LLM Mart Basic
@llm-mart · Joined Jun 2026
Statically review Vue Router navigation guards, redirect flows, and template bindings for client-side guards used as the sole authorization boundary, open redirects via route.query.redirect/returnUrl, javascript:/data: scheme injection through dynamic :to/:href bindings, route pa
Statically review Vue 3 SSR entry points and templates for cross-request state pollution (module-scope reactive state, non-per-request app/store creation) and injection via unsanitized v-html or unvalidated dynamic href/src bindings, grounded in Vue's own SSR and security-best-pr
Statically review Pinia and legacy Vuex state stores for sensitive data persisted to localStorage/sessionStorage without scoping, untrusted server-payload hydration (window.__pinia/__INITIAL_STATE__) with un-escaped state serialization, SSR store-singleton cross-request pollution
Audit frontend markup, components, and design-system primitives against WCAG 2.2 Level A/AA success criteria and ARIA APG interaction patterns, separating automated-detectable violations from manual-verification-required items and flagging legal exposure, with reference material
Design and build AI-powered applications on AlloyDB for PostgreSQL using AlloyDB AI — covering vector search, hybrid search (vector + full-text), AI SQL functions (ai_generate, ai_classify, ai_score, ai_embed), model endpoint management, and the AlloyDB Omni edge runtime. Prefer
Operate AlloyDB clusters and Cloud SQL instances — HA configuration, read replicas, connection pooling, maintenance windows, backup strategy, and performance diagnostics.
Design and operate Anthos / GKE Enterprise fleet management, Config Management (GitOps with Policy Controller), multi-cloud Kubernetes across GCP, AWS, and Azure.
Design and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management.
Analyze BigQuery slot reservation sizing, BI Engine acceleration, query cost estimation, dataset governance (expiration, access controls), and partitioning/clustering optimization to reduce on-demand scan costs.
Review GCP Certificate Manager and classic Google-managed TLS certificates — certificate map configuration, DNS authorization, CAA record validation, certificate rotation automation, wildcard vs SAN design, and expiry monitoring.
Pre-change blast radius analysis for GCP — cross-project resource dependency mapping, org policy cascade effects, Shared VPC peering impact, Service Account impersonation chain analysis, and safe change sequencing.
Advise on Google Cloud authentication and authorization patterns — covering Application Default Credentials (ADC), service account best practices, Workload Identity Federation (for GKE pods and external workloads), human user auth (gcloud, IAP, Identity Platform), service-to-serv
Deploy and operate Cloud Run services, Cloud Functions gen2, Eventarc triggers, traffic splitting for progressive delivery, and cold-start optimization strategies.
Build and operate CI/CD pipelines using Cloud Build, Cloud Deploy delivery pipelines, Artifact Registry, SLSA provenance generation, and release gating with approval workflows.
Configure Assured Workloads for regulated workloads (FedRAMP High/Moderate, HIPAA, PCI-DSS, ITAR, IL4/IL5), audit controls implementation, and gather compliance evidence using Security Command Center and Asset Inventory.
Operate GCE instances, manage Managed Instance Groups (MIGs), configure OS patch management via VM Manager, design preemptible/spot VM strategies, and manage startup/shutdown scripts.
Convert an arXiv paper to Markdown for reading or implementation reference. Use when asked to convert, fetch, or create documentation for an arXiv paper by its ID, or when a paper with a known arXiv ID needs to be read or referenced. Fetches the LaTeX source when available (plus
Look up arXiv paper metadata via the arXiv API. Use when you need to get a journal DOI from an arXiv ID (for OpenAlex integration), or find an arXiv ID from a title/keyword search (for arxiv-doc-builder). Requires the `arxiv` Python package.
Perform triangulated cognitive research combining SQLite memory, GitHub 10k+ stars patterns, and ToT DAG benchmarking before critical architectural decisions. Automatically triggers subagent research escalation when confidence is low (<0.70). Keywords: research, benchmark, github
Core Kilo-Kit skill enforcing Hard-Gate and Iron Law principles. Ensures AI agents scan the system and codebase before proposing solutions. Keywords: hard-gate, iron-law, evidence, scan, verify, system-check, codebase
Fourteen posts of being wrong in production, compressed to checkboxes
Healthy nodes, a quiet network, 300 restarts in three days, and a latency budget measured in milliseconds
Discovery worked. Ping worked. Every TCP connection timed out, and later the tunnel only worked when someone had a terminal open.
Every VM came back. The cluster did not. Declarative systems converge on config, and the datapath isn't config.
A surprising share of AI-in-the-terminal failures aren't the AI. They're zsh, and a version of bash from 2006.
A Claude Code plugin turns standalone project configuration into a namespaced, installable extension that teams and communities can update as one unit.
None of the safety came from the model. It came from six boring habits.
Skills package instructions and references. Subagents run work in a separate context and return results. They solve different problems and can be composed deliberately.
Six hours in, one step left, everything green, and the incident that didn't happen
CLAUDE.md carries persistent project context. Skills load reusable procedures when relevant. Separating stable facts from task-specific workflows keeps both easier to maintain.
Twenty minutes recovering secrets that never existed, and the one sentence from a human that ended it
An API request routing a model's tool call through an approval gate to a remote MCP server
31 config keys, two audits, and why the first one was wrong in both directions
The official MCP Registry stores standardized server metadata rather than package code. Publishers verify a namespace, describe installation or remote access, and submit immutable versions.
Everyone looks at the Dockerfile. The file that actually leaked the key was the project file.
Remote MCP authorization uses established OAuth standards, but secure integration still requires issuer validation, least-privilege scopes, protected token handling, and server-side enforcement.
"Copy it over and switch the reference" is two steps, and the outage lives in the one nobody checks
stdio fits local processes and prototypes. Streamable HTTP fits hosted services and shared integrations. The right choice follows where the capability runs and who must reach it.
The most important rule wasn't about what I could change. It was about what I was allowed to display.
Tools perform operations, resources expose readable context, and prompts provide reusable templates. Choosing the correct primitive makes an MCP server easier to understand and govern.
/check
Check
Run project checks and fix any errors without committing
/ci-setup
Ci setup
Setup continuous integration pipeline
/clean-branches
Clean branches
Clean up merged and stale git branches
/clean
Clean
Fix all linting and formatting issues across the codebase
/code-permutation-tester
Code permutation tester
Test multiple code variations through simulation before implementation with quality gates and performance prediction.
/code-review
Code review
Perform comprehensive code quality review
/code-to-task
Code to task
Convert code analysis to Linear tasks
/code_analysis
Code analysis
Perform comprehensive code analysis with quality metrics and recommendations
/commit-fast
Commit fast
Automatically create and execute a git commit using the first suggested commit message
/commit
Commit
Create well-formatted git commits with conventional commit messages and emoji
/constraint-modeler
Constraint modeler
Model world constraints with assumption validation, dependency mapping, and scenario boundary definition.
/containerize-application
Containerize application
Containerize application for deployment
/context-prime
Context prime
Load project context by reading README.md and exploring relevant project files
/create-architecture-documentation
Create architecture documentation
Generate comprehensive architecture documentation
/create-command
Create command
Create a new command following existing patterns and organizational structure
/create-database-migrations
Create database migrations
Create and manage database migrations
/create-docs
Create docs
Analyze GitHub issue and create technical specification with implementation plan
/create-feature
Create feature
Scaffold new feature with boilerplate code
/create-jtbd
Create jtbd
Create a Jobs to be Done (JTBD) document for a product feature focusing on user needs
/create-onboarding-guide
Create onboarding guide
Create developer onboarding guide
Atom Agent, Open-Source Governed AI Agent Platform for Self-Hosted Automation
13 views 0 likesThe agent engineering intelligence harness, optimized tools, memory system, subagents and mixture of models packages ⚚
16 views 0 likesSesori iOS/Android app and the Sesori Bridge CLI — drive Claude, Codex, OpenCode, Cursor, Pi, OMP, Hermes coding sessions from your phone
14 views 0 likes🧠 RepoBrain (formerly Antigravity) — Give your repo a brain. ChatGPT for your codebase: works in Claude Code, Cursor, Codex, Windsurf & more.
14 views 0 likesUse ChatGPT (Codex), Claude, and Grok (X Premium) subscriptions as DeepSeek Harness LLM providers — OAuth login in the web UI, no API keys
15 views 0 likesLatitude is the open-source AI monitoring platform.
16 views 0 likesOpen-source AI browser agent for Chrome and Firefox (monorepo) 🧠
16 views 0 likesOfficial Model Studio CLI(阿里云百炼 CLI)built for AI Agent frameworks, exposing models, search, multimodal, and workflow capabilities as structured tool calls.
15 views 0 likesCurated DeepSeek Harness (DSH) plugins, extensions, tools, skills, clients, runtimes, integrations, and verified references — English and Chinese.
16 views 0 likesTurn papers, code, and docs into presentation-ready, natively editable PPTX in Codex / Claude Code. Native charts and equations, speaker notes, click-build anim…
14 views 0 likesGrix : Work with agents like talking to people.
25 views 0 likesLocal First Ai Agent. Optimized for Local Ai models. Long context window. Proper tools callings. Runs privately on your device.
26 views 0 likesModel Context Protocol server that integrates AgentQL's data extraction capabilities.
15 views 0 likesAI that ships your tickets.
14 views 0 likesMetadata-driven CLI for AI Agent Bots — 48 operations across 7 domains, structured JSON envelope I/O, zero interactive prompts.
12 views 0 likesAn open-source, extensible, self-hosted agent workspace with multi-runtime support for Codex, Claude Code, and more, plus reusable local apps for custom interfa…
14 views 0 likesOpen-source Windows desktop client and GUI for DeepSeek Harness — zero-setup installer with Codex, plugins, skills, SSH, mobile remote access, and 11 skins.
12 views 0 likesThe open-source AI workbench for scientific research
15 views 0 likesDeepSeek-native AI coding agent for your terminal. Engineered around prefix-cache stability — leave it running.
15 views 0 likesA Fully free agentic browser driver for AI , few tools, full control, real stealth, top-tier token efficiency.
12 views 0 likes