LLM Mart Basic
@llm-mart · Joined Jun 2026
Use when building, debugging, or verifying browser-rendered code, or running browser tests for PR- or branch-affected pages. Not for source, remote-system, credential, publish, or deploy changes.
Use when reducing C/C++ compilation times with ccache, sccache, distcc, unity builds, precompiled headers, split DWARF, IWYU, or link time reduction.
Use when asked to analyze a Burp Suite .burp project for audit items, request/response metadata, or captured traffic. Modes: parsed (default) and stream. Not for source or remote-system changes.
Use when product copy needs buyer-objection evidence collected through approved, consented outreach. Not for unsolicited outreach or survey design.
Use when the user wants the current jargon weather of a domain described without advocacy. Not for choosing a positioning move: use buzzword-hijack.
Use when a user wants to choose and execute a bounded positioning move that rides a jargon wave. Not for describing the jargon weather of a domain: use buzzword-analysis.
Use when C code is written or audited and needs a pure-C baseline: standard, undefined behavior, integer and buffer safety, sanitizers, fuzzing, build flags. Not for C++: use modern-cpp-practices.
Use when the user requests a userspace C or C++ security review with a threat model and severity filter and wants validated findings. Not for kernel or bare-metal code: use kernel-security.
Use when the user asks "where to help", "contribution opportunities", or "find a good first issue". Returns data-backed first steps. Not for PR review queues: use gh-review-requests.
Use when the learner is ready to apply cleared concepts in a real project. Not for exercises or quizzes: use drill.
Use when evaluating Carbon for a C++ code base, running the carbon toolchain from a nightly or Bazel build, or comparing Carbon with staying on C++. Not for C++ modules: use cpp-modules.
Use when initializing, running, measuring coverage, or triaging a cargo-fuzz target in a Rust crate. Not for remote, credential, publish, deploy, or irreversible changes.
Use when managing Cargo workspaces, feature flags, build scripts, CI caching, dependency auditing, or Cargo.lock with Rust.
Use when prompt-doctrine is duplicated, drifted, or conflicting across output-style embeds and external harness AGENTS files. Not for editing the canonical baseline itself.
Use when the human returns after a gap, cannot follow the project, asks what happened, or wants a visual HTML recap page. Not for onboarding: use onboard. Not for handoff: use handoff.
Use when an Algorand, Cairo, Cosmos SDK, Solana, Substrate, or TON codebase needs vulnerability scanning with reachability-backed findings. Not for non-chain review: use security-review.
Use when a release or a since-tag window needs user-facing release notes drafted. Not for publishing the release.
Use when a human explicitly asks for a full repository agent-compatibility pass returning a scored report with prioritized fixes. Not for tasks that require source or remote-system changes.
Use when the user asks to cherry-pick, backport, or apply a hotfix to a release branch. Not for merging feature branches or cutting new release branches.
Use when the user explicitly asks to build, modify, or publish a Manifest V3 Chrome extension. Not for store submission without human-gated credentials.
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/python-scaffold
Python scaffold
Scaffold a Python project (FastAPI, Django, library, or CLI) with uv, type hints, testing, and dev tooling
/approve-review
Approve review
Open a review-action approval window by creating the ./.review-approved flag file. Takes an optional reason string that is recorded in the flag file and an unsigned approval log.
/list-pending
List pending
List the review actions that the review-governance policy blocked in this session. protect-mcp 0.7.4 writes no receipt for a denied call, so the list comes from the session, not from ./review-receipts/.
/compliance-check
Compliance check
Review software compliance controls, regulatory requirements, and audit readiness
/security-dependencies
Security dependencies
Scan dependencies for vulnerabilities and generate supply chain security evidence
/security-hardening
Security hardening
Orchestrate comprehensive security hardening with defense-in-depth strategy across all application layers
/security-sast
Security sast
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
/setup
Setup
Initialises the ShipMate pipeline in the current project. Creates the stories folder, sets up the pipeline state directory, and runs the initial codebase scan to generate project-doc.md and AGENTS.md.
/ship
Ship
Master pipeline entry point. Routes requirements from a story file through scan → orchestrate → architect → implement → review → QA → playwright stages. Use /ship stories/foo.md to start, /ship status to check progress, /ship resume to continue.
/business-case
Business case
Generate comprehensive investor-ready business case document with market, solution, financials, and strategy
/financial-projections
Financial projections
Create detailed 3-5 year financial model with revenue, costs, cash flow, and scenarios
/market-opportunity
Market opportunity
Generate comprehensive market opportunity analysis with TAM/SAM/SOM calculations
/rust-project
Rust project
Scaffold a Rust project (binary, library, workspace, or Axum web API) with Cargo, testing, and dev tooling
/tdd-cycle
Tdd cycle
Execute a comprehensive TDD workflow with strict red-green-refactor discipline
/tdd-green
Tdd green
Implement minimal code to make failing tests pass in TDD green phase
/tdd-red
Tdd red
Write comprehensive failing tests following TDD red phase principles
/tdd-refactor
Tdd refactor
Refactor code while keeping all tests green in TDD refactor phase
/issue
Issue
Resolve a GitHub issue from triage and root cause analysis through test-driven implementation and a pull request
/standup-notes
Standup notes
Generate async standup notes from git commits, Jira tickets, and Obsidian notes
/accessibility-audit
Accessibility audit
Audit UI code for WCAG compliance
面向中文开发者的 Claude Code Skills / Agents / Plugins 精选与原创技能库|按场景分类|复制即装|持续更新
17 views 0 likes原生 macOS Git 客户端,以 Agent 驱动仓库管理、审阅与协作。
15 views 0 likesA 股短线复盘看板:涨停池·连板梯队·龙虎榜·板块资金一屏看完,赚钱效应/晋级率/梯队断层/情绪周期等派生指标纯计算直出(不经过 AI),AI 只把数据串成能读的盘面研判。全本地运行,可用 Claude/Codex 订阅免 API key。| A-share short-term daily-review dashbo…
6 views 0 likes禁漫天堂 Agent Skills / AI 原生 JMComic 助手:通过 MCP 与 Skills 将 JMComic 注入你的 AI Agent. / AI-powered JMComic assistant for seamless integration with AI Agents via MCP & S…
13 views 0 likesPairlet (formerly CC Pocket / cc-pocket) — Continue your local AI coding tasks from phone, tablet, or desktop.
16 views 0 likesSelf-hosted Personal AI + agent runtime in .NET (NativeAOT-friendly)
7 views 0 likesA self-hosted knowledge platform for humans and AI agents — publish wikis, blogs, and portable Agent Skills.
14 views 0 likesNotion CLI with AI agent support. Smart queries, Obsidian sync, batch ops, backups, validation and more.
8 views 0 likesAI Coding Agent Multiplexer
16 views 0 likesIndependent executor–verifier orchestration for software changes.
9 views 0 likesAI-native, local-first video editor by Ribbi — runs entirely in the browser. Rust/WASM engine, WebGPU compositing, WebCodecs export; humans and LLM agents edit…
8 views 0 likesDistill your knowledge, memories, and decisions into an open-source, inspectable AI Agent Twin.
11 views 0 likes🔬 Harness Vibe Research with Self-evolving AI Scientists
3 views 0 likesPersonal AI desktop agent for Windows, macOS, Linux, Android & iOS. Set a goal, it works on its own. Teams (pair two desktops, agents + humans), Agent2Agent, Wo…
5 views 0 likesRun agents like a company. AgentOS is the native control plane for OpenClaw — manage agents, tasks, models, context, approvals, and runtime visibility from one…
15 views 0 likesCreate Agentic admin panels faster on TypeScript and Vue.js with AdminForth Framework. Setup main CRUD pages within minutes, extend as you need
9 views 0 likesOpenJudge: A Unified Framework for Holistic Evaluation and Quality Rewards
18 views 0 likesAn ebook reader with a self-evolving agent: it remembers your reading across books, and plugins extend the reader and the agent alike.
12 views 0 likesA curated list of awesome resources for vibe coding
14 views 0 likesAgentic Voice Notes for iPhone and macOS - Rust, Dioxus, LanceDB + RIG + SQLite
9 views 0 likes