated real-world use cases for Hermes Agent — the self-improving AI agent from Nous Research. Backed by primary sources.
0 views 0 likesAI Agent 教学仓库 | 系统化 LangChain、RAG、LangGraph、MCP 全栈实战代码 | 万字博客详解 | 开源可运行示例 | 从零构建智能体
0 views 0 likes从 0 复刻 WorkBuddy-style 桌面 AI 助手 Harness:24 章 Python 教程,覆盖 Agent Loop、工具调用、记忆系统、Sidecar、沙盒审计、DeepSeek/OpenAI 评测轨迹
0 views 0 likesMCP server and CLI tools for web search and crawling, built on SearXNG and Crawl4AI
0 views 0 likesDelta MCP is a free app that sits between your AI apps and their MCP servers: one program per task instead of one tool call per step, up to 24.1× fewer tokens i…
0 views 0 likesAva turns any Android 5+ device into a voice-first Home Assistant kiosk. Native C++ under the hood, so a 10-year-old tablet still listens, talks, and runs the h…
0 views 0 likesRoblox Studio macOS Window Capture Fix 2026: Real Screenshot Tool Instead of Magenta Playtest Glitch
0 views 0 likesLabTether
0 views 0 likes