LLM Mart Basic
@llm-mart · Joined Jun 2026
Use when the user wants a new git worktree created for a task. Picks a kebab-case branch name with a fix/feat/chore/docs/refactor prefix, runs `git worktree add` from the configured base branch, and reports the new path. Also known as `klaussy-new-worktree`.
Use when reviewing a staged diff or an about-to-commit/push change for last-mile issues — silent failures, leaked secrets, debug leftovers, blatant correctness landmines, and excessive/narrating comments. Reports findings on the changed lines only; it does not refactor or rewrite
Use when the user wants the current change QA'd and PR-ready evidence captured. Classifies the diff and runs the verification that actually fits it — screen recordings and screenshots for UI/frontend changes, endpoint or e2e runs for backend, command output for a CLI, tests for a
Use when the user wants to restructure code while preserving behavior exactly. Establishes a passing test baseline first, then makes incremental moves that each leave the suite green. Refuses to change behavior and structure in the same step. Also known as `klaussy-refactor`.
Use when the user wants to cut a release — bump the version, update the changelog from conventional commits, and tag. Detects where the version lives, derives the next version from the commits since the last tag, and stages the release locally; it does not push or publish unless
Use when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go significant. NOT recurring metric tracking (that is `analytics`), NOT north-star/KPI trees (that is `kp
Use when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast, tap-target size. NOT palette or visual intent (that is `design`), NOT test-runner setup (that is `testi
Use when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules, break-even ROAS math, and Consent Mode v2 / CAPI tracking gaps. NOT the page the ad clicks into (that
Use when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual recall) or agent trajectories (tool correctness, completion), or picking an eval framework. NOT build
Use when bounding an LLM agent that already runs — scoping its task domain, gating tools to least privilege, defending against prompt injection in untrusted web/email/RAG text, requiring human approval on irreversible actions, capping runtime and cost, or triaging what it already
Use when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with ffmpeg (mux, duck, loudnorm, concat). NOT still-image generation/editing (that is `replicate-images`);
Use when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing. NOT charting that data (that is dashboard), NOT choosing which metrics matter (that is kpi-framework), NOT experiment math (tha
Use when constitution, spec, plan and tasks all exist and you want them cross-read against each other before any code is written — the rsc-sdd pre-implementation gate. Reports coverage gaps, contradictions, duplication, ambiguity and scope drift; edits nothing. NOT the task break
Use when building, refactoring, or debugging Angular (v20/21+): standalone components, signals, zoneless change detection, @if/@for/@defer control flow, inject() DI, resource()/httpResource(), RxJS interop, NgRx SignalStore, ng CLI. NOT React (that is react), NOT Next.js (that is
Use when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only, rate-limit-aware throttling. NOT inbound callbacks (that is `webhooks`), NOT chaining services (that is `a
Use when settling the contract of an API you expose, before implementation: resources/URLs, REST vs GraphQL, versioning, one RFC 9457 error envelope, pagination, idempotency — emitted as OpenAPI 3.1. NOT implementing the endpoints (that is `fastapi`/`nestjs`/`go`/`nodejs`), NOT a
Use when writing one long-form article end to end — answer-first lede, question-shaped headings, plus its on-page surface (title, meta, slug, FAQ, Article/FAQPage JSON-LD) — or fixing a draft that buries the answer or reads AI-padded. NOT keyword research or topic selection (that
Use when building a content-driven or marketing site with Astro 6: static-first pages, islands and partial hydration, content collections, server islands, per-route on-demand rendering, deploy adapters, and Astro 5→6 migration. NOT app-router React with server actions and heavy c
Use when authoring a NEW rsc skill or editing an existing one — scoping it to one job, writing the description that decides whether it ever loads, splitting the body into references/, writing its evals, auditing it against the rubric. NOT building a product feature (that is `spec
Use when building or fixing a no-code automation on n8n, Make, or Zapier — trigger to multi-app steps with data mapping, dedup, retries and an error path — or picking the platform by billing unit (task vs credit vs execution). NOT a typed API client in code (that is api-connector
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/monitor-status
Monitor status
Check all Better Stack monitor statuses and identify downtime
/search-logs
Search logs
Search logs via Better Stack Logtail
/status-page-update
Status page update
Update a Better Stack status page with current status or maintenance
/investigate-detection
Investigate detection
Investigate a single Blackpoint Cyber / CompassOne detection end-to-end
/partner-overview
Partner overview
Portfolio-level Blackpoint Cyber / CompassOne rollup of detections and exposure across all tenants
/search-detections
Search detections
List recent Blackpoint Cyber detections for a tenant
/tenant-exposure
Tenant exposure
Build a prioritized exposure report for a Blackpoint Cyber / CompassOne tenant
/triage-detections
Triage detections
Sweep and prioritize the open Blackpoint Cyber / CompassOne detection queue across tenants
/agent-inventory
Agent inventory
List all devices and agents across the organization with status and health information
/finding-triage
Finding triage
Triage open Blumira findings by severity, presenting a prioritized list for review
/investigate-finding
Investigate finding
Deep investigation of a specific Blumira finding with details, context, and comment history
/msp-overview
Msp overview
MSP dashboard showing all managed accounts with open finding counts and severity breakdown
/resolve-finding
Resolve finding
Resolve a Blumira finding with the appropriate resolution type and notes
/security-posture
Security posture
Overall security posture review including open findings by severity, agent coverage, and trends
/offboard-user
Offboard user
Run the complete CIPP M365 offboarding workflow for a departing user — capture audit state, revoke access, handle mailbox, reclaim licenses
/secure-score-report
Secure score report
Generate a portfolio-wide M365 security posture report — Secure Score equivalents, MFA enrollment, conditional access coverage, and domain authentication across all managed tenants
/standards-drift
Standards drift
Find tenants that have drifted from the MSP's configured CIPP standards baseline — missing standards, standards in Report-only mode, recent compliance failures
/tenant-health
Tenant health
Quick health snapshot for a single tenant — BPA failures, conditional access enforcement, MFA gaps, domain authentication, standards compliance
/log-time
Log time
Log a time entry (billable activity) against a Clio matter
/matter-summary
Matter summary
Consolidated view of one Clio matter — contacts, open tasks, recent activities, recent communications, and bills
Your efficient agentic AI coding CLI assistant
2 views 0 likesAI coding with Aegis governance built into execution: baseline-aware changes, evidence-backed delivery. Free desktop client, your choice of model. 将哲科思维融入 AI 开发…
1 views 0 likesAndroid in docker solution with noVNC supported, video recording, mcp server and AI-agent
2 views 0 likesYour AI assistant, built for the agentic era. Open source and local: talk to it, and it runs your agents, your coding CLIs, your browser and your apps. Windows,…
0 views 0 likesVerifiable program-level self-evolution for AI-for-Science agents: Skills and typed Operators grow from replay-verified executions.
3 views 0 likesLet Claude Code and other coding agents drive and debug Chrome from the shell. DOM, network, console and raw CDP as short commands, no screenshots and no MCP ne…
3 views 0 likesUnofficial, agent-friendly Mercadona shopping CLI (Go) — search products, read prices, build a cart and prepare checkout from the terminal. BYO credentials.
3 views 0 likesLocal-first AI canvas for visual workflows, AI short drama, image/video generation, storyboarding and asset management. ComfyUI, AI agents, MCP & Blender. 本地优先…
3 views 0 likesLet any AI coding tool — Claude Code, Cursor, Codex — drive your real Chrome. One-prompt setup, muscle memory, local-first.
3 views 0 likesruns anywhere. uses anything
3 views 0 likesOpen-source dots for the web: an AI agent with its own browser, one that does not get blocked.
0 views 0 likesFree MIT AI coding agent — no API key needed. Built-in free model, or bring Claude, GPT, Gemini, DeepSeek, Ollama +50 more. Swarm mode, 40+ tools, browser & des…
2 views 0 likesOpen-source AI customer support system. AI-first support, human-ready operations.
2 views 0 likesA durable, multiplayer, mobile-first web app for Pi agents, built on Pi Durable
2 views 0 likesEmbedded Cypher knowledge graph for Python and Rust. Bundled MCP server, describe() schema, and code-graph parser for LLM agents.
2 views 0 likesTurn PDFs, books and papers into interactive learning webpages|将复杂材料转化为可追溯、可测验、可做笔记的学习网页
2 views 0 likesPhysicsOS 是一个面向初高中物理学习的公益可视化智能体,通过 AI 理解题目并结合物理引擎,将抽象物理过程转化为可交互、可观察、可计算、可验证的真实物理场景。
2 views 0 likes