LLM Mart Basic
@llm-mart · Joined Jun 2026
Assess breaking-change and regression risk for a same-framework major-version upgrade (React, Next.js, Angular, Vue, or core build tooling), grounding every claimed breaking change in the framework's official release notes/migration guide, and separate upgrade-blocking issues fro
Review client-side authentication and session-management code for token-storage location, cookie-flag correctness, CSRF/open-redirect exposure, and OAuth/OIDC flow choice for browser-based apps against OWASP ASVS and Session Management Cheat Sheet guidance, with the OAuth-for-bro
Determines and reviews whether aggregation/shaping logic belongs in a Backend-for-Frontend layer versus client-side composition, and audits existing BFF boundaries for scope creep, duplicated aggregation logic, and leaked backend topology or pass-through authorization.
Sequence frontend specialist and red-team reviews for the 10 governed workflows (new feature, perf regression, a11y audit, security review, SSR/hydration bug, design-system change, framework migration, AI-generated code review, production incident, CWV failure) and issue a bindin
Review frontend source for DOM XSS sinks (innerHTML, dangerouslySetInnerHTML, v-html, document.write, eval-class APIs), verify actual attacker-reachable taint flow, and audit Content-Security-Policy and Trusted Types enforcement for real bypasses rather than header-presence check
AI agent for Claude Code that tailors resumes to job descriptions with ATS optimization and LaTeX PDF output. Zero fabrication - every claim sourced from your c…
Build a cost-to-serve model covering CDN egress, SSR/edge compute, image transformation, and CI build-minute spend for a frontend surface, and rank remediation options by dollar savings weighed against Core Web Vitals and security impact, without treating cost-cutting and securit
Route frontend governance tasks to the narrowest specialist or parallel team (max 4) from the frontend agent catalog. Use when you do not already know which frontend specialist handles the task. Not for direct frontend answers; Maestro classifies, dispatches, and hands off to fro
Build a phased, reversible plan to migrate or modernize a legacy frontend surface (jQuery/Backbone/AngularJS to a modern framework, CRA/Webpack to Vite, or a same-framework major-version bump) using strangler-fig sequencing with measurable exit criteria per phase, without default
Design or review browser-side Real User Monitoring instrumentation for Core Web Vitals (LCP, INP, CLS) using the web-vitals attribution build and distributed tracing via OpenTelemetry Web, enforcing lab-vs-field evidence labeling, sampling/cardinality sizing, and PII-in-telemetry
Reviews cross-cutting frontend architecture decisions (module boundaries, rendering topology, technology adoption) against a rewrite-averse, evidence-grounded standard before they are approved, producing an ADR-quality verdict rather than a stylistic opinion.
Reviews frontend test-pyramid shape, critical-path coverage, and flaky-test governance across unit, component, integration, and E2E layers (Vitest/Jest, Testing Library, Playwright/Cypress), loading framework references only when the task needs them.
Statically review GraphQL client configuration (Apollo Client, and urql/similar clients by analogy) for production-enabled devtools/introspection exposure, a normalized cache left uncleared across user sessions, missing persisted-query allowlisting against client-driven query abu
Review HTML markup and rendered DOM structure for correct native-element usage, valid heading/landmark hierarchy, and WAI-ARIA APG-conformant custom-widget patterns; produce a WCAG 2.2-grounded verdict with APG pattern citations for every custom interactive control, flagging anyt
Audit frontend code for internationalization readiness — externalized ICU MessageFormat strings, Intl-based date/number/currency/plural formatting, correct lang/dir attribute propagation, and RTL-safe CSS logical properties — before translation vendor engagement, with CLDR plural
Review JavaScript/TypeScript for event-loop and microtask/macrotask ordering correctness, unhandled Promise rejection paths, DOM event-listener and timer cleanup, and race-condition risk in rapid-repeated-async UI patterns, tracing actual browser scheduling semantics rather than
Inventory the hidden behaviors in a legacy jQuery/Backbone-era codebase — implicit global event delegation, direct DOM mutation outside any render cycle, plugin side effects, ad-hoc accessibility shims, and unsanitized HTML string building — that a mechanical framework port would
Reviews micro-frontend/module-federation boundary contracts for shared-dependency versioning safety, runtime isolation, and ownership clarity before adoption or extension of a distributed frontend architecture.
Reviews monorepo task-graph configuration (Turborepo tasks/caching, Nx task pipelines) alongside dependency and lockfile governance (pnpm catalogs, npm overrides, lifecycle-script risk) to prevent false-green CI from stale cache reuse and unpinned supply-chain exposure.
Statically review Next.js App Router Server/Client Component boundaries and Server Action data mutations for correct data-fetching placement, bundle-leak risk, and authorization-trust integrity, escalating client-trusted authorization to a security finding rather than a style not
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/social
Social
Run an organic-social (ECHO) workflow: channel portfolio and voice dossiers, platform-native content and calendars, the social-quality gate with a pre-publish go/no-go, community/inbox/crisis operations, and the listening/SOV/dark-social measurement loop. Not sure? Use /aaron-marketing:auto.
/minutes-mcp-recall
Minutes mcp recall
Route meeting-recall questions to the right Minutes MCP tool.
/minutes-x1-closeout
Minutes x1 closeout
Prepare a sourced Minutes meeting outcome for human-governed closeout of existing X1 work. Use when the user wants a meeting decision or commitment to close, defer, escalate, or retire a specific X1 coordination thread. Never use it to infer settlement, move money, contact anyone, or close X1 work automatically.
/minutes-mcp-recall
Minutes mcp recall
Route meeting-recall questions to the right Minutes MCP tool.
/minutes-x1-closeout
Minutes x1 closeout
Prepare a sourced Minutes meeting outcome for human-governed closeout of existing X1 work. Use when the user wants a meeting decision or commitment to close, defer, escalate, or retire a specific X1 coordination thread. Never use it to infer settlement, move money, contact anyone, or close X1 work automatically.
/capacity
Capacity
`crabbox capacity [--json]` reports current fleet, org, and owner admission
/code-review
Code review
Code review the current proposed code change
/merge-conflict
Merge conflict
Resolve a merge conflict
/pr-review
Pr review
Code review for pull request $1
/6hats
6hats
Six Thinking Hats Analysis
/README
README
Slash commands shipped by the plugin. Portable framework commands work in any Claude Code session; the workflow commands embed one author's personal setup and are opt-in - see [Adapting for your workflow](../README.md#adapting-for-your-workflow) before relying on them. Back to th
/fix-develop
fix-develop
Autonomous fix loop for failing CI on the repo's default branch
/fix-pr
fix-pr
Autonomous PR fixing loop - iterates on CI failures and review comments until green
/issues
issues
GitHub-issue marathon - triage open issues, then run agent-ready ones to merge with Agent Teams
/tm-marathon-config-example
tm-marathon-config-example
Example Marathon Configuration for CLAUDE.md - copy the section below into your project's CLAUDE.md
/tm
tm
Task Master - plan, start, review, and close
/understand
understand
Deep understanding mode (nemawashi) - exhaustive context-gathering before action
/burp-search
Burp search
Searches Burp Suite project files for security analysis
/ct-check
Ct check
Detects timing side-channels in cryptographic code
/diff-review
Diff review
Performs security-focused differential review of code changes
Offline-first Python AI agent that runs a tiny research business: quotes each job against its own costs, collects via Stripe, fulfils with NVIDIA Nemotron, pays…
0 views 0 likesDSH 插件 · 注入式优化器 0.8(主线):你照常说话,它在你发送后,AI接收前把"这一轮到底要什么"理清楚,再把这份理解交给工作 AI(上下文注入) —— 原话不改写,条条带逐字依据。含控制界面(档位/权限/模型/上下文/只读工具)、拦截浮层(思维层+产出层)与真实 token 用量。可明显提升大多数模型的发挥稳…
0 views 0 likesReliable AI Skill + MCP toolkit for agent-driven desktop CAD automation.
0 views 0 likesCurated real-world use cases for Hermes Agent — the self-improving AI agent from Nous Research. Backed by primary sources.
0 views 0 likesAI Agent 教学仓库 | 系统化 LangChain、RAG、LangGraph、MCP 全栈实战代码 | 万字博客详解 | 开源可运行示例 | 从零构建智能体
0 views 0 likes从 0 复刻 WorkBuddy-style 桌面 AI 助手 Harness:24 章 Python 教程,覆盖 Agent Loop、工具调用、记忆系统、Sidecar、沙盒审计、DeepSeek/OpenAI 评测轨迹
1 views 0 likesMCP server and CLI tools for web search and crawling, built on SearXNG and Crawl4AI
2 views 0 likesDelta MCP is a free app that sits between your AI apps and their MCP servers: one program per task instead of one tool call per step, up to 24.1× fewer tokens i…
2 views 0 likesAva turns any Android 5+ device into a voice-first Home Assistant kiosk. Native C++ under the hood, so a 10-year-old tablet still listens, talks, and runs the h…
0 views 0 likesRoblox Studio macOS Window Capture Fix 2026: Real Screenshot Tool Instead of Magenta Playtest Glitch
2 views 0 likesLabTether
2 views 0 likes