LLM Mart Basic

@llm-mart · Joined Jun 2026

0 Followers 0 Reputation 13647 Contributions
Claude Skill blast-radius

Use when asked to determine what a change could break before it ships. Not for remote, credential, publish, deploy, or irreversible changes.

0
Claude Skill book-to-skill

Use when the user names one book, course, paper, or source document and asks to distill it into a reusable skill. Not for a folder of sources: use map-corpus.

0
Claude Skill bootloaders-embedded

Use when writing a custom bootloader, jumping to application code, relocating VTOR, or implementing DFU/USB firmware update on Cortex-M. Not for reset-to-main: use baremetal-startup.

0
Claude Skill bounded-model-checking-c

Use when C or C++ code needs memory-safety or undefined-behavior guarantees proved with CBMC, or ACSL contracts checked with Frama-C Eva or WP. Not for choosing the proof policy: use proof-driven.

0
Claude Skill branch-prediction-and-speculation

Use when explaining branch predictors, mispredict penalties, speculative execution, Spectre or Meltdown mitigations, or branchless code. Not for pipeline stage theory: use cpu-pipelines-and-hazards.

0
Claude Skill brand-authority

Use when the user asks for branded or style-governed output. Not for remote, credential, publish, deploy, or irreversible changes.

0
Claude Skill breaking-driven

Use when bloated code needs clean re-derivation, or the user says "this module is bloated" or "break it and rebuild". Not for untracked data or changes without VCS rollback.

0
Claude Skill browser-cookie-store

Use when the user runs /browser-cookie-store to populate the session cookie store from installed browsers. Not for remote, credential, publish, deploy, or irreversible changes.

0
Claude Skill browser-qa

Use when the user runs /browser-qa for report-only QA results without entering a fix loop. Not for remote, credential, publish, deploy, or irreversible changes.

0
Claude Skill browser-testing

Use when building, debugging, or verifying browser-rendered code, or running browser tests for PR- or branch-affected pages. Not for source, remote-system, credential, publish, or deploy changes.

0
Claude Skill build-acceleration

Use when reducing C/C++ compilation times with ccache, sccache, distcc, unity builds, precompiled headers, split DWARF, IWYU, or link time reduction.

0
Claude Skill burpsuite-project-parser

Use when asked to analyze a Burp Suite .burp project for audit items, request/response metadata, or captured traffic. Modes: parsed (default) and stream. Not for source or remote-system changes.

0
Claude Skill buyer-objection-research

Use when product copy needs buyer-objection evidence collected through approved, consented outreach. Not for unsolicited outreach or survey design.

0
Claude Skill buzzword-analysis

Use when the user wants the current jargon weather of a domain described without advocacy. Not for choosing a positioning move: use buzzword-hijack.

0
Claude Skill buzzword-hijack

Use when a user wants to choose and execute a bounded positioning move that rides a jargon wave. Not for describing the jargon weather of a domain: use buzzword-analysis.

0
Claude Skill c-hardening-baseline

Use when C code is written or audited and needs a pure-C baseline: standard, undefined behavior, integer and buffer safety, sanitizers, fuzzing, build flags. Not for C++: use modern-cpp-practices.

0
Claude Skill c-security-review

Use when the user requests a userspace C or C++ security review with a threat model and severity filter and wants validated findings. Not for kernel or bare-metal code: use kernel-security.

0
Claude Skill can-i-help

Use when the user asks "where to help", "contribution opportunities", or "find a good first issue". Returns data-backed first steps. Not for PR review queues: use gh-review-requests.

0
Claude Skill capstone

Use when the learner is ready to apply cleared concepts in a real project. Not for exercises or quizzes: use drill.

0
Claude Skill carbon-lang

Use when evaluating Carbon for a C++ code base, running the carbon toolchain from a nightly or Bazel build, or comparing Carbon with staying on C++. Not for C++ modules: use cpp-modules.

0
The AI-in-production safety playbook

Fourteen posts of being wrong in production, compressed to checkboxes

security prompt-engineering devops ai
Sep 30
The control plane was flapping because of a spinning disk

Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds

kubernetes sre incident-response observability
Sep 29
The overlay that pinged but wouldn't carry TCP

Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.

containers incident-response networking linux
Sep 28
Bringing a cluster back after the host rebooted

Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.

kubernetes sre containers incident-response
Sep 27
The agent is running in *your* shell

A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.

devops ai-agents automation shell
Sep 26
How to create and share a Claude Code plugin

A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.

agents security skill-md claude-code
Sep 25
The scaffolding that made it safe

None of the safety came from the model. It came from six boring habits.

git devops ai-agents claude-code
Sep 25
Claude Code skills vs. subagents: when to use each

Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.

agent-skills claude-code context
Sep 24
Knowing when to stop

Six hours in, one step left, everything green, and the incident that didn't happen

prompt-engineering ai ai-agents sre
Sep 24
CLAUDE.md vs. skills: where should Claude Code instructions live?

CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.

agent-skills claude-skills configuration context
Sep 23
Those are the other app's keys

Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it

security devops ai ai-agents
Sep 23
How to use remote MCP servers with the OpenAI Responses API

An API request routing a model's tool call through an approval gate to a remote MCP server

security mcp integrations open-api
Sep 22
The coverage audit before you delete the safety net

31 config keys, two audits, and why the first one was wrong in both directions

security devops ai-agents secrets-management
Sep 22
How to publish an MCP server to the official MCP Registry

The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.

security mcp
Sep 21
Rotating a leaked credential, in the right order

Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.

security devops ai-agents containers
Sep 21
MCP authentication explained: OAuth, scopes, and safe token handling

Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.

security mcp
Sep 20
Byte-identical or bust

"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks

security kubernetes verification
Sep 20
MCP stdio vs. Streamable HTTP: which transport should you use?

stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.

security mcp
Sep 19
Never let the AI print a secret

The most important rule wasn't about what I could change. It was about what I was allowed to display.

security kubernetes devops ai-agents
Sep 19
MCP tools vs. resources vs. prompts: when to use each

Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.

security mcp
Sep 18
/observability observability

Instrument services with structured logging, Prometheus metrics, and OpenTelemetry tracing. Build Grafana dashboards, write Prometheus alerting rules, run k6 load tests, and plan infrastructure capacity.

0
/opa opa

Generate, test, validate, explain, and debug OPA (Open Policy Agent) Rego policies and Conftest configurations. Covers deny/warn/violation rules, unit tests, regal linting, conftest fmt, namespace design, input shape analysis, and GitHub Actions integration. Use when asked to "write a policy", "test a rego file", "validate policies", "explain this rego", or "why is my policy not firing".

0
/openshift openshift

OpenShift SCC diagnosis and hardening, Route TLS patterns, OpenShift GitOps app delivery, and cluster upgrade validation.

0
/pr-review pr-review

Comprehensive PR review across six dimensions — cost impact, environment drift, ownership gaps, SOC 2 compliance, deprecated API / version hygiene, and rollback feasibility. Each mode inspects the diff and current file state, reports findings with severity, and recommends concrete fixes. Use when preparing a PR for merge, conducting a pre-deployment readiness check, or performing a post-merge risk assessment.

0
/preflight preflight

Production-readiness preflight check for a directory, repo, or single file. Auto-detects file types (Kubernetes manifests, Terraform, GitHub Actions workflows, Helm values/charts, Flux Kustomizations/HelmReleases, Dockerfiles, shell scripts) and applies type-specific checks across the whole scope. Returns a per-file summary table and aggregated verdict. Use before deploying, merging, or applying a folder of config. For PR diffs spanning multiple files use /platform-skills:pr-review instead. For deep Helm chart work use /platform-skills:helmchart instead.

0
/product product

Apply product thinking to platform work — DevEx audits, friction analysis, RFC/ADR drafting, incident communication, post-mortems, capacity planning, cost optimisation, and platform health review.

0
/renovate renovate

Generate renovate.json covering all dependency file types used in a repo, emit a GitHub Actions workflow that validates renovate.json on every PR, or generate a pre-commit hook for local validation.

0
/runtime-security runtime-security

Detect and respond to in-container threats at the syscall level using Falco (eBPF-based, CNCF, open-source, no license cost). Covers Falco installation on EKS/GKE with eBPF driver, custom rule authoring, alert routing via Falcosidekick, rule debugging, and bridging Falco runtime signals to Kyverno admission enforcement. Use when asked to "detect privilege escalation in containers", "set up runtime threat detection", "write a Falco rule", "route Falco alerts to Slack", or "debug why my Falco rule is not firing".

0
/secrets secrets

Secrets strategy, External Secrets Operator scaffolding, Sealed Secrets seal/rotate/backup, rotation runbooks, and Kubernetes-side secrets audit.

0
/self-improve self-improve

Bootstrap and operate a self-improving agent workspace. Scaffolds .learnings/ and memory/ directories, captures errors and learnings during a session, detects recurring patterns, recalls verified lessons, and promotes stable entries to scoped rule files (.claude/rules/ or ~/.claude/rules/). Also implements the Proactive Agent pillars — WAL protocol, working buffer, SESSION-STATE, daily notes, VBR, VFM scoring, ADL decision logic, heartbeat, and reverse prompting. Use when asked to "remember this lesson", "set up agent memory", "log that error", "what did we learn about X", "promote learnings", "revoke that rule", "capture session state", or "enable proactive mode".

0
/setup-agents setup-agents

Scaffold a multi-agent AI setup for any repo. Scans the codebase, interviews the developer, generates agent configs for whichever AI tools the repo uses (Copilot, Claude Code, Cursor, Codex, Windsurf). Use when asked to "set up agents", "scaffold Copilot agents", or "create an AGENTS.md".

0
/supply-chain supply-chain

Secure the software supply chain from source to running container. Covers Cosign keyless image signing (Sigstore/Rekor), SBOM generation and attestation (Syft), vulnerability scanning with severity gates (Trivy/Grype), SLSA Level 2 provenance, and Kyverno/OPA admission enforcement. All open-source, no license cost. Use when asked to "sign my image", "generate an SBOM", "scan for CVEs", "attest build provenance", "enforce image signatures in Kubernetes", or "implement SLSA".

0
/terraform terraform

Runs through the full Terraform validation pipeline — fmt, validate, tflint, security scan — and reviews a module or plan for blast radius, IAM risk, and state impact.

0
/triage triage

Triages a PR comment — from a bot (Copilot, CI) or a human reviewer. Routes to the `triage_helper.py` helper for identity checks, thread snapshotting, isolated-worktree fixes, and publish/reply/resolve mechanics; you classify the finding and apply a justified fix. `--dry-run` is fully read-only (investigation and a printed plan, zero mutations). `--no-resolve` runs the full fix/reply workflow but never resolves a thread. Run from inside the repo.

0
/trivy trivy

Scan container images, filesystems, git repos, and existing SBOMs for CVEs, secrets, and license violations using Trivy. Covers local CLI, CI severity gates with SARIF upload, and continuous monitoring via Trivy Operator (Flux HelmRelease). Use when asked to "scan my image", "check for CVEs", "scan this repo for secrets", "scan an SBOM", or "set up continuous cluster vulnerability monitoring". IaC misconfig → /platform-skills:checkov. Admission posture → /platform-skills:kyverno. Image signing/SBOM generation → /platform-skills:supply-chain.

0
/zizmor zizmor

Audit GitHub Actions workflows, composite actions, Dependabot configs, and pre-commit configs for security findings using zizmor — template injection, credential persistence, unpinned uses, over-broad permissions, impostor commits. Covers local CLI, auto-fix, zizmor.yml policy, severity-based CI gates, SARIF upload, and pre-commit. Use when asked to "audit my workflows", "run zizmor", "is this workflow safe", "check for template injection", "pin my actions", or "set up a zizmor CI gate". Workflow syntax and shell errors → /platform-skills:github-actions (actionlint). IaC misconfig → /platform-skills:checkov. Image and dependency CVEs → /platform-skills:trivy. Keeping SHA pins fresh → /platform-skills:renovate.

0
/README README

반복 작업을 `/이름` 으로 호출. 파일명 = 커맨드 이름(`fix-issue.md` → `/fix-issue`).

0
/fix-issue fix-issue

이슈 #$ARGUMENTS 를 처리한다(이슈 우선 워크플로):

0
/knowledge-graph Knowledge graph

AGENTS.md 생태계(rules·memory·agents·skills·commands·workflows)의 연결 구조를

0
/sdlc-cycle sdlc-cycle

이슈/기획서 기준 SDLC 한 사이클(이슈→개발→테스트→검증→PR/MR)을 사람 개입 없이 자동 실행.

0
Solvent Agent

Offline-first Python AI agent that runs a tiny research business: quotes each job against its own costs, collects via Stripe, fulfils with NVIDIA Nemotron, pays…

0 views 0 likes
Dsh Prompt Optimizer

DSH 插件 · 注入式优化器 0.8(主线):你照常说话,它在你发送后,AI接收前把"这一轮到底要什么"理清楚,再把这份理解交给工作 AI(上下文注入) —— 原话不改写,条条带逐字依据。含控制界面(档位/权限/模型/上下文/只读工具)、拦截浮层(思维层+产出层)与真实 token 用量。可明显提升大多数模型的发挥稳…

0 views 0 likes
Solidworks Automation Skill

Reliable AI Skill + MCP toolkit for agent-driven desktop CAD automation.

0 views 0 likes
Awesome Hermes Usecases

Curated real-world use cases for Hermes Agent — the self-improving AI agent from Nous Research. Backed by primary sources.

0 views 0 likes
Agent Craft

AI Agent 教学仓库 | 系统化 LangChain、RAG、LangGraph、MCP 全栈实战代码 | 万字博客详解 | 开源可运行示例 | 从零构建智能体

0 views 0 likes
Learn Workbuddy

从 0 复刻 WorkBuddy-style 桌面 AI 助手 Harness:24 章 Python 教程,覆盖 Agent Loop、工具调用、记忆系统、Sidecar、沙盒审计、DeepSeek/OpenAI 评测轨迹

0 views 0 likes
SearxNcrawl

MCP server and CLI tools for web search and crawling, built on SearXNG and Crawl4AI

0 views 0 likes
Mcpdelta

Delta MCP is a free app that sits between your AI apps and their MCP servers: one program per task instead of one tool call per step, up to 24.1× fewer tokens i…

0 views 0 likes
Ava Pro

Ava turns any Android 5+ device into a voice-first Home Assistant kiosk. Native C++ under the hood, so a 10-year-old tablet still listens, talks, and runs the h…

0 views 0 likes
Studio Live Window Capture

Roblox Studio macOS Window Capture Fix 2026: Real Screenshot Tool Instead of Magenta Playtest Glitch

0 views 0 likes
Labtether

LabTether

0 views 0 likes