LLM Mart Basic
@llm-mart · Joined Jun 2026
用于审阅人物传记。适合检查身份归属、动机代价、能力边界、关系网、写作抓手、心理弧线与索引映射是否成立,并输出可落库、可回写的传记审阅报告。内置 Nuwa 深度审阅(心智模型、表达DNA、矛盾张力、诚实边界、决策启发式)。关键词:审人物传记、人物审阅、能力边界、关系网、心理弧线、传记报告、心智模型、表达DNA。
用于审阅分部大纲、分卷大纲、章清单与单元案执行版。适合检查上级分配内容是否全量落地、5/15 节奏与钩子是否成立、章中回报是否存在、单元案是否能阶段闭环并供血主线,并输出可回写的分层审阅报告。关键词:审分卷、分卷审阅、章清单审阅、章中回报、卷内节奏、分层报告。
用于审阅总大纲、全书总纲与战略层文件组。适合检查总纲包对象是否完整、M0 / X / C 体系是否稳固、四阶段机制递进是否成立、单元案矩阵是否持续供血主线,并输出可回写的总纲审阅报告。关键词:审总纲、全书总纲审阅、M0、X线、C线、总纲报告。
用于审阅故事设定、手法、程序链、证据载体或规则文档。适合检查规则是否可执行、边界与代价是否明确、是否可证据化、是否具备程序摩擦与镜头化表达,并输出可落库、可回写的设定审阅报告。关键词:审故事设定、设定审阅、规则边界、证据化、程序摩擦、设定报告。
用于审阅章节正文的执行质量。适合检查章首抓力、中段回报、章末钩子、现实落地、规则边界、链路失配与可回写的审阅结论。内置人物执行审计(声口一致性、心智模型落地、压力反应匹配、误判/盲区触发、关系拉扯兑现)。关键词:审这章、章节审阅、章首抓力、中段回报、章末钩子、审阅报告、人物执行审计、声口检测。
用于在选定平台与题材之后、设计大纲之前,完成项目级战略初始化。唯一目标:在平台和题材约束下确定最能吸引读者和最能赚钱的小说要素清单。 核心方法:从写作研究和竞对分析数据出发自主决策。核心产出:项目根目录下的 Agents.md(强制产出)+ 项目初始化蓝皮书。 关键词:项目初始化、项目策划、Agents.md、从数据出发、套路自主决策、蓝皮书
用于以默认极严、保守、负面证据优先的口径评估作品在目标平台的签约或过稿潜力。适合统一承接评估流程骨架、分阶段准入评估、材料完整度判断、评分维度、概率区间、封顶与一票否决规则,并兼容竞争位 / 竞品威胁评估语境。评估{目标平台}项目时,强制要求使用多种可用网络搜索工具检索{目标平台}同题材 TopN 候选池(起点默认按起点中文网榜单检索,其他平台按可用性调整),并按 "TopN 候选池 + 3–5 主压制样本 + 四层竞对拆解"做从严对照。目标平台路由优先级:用户显式指定 > Agents.md 主输出平台 > 默认回退起点中文网。关键词:平台签约评估、极
用于强化章节结尾的章末钩子。适合章末抢救、结尾补针、翻页感增强、下一章驱动增强与最后 150–300 字局部强化。关键词:强化章末钩子、结尾没翻页感、只修结尾、下一章驱动、最后一句、章末补针。
用于强化章节开头前 150–300 字的入场抓力。适合章首抢救、首屏留存优化、异常前置、冲突前置与只修前两三段的局部强化。关键词:强化开头、章首抓人、前 150–300 字、首屏留存、开头太慢、只修前两段。
用于设计或重写场景单元、章节场景与微型剧本。适合场景施工卡落地、动作链推进、证据入场、对话承压与控制卡到场景的职责拆解。关键词:场景单元、场景施工卡、微型剧本、动作链、证据推进、场景职责。
用于设计、重写或强化对话冲突。适合把角色对话写成立场碰撞、潜台词拉扯、信息释放与情绪升级并存的有效场景。关键词:对话冲突、盘问、谈判、争执、潜台词、关系升级。
执行微空间或受限空间场景。用于在楼道、电梯、值班室、走廊、地下车库、出租屋、候诊区、办公室后区等熟悉空间里,把空间常态、微反常、人物动作、后果升级与证据入场咬成一个可落地的场景引擎;执行时必须先加载 通用-执行场景单元,再叠加本 Skill 的微空间专项工法。适合微空间惊悚、受限场景压迫、日常异化场景设计。
提纯多平台输出前的中文母稿。用于在不同平台改写前,把正文母稿修成信息稳、事件链稳、情绪主轴清、证据与规则关键点不丢、追读链完整、平台可分化的高质量源稿,避免后续平台适配建立在松散底稿上。适合多平台前置精修、母稿加固、跨平台源稿提纯。
用于撰写、重写或审计小说书评。适合把全书 / 分部 / 分卷 / 分章的阅读体验、核心卖点、平台传播口径与非剧透钩子写成可直接发布的书评文件。关键词:撰写书评、推荐文案、分章安利、平台推荐评述、非剧透书评、今日头条。
用于撰写、重写或审计作品的内容简介。简介即开篇——读者看简介的决策模式与看开头完全一致:在 3–5 秒内决定要不要点开。适合把题材卖点、主角处境、核心冲突、持续承诺与情绪抓手压缩成平台可用文本,支持全层级(全书/分部/分卷/章节)简介。关键词:内容简介、作品简介、平台简介、卖点压缩、简介重写、简介审计、简介同构。
用于润色已有章节正文。适合整章精修、局部重写、节奏提纯、章首抓力增强、中段回报提亮与章末钩子收紧。关键词:润这章、精修正文、整章精修、局部重写、节奏提纯、直接回写。
润色章节后的 `## 作者有话说`。用于把作者有话说修成读者向小剧场:一丢丢创作花絮 + 一点贴着本章余波的情绪共鸣 + 一个开放式轻追问,而不是创作说明会、设定讲义或章节总结。适合发布前精修、后记前小剧场重写、把作者有话说从复盘腔改回读者腔。
专用于小说写作的结构化深度研究 Skill。支持对题材趋势、平台生态、专业知识、场景环境、人物原型、写作技法、读者市场等研究域,执行大纲生成→并行深搜→报告输出的全流程深度调研。关键词:深度研究、写作研究、题材调研。
用于生成写前章节控制卡、章节施工卡或章节作战卡。适合写前施工、场景拆分、中段回报预埋、章末钩子预埋与上游供血对齐。关键词:章节控制卡、施工卡、作战卡、中段回报、章末钩子、写前施工。
用于对单章或连续多章执行"初始化→控制卡→创作→润色→去AI味→审阅回炉→读者产物→摘要"的完整章节闭环。适合章节写作 SOP、批量写章、日志续跑、9.2+ 回炉与最终摘要收口。关键词:章节创作闭环、跑完整 SOP、批量写章、回炉到 9.2、日志续跑、最终摘要。
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/autopilot
autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
/chain
chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
/hunt
hunt
Active vulnerability hunting. Two-track dispatcher — asks Red Team vs WAPT, hands off to hunt-dispatch skill and sibling commands. Usage: /hunt target.com | /hunt *.target.com | /hunt targets.txt [--vuln-class X] [--source-code P] [--chrome]
/intel
intel
On-demand intelligence fetch for a target — CVEs, disclosed reports, new features. Pulls NVD/GitHub-Advisory CVEs + bundled disclosed reports + hunt memory context. Usage: /intel target.com
/memory-gc
memory-gc
Inspect or rotate the autopilot ledger JSONL files (findings.jsonl, negatives.jsonl). Caps file size and keeps N rotated backups so memory does not grow unbounded.
/pickup
pickup
Pick up a previous hunt on a target — shows hunt history and untested surface from the autopilot ledger. Usage: /pickup target.com
/recon
recon
Run full recon pipeline on a target — subdomain enum (Chaos API + subfinder), live host discovery (dnsx + httpx), URL crawl (katana + waybackurls + gau), gf pattern classification, nuclei scan. Outputs to recon/<target>/ directory. Usage: /recon target.com
/remember
remember
Optional manual note on a target or the last confirmed finding. Capture is automatic during autopilot; this is for extra context. Usage: /remember
/report
report
Write a submission-ready bug bounty report. Generates H1/Bugcrowd/Intigriti/Immunefi format with CVSS 3.1 score, proof of concept, impact statement, and remediation. Run /validate first. Usage: /report
/scope
scope
Mandatory pre-flight scope check — verify an asset is in scope BEFORE any HTTP touch. Deterministic (deny-wins, default-deny) via engine/scope.py against the engagement's scope.md. Blocks out-of-scope testing. Usage: /scope <asset> [<asset> ...]
/surface
surface
Show ranked attack surface for a target from its recon manifest + hunt memory. Deterministic backing is `cbh surface <target>` (reads recon/<target>/manifest.json); LLM layer adds ledger signal. Usage: /surface target.com
/token-scan
token-scan
Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP lock bypass, authority retention, bonding curve exploits, fake renounce, sandwich amplification). Manual 8-class grep audit (with an optional automated scanner if present). Usage: /token-scan <contract_path_or_dir> [--chain solana]
/triage
triage
Quick 7-Question Gate triage on a finding before writing a report. Kills N/A submissions before they happen. Faster than /validate — for quick go/no-go decisions. Usage: /triage
/validate
validate
Validate a finding — runs 7-Question Gate + 4-gate checklist. Kills weak findings before report writing. Prevents N/A submissions that hurt validity ratio. Usage: /validate
/web3-audit
web3-audit
Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomplete path, off-by-one, oracle errors, ERC4626, reentrancy, flash loan, signature replay, proxy/upgrade). Applies pre-dive kill signals first. Generates Foundry PoC template for confirmed findings. Usage: /web3-audit <contract.sol>
/README
README
Crabbox is a single CLI (`crabbox`). Commands are top-level, not nested under a
/actions
Actions
`crabbox actions` prepares a leased box from your repository's own GitHub
/adapter
Adapter
See [Runtime adapter stack](../features/runtime-adapter-stack.md) for the
/admin
Admin
`crabbox admin` groups trusted operator controls for coordinator-backed leases and the cloud resources behind them. Use it to inspect every lease the broker tracks, reconcile expired leases against live cloud state, force-release or delete a backing server, print provider IAM pol
/artifacts
Artifacts
`crabbox artifacts` turns a desktop lease into durable QA evidence: it collects
Open-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-model, multi-channel. Lightwei…
10 views 0 likesOpen-source AI browser agent for web automation: a web browsing agent and computer-use agent in plain English. Browser MCP for Claude Code and Gemini CLI.
9 views 0 likesAgent-native trading terminal built on DeepSeek Harness. Crypto, US, CN and HK in one three-column GUI, 19+ hot-swappable connectors, dry-run by default with hu…
11 views 0 likesOpen-source desktop and web coding agent with a first-party host and harness, durable sessions, model connections, streaming chat, and workspace tools.
8 views 0 likesOrcaReplay — Time travel for AI agents. Record, replay, fork, and debug any agent run with any model. Built by the OrcaRouter.ai team.
8 views 0 likesA complete toolkit for connecting R and LLMs
9 views 0 likesOpenSRE — the memory-first AI SRE. Self-hosted incident investigation with episodic memory, knowledge graph, web console, Slack & Teams. opensre.in
11 views 0 likesA desktop AI coding assistant that works with your local projects. Ally helps you understand code, edit files, search a workspace, manage tasks, and complete de…
9 views 0 likes【在线免费使用】 简单快速将SQL或DBML转换为美观的ER图(支持 Agent Skill)/ The best SQL to ER Diagram converter (Support Agent Skill).
11 views 0 likesOperation-bound protection for autonomous AI agents: contain and verify operations before committing changes, understand intent and risk across long-running wor…
8 views 0 likesLocal-first AI coding agent desktop: Electron + Rust host core + pi Agent Harness + user-installable plugins
10 views 0 likesLocal-only Go static analysis engine with a built-in MCP server. Gives AI coding agents deterministic structural awareness: call graphs, impact analysis, symbol…
17 views 0 likesSelf-hosted AI agent workspace with tool calling, MCP, multi-model routing, sandboxed execution, multi-agent workflows, and LLM-authored 3D character animation…
16 views 0 likesAutomated TDD enforcement for Claude Code
12 views 0 likesHigh-performance platform for building websites, e-commerce, and web applications—with Native AI, JavaScript development, and a marketplace for portable sites a…
13 views 0 likesAutonomous AI-agent orchestration engine for job discovery with decision traces, tool adapters, and production-grade run control.
9 views 0 likesToken efficient Claude Code full Python rebuild. AI Coding Agent in 310K LoC Python.
13 views 0 likesOPC — One Person Company. A full team in a single Claude Code skill. Adaptive agent orchestrator with 21 built-in roles, 6 flow templates, and adversarial quali…
10 views 0 likesOpen-source, secure environment with real-world tools for enterprise-grade agents.
9 views 0 likesMCP server for AI-powered GitHub project management — agent orchestration, PRD-to-issues pipeline, sprint planning, and multi-agent swarm coordination
10 views 0 likes