gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Search MCP Github · gabrielmoreiraSearch MCP PRs, issues, and discussions across the modelcontextprotocol GitHub org
- ▌ Evaluating Llms Harness · gabrielmoreiraEvaluates LLMs across 60+ academic benchmarks (MMLU, HumanEval, GSM8K, TruthfulQA, HellaSwag). Use when benchmarking model quality, comparing models, reporting academic results, or tracking training progress. Industry standard used by EleutherAI, HuggingFace, and major labs. Supports HuggingFace, vLLM, APIs.
- ▌ Analyzing Docker Container Forensics · gabrielmoreira bundleInvestigate compromised Docker containers by analyzing images, layers, volumes, logs, and runtime artifacts to identify malicious activity and evidence.
- ▌ Analyzing Golang Malware With Ghidra · gabrielmoreira bundleReverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo and pclntab structures, recovering stripped/obfuscated function names (e.g. via GoResolver), and extracting embedded module/dependency strings and types from Go binaries. Use when analyzing a Go-language malware sample, deobfuscating a garble-packed Go binary, or recovering function names and third-party dependencies from a stripped Go executable.
- ▌ Analyzing Network Packets With Scapy · gabrielmoreira bundleUse Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during security testing.
- ▌ Analyzing Ransomware Payment Wallets · gabrielmoreira bundleTraces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments, performing cryptocurrency wallet forensics, or gathering blockchain threat intelligence on extortion payments.
- ▌ Analyzing Threat Landscape With Misp · gabrielmoreira bundleQuery a MISP (Malware Information Sharing Platform) instance via PyMISP to compute event statistics, IOC type breakdowns, threat actor galaxy clusters, and tag trends, and generate threat landscape reports with temporal trends. Use when asked to analyze threat intelligence data, summarize top threat actors or malware families, or produce a CTI landscape report from MISP events.
- ▌ Analyzing Windows Shellbag Artifacts · gabrielmoreira bundleAnalyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and Shellbags Explorer to reconstruct folder browsing activity and prove user interaction with directories, including removable media and network shares, even after the folders are deleted. Use when reconstructing a user's folder access history or proving access to a since-removed directory in DFIR work.
- ▌ Conducting Malware Incident Response · gabrielmoreira bundleRespond to malware infections across enterprise endpoints by identifying the malware family, determining infection vectors, assessing spread, and executing containment, analysis, eradication, and recovery procedures aligned to MITRE ATT&CK. Use when responding to a confirmed or suspected malware infection, including trojan/worm/ransomware outbreaks, malware triage, or infected endpoint remediation.
- ▌ Deploying Software Defined Perimeter · gabrielmoreira bundleDeploys a Software-Defined Perimeter per the CSA v2.0 specification, configuring Single Packet Authorization, mutual TLS, and SDP controller/gateway components to enforce zero trust network access. Use when building or hardening zero trust network architecture, implementing SPA-based "invisible" infrastructure that cloaks services from unauthenticated scanning, or meeting compliance requirements for zero trust network access.
- ▌ Detecting Container Drift At Runtime · gabrielmoreira bundleDetects unauthorized runtime drift in containers by monitoring binary execution, filesystem changes, and configuration deviation from the original immutable image, using Falco and Microsoft Defender for Containers. Use when validating immutable-infrastructure controls, hunting for unexpected package installs or binaries written inside a running container, or determining whether a container diverged from the image it was built from. Keywords: drift, immutable infrastructure, new binary executed, package install, image mismatch, Falco. Do not use for detecting breakout from the container to the host - use detecting-container-escape-attempts.
- ▌ Extracting Browser History Artifacts · gabrielmoreira bundleExtracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools (BrowsingHistoryView, ChromeCacheView, MZCacheView). Use when performing digital forensics or incident response on a disk image or live system and you need timeline evidence of a user's web activity.
- ▌ Extracting Iocs From Malware Samples · gabrielmoreira bundleExtracts indicators of compromise (IOCs) from malware samples, including file hashes, network indicators (IPs, domains, URLs, PCAP indicators), host artifacts (file paths, registry keys, mutexes), and behavioral patterns, using tools like CyberChef, then defangs and exports them in standard threat-intel formats. Use for IOC extraction, threat indicator harvesting, or building detection content from a sample.
- ▌ Hunting For Lateral Movement Via Wmi · gabrielmoreira bundleDetects WMI-based lateral movement (e.g. wmic process call create, Win32_Process.Create()) by analyzing Windows Event ID 4688 and Sysmon Event ID 1 for WmiPrvSE.exe spawning suspicious child processes like cmd.exe or powershell.exe, plus WMI-Activity/Operational events 5857/5860/5861 for subscription-based persistence. Use when hunting for remote code execution via WMI or investigating lateral movement across Windows hosts.
- ▌ Implementing Pam For Database Access · gabrielmoreira bundleDeploy privileged access management for database systems including Oracle, SQL Server, PostgreSQL, and MySQL, covering session proxy configuration, credential vaulting, query auditing, dynamic credential generation, and least-privilege database roles. Use when securing DBA access, implementing database PAM controls, or auditing privileged database sessions.
- ▌ Implementing Rsa Key Pair Management · gabrielmoreira bundleGenerates, stores, rotates, and manages RSA key pairs following NIST SP 800-57 guidelines, covering serialization formats (PEM, DER, PKCS#8), passphrase protection, and key strength validation. Use when creating or rotating RSA keys for signatures, key exchange, or encryption, or when auditing existing keys for proper storage and NIST-compliant strength.
- ▌ Orchestrating LLM Attacks With Pyrit · gabrielmoreira bundleBuild automated multi-turn adversarial attacks against conversational LLM targets using Microsoft PyRIT's RedTeamingOrchestrator, CrescendoOrchestrator (gradual escalation), and TreeOfAttacksWithPruningOrchestrator (adaptive branching), with scorer feedback loops and persisted conversation memory. Use when single-shot LLM scanning is insufficient and you need multi-turn, scorer-driven AI red-team campaigns against a chatbot or agent.
- ▌ Performing Container Image Hardening · gabrielmoreira bundleHarden container images by minimizing attack surface, stripping unnecessary packages, implementing multi-stage builds, configuring non-root users, and applying CIS Docker Benchmark recommendations to produce secure, production-ready images. Use when building production container images, when compliance requires CIS Docker Benchmark adherence, or when shrinking image size to reduce vulnerability exposure from unused packages.
- ▌ Performing Firmware Malware Analysis · gabrielmoreira bundleAnalyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Use for firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
- ▌ Performing JWT None Algorithm Attack · gabrielmoreira bundleExecute and test the JWT none algorithm attack, crafting tokens with the alg header set to none using PyJWT and an intercepting proxy (Burp Suite/mitmproxy) to bypass signature verification and forge arbitrary claims. Use during authorized penetration tests or security assessments of applications that use JWT for authentication or authorization, to validate that the server rejects unsigned tokens.
- ▌ Performing Sqlite Database Forensics · gabrielmoreira bundlePerforms forensic analysis of SQLite databases by examining B-tree page structures, recovering deleted records from freelist pages and Write-Ahead Log (WAL) files, decoding encoded timestamps, and extracting evidence from browser history, messaging apps, and mobile device databases. Use when recovering deleted or unallocated data from a SQLite database during digital forensics or mobile/browser evidence analysis.
- ▌ Scanning Container Images With Grype · gabrielmoreira bundleScans container images, filesystems, and SBOMs for known CVEs with Anchore Grype, matching Syft-generated SBOM packages against NVD, GitHub Advisories, and OS-specific feeds with configurable severity thresholds and failure gates. Use when Grype or Syft is the chosen toolchain, when scanning an existing SBOM rather than an image, or when gating a build on severity. Keywords: Grype, Syft, SBOM, NVD, GitHub Advisory, --fail-on, severity threshold. Do not use when the toolchain is Trivy - use scanning-docker-images-with-trivy.
- ▌ Tracking Threat Actor Infrastructure · gabrielmoreira bundleDiscovers and maps adversary-controlled infrastructure (C2 servers, phishing domains, exploit-kit hosts, bulletproof hosting) by pivoting across passive DNS, certificate transparency logs, Shodan/Censys scans, WHOIS records, and network fingerprints (JARM/JA3S). Use when tracking threat actor infrastructure, expanding a known IOC into related assets, or producing STIX-based threat intelligence during a CTI investigation.
- ▌ Android Accessibility · gabrielmoreiraExpert checklist and prompts for auditing and fixing Android accessibility issues, especially in Jetpack Compose.
- ▌ Context Window Design · gabrielmoreiraDesigning around token limits, memory, and conversation persistence.
- ▌ Conversation Patterns · gabrielmoreiraTurn-taking, repair sequences, grounding, and dialogue structure for human-AI interaction.
- ▌ Frustration Detection · gabrielmoreiraReading user emotional state from text signals — caps, punctuation density, repetition, latency — and adapting before the user disengages.
- ▌ Mixed Initiative Flow · gabrielmoreiraWhen the AI leads vs. when the user leads, and how to hand off control.
- ▌ Behavioral Consistency · gabrielmoreiraEnsuring the AI behaves predictably across sessions, edge cases, and modalities.
- ▌ Scanning Experiments With Replay Vision · gabrielmoreiraProvisions a Replay Vision scanner scoped to one experiment's exposed sessions: sets `experiment_targeting` so the API derives the person-scoped exposure filter server-side, templates a prompt that stays comparable across variants, sizes credit spend against the experiment's own population, and creates the scanner disabled so its prompt can be previewed on real sessions before it sweeps. TRIGGER when: user wants Replay Vision to watch an experiment, asks to scan or analyze an experiment's recordings with AI, asks "what are users actually doing in the test variant", or wants a scanner scoped to an experiment's exposed sessions. DO NOT TRIGGER when: creating a general-purpose scanner not tied to an experiment (use creating-replay-vision-scanners), reading observations a scanner already produced (use exploring-replay-vision-observations), or manually browsing an experiment's recordings without AI analysis (use analyzing-experiment-session-replays).
- ▌ Review Hog Perspective Logic Correctness · gabrielmoreiraThe Logic & Correctness review perspective for PostHog Review. Verifies that changed code does what it is supposed to do: business logic, edge cases, data transformations, and query / data-access correctness. Reports correctness issues only; security and performance are separate perspectives.
- ▌ Diagnosing Failed Warehouse Syncs · gabrielmoreiraDiagnose why a data warehouse sync is failing and recommend the right recovery action. Use when the user asks "why isn't my Stripe/Postgres/Hubspot sync working?", "this table has been stuck for hours", "the data in the warehouse looks wrong", or wants to troubleshoot a specific source or schema. Covers source-level vs schema-level failures, stuck Running states, credential and schema-drift errors, incremental-field misconfig, CDC prerequisite failures, and the cancel / reload / resync / delete-data recovery actions.
- ▌ Root Cause Analysis · gabrielmoreiraPerforms systematic root cause analysis to identify the true source of bugs, errors, and unexpected behavior through structured investigation phases — not just treating symptoms. Use when a user reports a bug, crash, error, or broken behavior and needs to debug, troubleshoot, or investigate why something is not working; especially for complex or intermittent issues across multiple components. Applies the Five Whys method, hypothesis-driven testing, stack trace analysis, git blame/log evidence gathering, and causal chain documentation to isolate and confirm root causes before applying any fix.
- ▌ Threejs Procedural Animation · gabrielmoreira bundleBuild advanced procedural animation in Three.js. Use for launch kinematics, gravity turns, staging, spin docking, target-frame decomposition, spring-follow motion, rotating-frame alignment, peeling debris, analytic transform timelines, frame-rate-independent response, and quaternion control.
- ▌ Threejs Procedural Materials · gabrielmoreira bundleAuthor production procedural materials in Three.js. Use for hybrid texture-backed PBR soil and moss with procedural displacement and masks, upward-facing model moss accumulation, atlas filtering, specular AA, planet-space fields, terrain wetness, lava and emissive surfaces, reflective wave-optical diffraction gratings, air-film-air soap bubbles with Airy interference, raytraced diamond and gem refraction with internal reflection and dispersion, image-space glass transmission with spectral dispersion and volume absorption, per-instance dissolve, authored PBR identities, derivative normals, and custom direct-light shadow modulation.
- ▌ Powershell Scripting · gabrielmoreiraIdiomatic PowerShell scripting — SupportsShouldProcess/-WhatIf/-Confirm, safe destructive operations, and preview-before-apply patterns
- ▌ Syncfusion Maui Toolkit Shimmer · gabrielmoreira bundleImplements Syncfusion .NET MAUI Shimmer (SfShimmer) loading placeholder effects. Use when implementing shimmer or skeleton loading animations, loading placeholders, or content loading indicators in .NET MAUI apps. Covers shimmer types (CirclePersona, Article, Feed, Shopping), custom shimmer views, wave animation, and customization.
- ▌ Syncfusion Maui Toolkit Tabview · gabrielmoreira bundleImplement tabbed navigation with Syncfusion MAUI TabView. Covers tab setup, customization, selection events, nested tabs, swiping gestures, and visual state management.
- ▌ Syncfusion Maui Toolkit Theming · gabrielmoreira bundleThemes and styles Syncfusion .NET MAUI components. Use when working with SyncfusionThemeResourceDictionary, MaterialLight, MaterialDark, visual themes, or theme switching. This skill covers theme customization, color overrides, theme keys, dark mode, light mode, and branding.
- ▌ Rails Dev · gabrielmoreiraOpinionated Rails conventions: rich models, concerns, CRUD-everything, state-as-records, minimal dependencies, Minitest with fixtures. Load this skill BEFORE any code-level thinking, not only before editing a file. It is required the moment a task touches Rails code in ANY way: designing or even just discussing a data model, schema, migration, entity, association, field, validation, class, or method name; writing, planning, reviewing, analyzing, testing, debugging, or refactoring; or proposing any model, table, column, route, or code snippet inline in chat. If you are about to name a model or sketch a column you are already in scope, even in an exploratory back-and-forth where no file is written yet. Do not let a "we're just discussing" framing defer it. Do NOT use for non-Rails backends, NestJS, or general architecture (use nestjs-modular-monolith or coding-guidelines).
- ▌ Azure Drawio MCP Diagramming · gabrielmoreiraCreate and edit architecture diagrams using Draw.io MCP (`drawio/create_diagram`) with reliable Azure icon rendering guidance and troubleshooting. compatibility Requires Python 3 and internet access to refresh the icon catalog (periodic, not per-run).
- ▌ Burpsuite Project Parser · gabrielmoreiraSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.
- ▌ AI Coding Agents Tasks · gabrielmoreiraDesigns task runtimes for Loop Engineering, Graph Engineering, and background work. Use when work needs task lists, cyclic/workflow graphs, cancellation, or teammate coordination.
- ▌ Dev Git Commit Message · gabrielmoreiraGenerates or validates Conventional Commits messages from staged diffs. Use when drafting commit messages, checking repo rules, or inferring scope from changed files.
- ▌ Software IOS AI Engine · gabrielmoreiraDesign local AI engines for iOS. Use when wiring Apple Foundation Models, local classifiers, extraction, summarization, grounded answers, and cloud fallbacks.
- ▌ Testing MCP Server Security · gabrielmoreiraTesting Model Context Protocol (MCP) servers and the clients that consume them for tool poisoning, prompt injection via tool descriptions/outputs, over-permissioned and local-credential-stealing tools, config/trust bypasses, and unauthenticated RCE during authorized penetration tests of AI agent infrastructure.
- ▌ Competition Ad Certificate Abuse · gabrielmoreiraInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- ▌ Competition Relay Coercion Chain · gabrielmoreiraInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for forced-auth coercion, relay chains, target selection, NTLM or related acceptance paths, and coercion-to-privilege transitions. Use when the user asks to trace a coercion primitive, follow a relay path, analyze forced authentication, determine which service accepts relayed auth, or connect a coercion step to resulting privilege, enrollment, or code execution. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- ▌ Competition Template Render Path · gabrielmoreiraInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for SSR, template rendering, route loaders, hydration payloads, server-client render boundaries, and template-to-handler enforcement gaps. Use when the user asks to inspect SSR or template routes, trace render context or hydration data, compare template gating with handler enforcement, explain preview or hidden-route rendering, or connect render pipeline behavior to the decisive branch. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- ▌ Strategic Narrative Designer · gabrielmoreiraUse when the user asks to "design our change narrative", "build the old-world-to-new-game story arc", or "frame the shift our category is undergoing"; produces a Raskin-style strategic narrative arc — old world → the undeniable shift → winners vs losers under the new rules → the promised land → proof the promised land is real — derived from the positioning truth set and the belief/objection map, feeding the TALE Architecture arc sub-item. Every proof beat is labeled Measured / User-provided / [needs source] and this skill never adjudicates a claim. Not for the message house hierarchy — use message-system-architect; not for the pitch deck narrative — use pitch-narrative-builder; not for claim substantiation — use offer-claims-registry. 变革叙事弧/旧世界/应许之地/战略叙事结构
- ▌ Citation Formatter · gabrielmoreiraUse when formatting references for journal submission, converting between citation styles (APA, MLA, Vancouver, Chicago), generating bibliographies for manuscripts, or ensuring consistent reference formatting. Automatically formats citations and bibliographies in 1000+ academi...
- ▌ Linkedin Optimizer · gabrielmoreiraUse when optimizing LinkedIn profiles for doctors, physicians, nurses, healthcare professionals, or medical researchers. Crafts compelling headlines, writes professional summaries, integrates healthcare keywords, and builds personal branding for medical careers.
- ▌ Biopython Sequence Io · gabrielmoreiraUse Biopython to read/write/convert biological sequence files (FASTA/GenBank/FASTQ, etc.) and perform basic sequence operations; use when you need reliable sequence I/O, lightweight sequence manipulation, or scalable processing of large sequence datasets.
- ▌ Circos Plot Generator · gabrielmoreiraGenerate Circos configuration files for circular genomics data visualization. Supports genomic variations (SNPs, CNVs, structural variants), cell-cell communication networks, and custom track configurations for publication-ready circular plots.
- ▌ Clinical Data Cleaner · gabrielmoreiraUse when cleaning clinical trial data, preparing data for FDA/EMA submission, standardizing SDTM datasets, handling missing values in clinical studies, detecting outliers in lab results, or converting raw CRF data to CDISC format. Cleans and standardizes clinical trial data fo...
- ▌ Meta Sensitivity Plot · gabrielmoreiraGenerate leave-one-out sensitivity analysis plots for meta-analysis. Input is a CSV file containing meta-analysis data; outputs are a sensitivity forest plot (PNG) and a sensitivity data table (CSV) showing pooled effect estimates after excluding each study in turn.
- ▌ Retraction Watcher · gabrielmoreiraAutomatically scan reference lists and check whether cited papers have been retracted, corrected, or flagged; use before submission, review, or evidence synthesis to reduce citation risk.
- ▌ Clinical Diagnostic Reasoning · gabrielmoreiraIdentify and counteract cognitive biases in medical decision-making through systematic error analysis and contextual algorithm application. For diagnostic reasoning, treatment decisions, and
- ▌ Resubmission Deadline Tracker · gabrielmoreiraTrack manuscript resubmission deadlines and automatically generate phase-appropriate task breakdowns for academic researchers based on remaining time.
- ▌
- ▌
- ▌ Universal Video Prompt Skill · gabrielmoreira bundleWrite one model-agnostic video prompt spec, then compile it to whichever video model you can actually call. Use for cross-model prompt work, model comparison matrices, reusing one brief across providers, or when the target model is not yet available and the work must proceed on another one.
- ▌ Devcontainers Nix · gabrielmoreiraCreate reproducible development environments with Dev Containers, Nix flakes, and Devbox for consistent toolchains across teams. Use when onboarding developers, standardizing build environments, or eliminating "works on my machine" problems.
- ▌ Model Serving Kubernetes · gabrielmoreiraDeploy ML models on Kubernetes with KServe (formerly KFServing) and NVIDIA Triton Inference Server. Includes canary deployments, autoscaling, model versioning, A/B testing, and GPU resource management for production model serving.
- ▌ Boltz Structure Prediction · gabrielmoreira bundleBoltz-1 / Boltz-2 structure prediction for proteins, complexes, and ligand-aware validation. Use this skill when: (1) Predicting protein complex structures, (2) Validating designed binders, (3) Need open-source alternative to AF2, (4) Predicting protein-ligand complexes, (5) Using local GPU resources. For QC thresholds, use protein-design-qc. For AlphaFold2 prediction, use alphafold2-multimer. For Chai prediction, use chai1-structure-prediction.
- ▌ Chai1 Structure Prediction · gabrielmoreira bundleChai-1 structure prediction for protein complexes and design validation. Use this skill when: (1) Predicting protein-protein complex structures, (2) Validating designed binders, (3) Predicting protein-ligand complexes, (4) Using the Chai API for high-throughput prediction, (5) Need an alternative to AlphaFold2. For QC thresholds, use protein-design-qc. For AlphaFold2 prediction, use alphafold2-multimer. For ESM-based analysis, use esm2-sequence-scoring.
- ▌ Machine Learning For Omics · gabrielmoreira bundleWorkflow for predictive modeling, biomarker discovery, survival modeling, and explainability over omics-derived features.
- ▌ Bio Chipseq Chromatin State Segmentation · gabrielmoreira bundleSegments the genome into chromatin states from combinatorial histone modification and chromatin factor ChIP-seq data. Uses ChromHMM (multivariate HMM on binarized signal, v1.27), Segway (Dynamic Bayesian Network on continuous signal), EpiSegMix (flexible-distribution HMM with duration modeling, 2024), EpiLogos (multi-biosample visualization), IDEAS (cell-type-aware joint), and full-stack ChromHMM (Vu Ernst 2022) for cross-cell-type segmentations. Handles state-count selection (15 vs 18 vs 25 states), binarization choice, OverlapEnrichment / NeighborhoodEnrichment downstream analysis, and cross-biosample integration. Use when learning chromatin states from a histone mark panel, characterizing learned states by genomic feature enrichment, or comparing chromatin landscapes across cell types.
- ▌ Bio Causal Genomics Effector Gene Prioritization · gabrielmoreira bundleMaps GWAS-implicated loci to candidate effector (causal) genes by integrating variant-to-gene (V2G) features via Open Targets L2G (Mountjoy 2021), MAGMA gene-based association (de Leeuw 2015), FUMA SNP2GENE, cS2G combined SNP-to-gene scores (Gazal 2022), Polygenic Priority Scores (PoPS, Weeks 2023), FLAMES, INQUISIT, DEPICT, and enhancer-gene predictors (ABC, ENCODE-rE2G). Use when narrowing a GWAS lead locus to a candidate causal gene, picking between proximity, eQTL-based, and similarity-based prioritizers, integrating multi-evidence streams (fine-mapping, colocalization, ABC enhancer-gene, distance, chromatin), reconciling discordant L2G vs PoPS calls, prioritizing tissue-specific eQTL evidence, or triangulating across at least three independent lines of evidence for a publication-grade effector-gene nomination.
- ▌ Managed Model Endpoints · gabrielmoreiraRegister a model service in the managed family — a local model server container the daemon starts/stops on demand, or a remote upstream model API (https). Read the runbook, allocate a port (local only), compose idempotent start/stop scripts (local only), register once. Load when the user wants a model service available for inference, or when list_compute shows managed endpoints.
- ▌ Bio Protein Clustering Pangenome · gabrielmoreira bundleCluster proteins into orthogroups and derive pangenome matrices.
- ▌ Clinical Trial Protocol Skill · gabrielmoreira bundleGenerate clinical trial protocols for medical devices or drugs. This skill should be used when users say "Create a clinical trial protocol", "Generate protocol for [device/drug]", "Help me design a clinical study", "Research similar trials for [intervention]", or when developing FDA submission documentation for investigational products.
- ▌ Bcftools Variant Manipulation · gabrielmoreiraCLI for VCF/BCF: filter, merge, annotate, query, normalize, compute stats. Core post-variant-calling: quality filtering, multi-sample merging, rsID annotation, genotype extraction. Samtools companion in HTSlib. Use GATK for complex indel realignment during calling; use VCFtools for population genetics stats.
- ▌ Plannotate Plasmid Annotation · gabrielmoreiraAuto-annotate plasmids with features (promoters, terminators, resistance, origins, tags, fluorescent proteins) via BLAST against curated DBs (Addgene, fpbase, SnapGene). FASTA or raw sequence in; annotated GenBank, interactive HTML maps, CSV tables out. Handles circular topology. Use to verify synthetic constructs, prep Addgene submissions, share maps, or batch-annotate cloning libraries.
- ▌ Scikit Learn Machine Learning · gabrielmoreiraClassical ML in Python: classification, regression, clustering, dim reduction, evaluation, tuning, preprocessing pipelines. Linear models, tree ensembles, SVMs, K-Means, PCA, t-SNE. Use PyTorch/TF for deep learning; XGBoost/LightGBM for scale.
- ▌
- ▌ X Algo Tweet Writer · gabrielmoreira bundleUse this skill whenever the user asks to write, draft, or create a tweet, X post, thread, quote-tweet, or reply on X (formerly Twitter). Also trigger when the user shares a topic, news item, link, or rough idea and wants it shaped into an X post. Covers all formats: single tweets, short threads, quote-tweets, reply-jacks, and posts with image/video. Every tweet produced should be engineered to perform well under the X 'For You' algorithm based on the leaked xAI source code (May 2026): optimize for dwell + reply + follow_author, cross the 30-minute min-traction gate, avoid AI slop and negative signals (not_dwelled, not_interested, block, mute, report), and apply the right format for the goal (reach vs. engagement vs. follower growth). Use this even if the user just says 'tweet this' or 'post about X' — assume they want algorithm-optimized output. Do NOT use for LinkedIn posts (use linkedin-post-writer), blogs (use organic-traffic-generator), or Unrot daily news items (use unrot-news-writer).
- ▌
- ▌ Component Common Domain Detection · gabrielmoreira bundleFinds duplicate business logic spread across multiple components and suggests consolidation. Use when asking "where is this logic duplicated?", "find common code between services", "what can be consolidated?", "detect shared domain logic", or analyzing component overlap before refactoring. Do NOT use for code-level duplication detection (use linters) or dependency analysis (use coupling-analysis).
- ▌ Update Oo Component Documentation · gabrielmoreiraUpdate existing object-oriented component documentation following industry best practices and architectural documentation standards.
- ▌ Experiment Iterative Coder · gabrielmoreiraIterative code refinement through plan → code → evaluate → refine cycles. Runs lint checks (ruff), tests (pytest), and structured self-evaluation each cycle, then diagnoses failures and refines. Decomposes complex tasks into sequential phases, iterates up to 3 times per phase (10 total). Use when: the main agent delegates a code task with 'MODE: MORE_EFFORT', the user selects 'More Effort' code generation mode, or the task explicitly requests iterative refinement for higher code quality. Do NOT use for single-pass code generation (Lite mode), experiment pipeline orchestration (use experiment-pipeline), or diagnosing a specific experiment failure (use experiment-craft).
- ▌ Bio Workflow Methods Docwriter · gabrielmoreira bundleGenerate reproducible Methods documentation from workflow run artifacts (Nextflow/Snakemake/CWL), including exact commands, versions, parameters, QC gates, and outputs.
- ▌ Medea Therapeutic Discovery · gabrielmoreiraAn AI agent for therapeutic discovery that executes transparent, multi-step omics analyses including research planning, code execution, and literature reasoning.
- ▌ Biopython Molecular Biology · gabrielmoreiraMolecular biology toolkit: sequence manipulation, FASTA/GenBank/PDB I/O, NCBI Entrez, BLAST automation, pairwise/MSA alignment, Bio.PDB, phylogenetic trees. Use for batch processing, custom pipelines, format conversion, PubMed/GenBank queries. For quick gene lookups use gget; for multi-service REST APIs use bioservices.
- ▌ Biopython Sequence Analysis · gabrielmoreiraBiopython sequence analysis: parse FASTA/FASTQ/GenBank/GFF (SeqIO), NCBI Entrez (esearch/efetch/elink), remote/local BLAST, pairwise/MSA alignment (PairwiseAligner, MUSCLE/ClustalW), phylogenetic trees (Phylo). Use for gene family studies, phylogenomics, comparative genomics, NCBI pipelines. For PCR/restriction/cloning use biopython-molecular-biology; for SAM/BAM use pysam.
- ▌ Busco Status Interpretation · gabrielmoreiraGuide to interpreting BUSCO completeness statuses: why Duplicated BUSCOs count as complete, parsing output files, computing/comparing completeness across proteomes/genomes, common counting mistakes. Use when running BUSCO QC, comparing assemblies, or reporting completeness. See also: prokka-genome-annotation for annotation workflows feeding BUSCO.
- ▌ Cellchat Cell Communication · gabrielmoreiraInfer and visualize intercellular communication from scRNA-seq with CellChat (R). Build CellChat from Seurat/counts → subset CellChatDB ligand-receptor pairs → over-expressed genes per group → communication probabilities → pathway signaling → network centrality (senders/receivers/influencers) → chord/heatmap/bubble plots → cross-condition compare. Human, mouse. Use liana for pure-Python.
- ▌ Chembl Database Bioactivity · gabrielmoreiraQuery ChEMBL (2M+ compounds, 19M+ bioactivity measurements, 13K+ targets) via the public REST/JSON API with plain `requests` — no SDK install required. Search compounds, retrieve IC50/Ki/EC50 bioactivities, find target inhibitors, run SAR, access drug mechanism/indication data.
- ▌ Startupblueprint · gabrielmoreira bundleTurn a startup, SaaS, app, developer tool, website, repository, or product idea into an evidence-backed business plan, monetization strategy, pricing architecture, editable 12-month financial model, and 90-day execution roadmap. Use when Codex needs to analyze how a startup can become a sustainable business; decide free versus paid, monthly, annual, usage-based, one-time, or lifetime pricing; design tiers and upgrade triggers; estimate unit economics and break-even under explicit assumptions; compare scenarios; or produce a native Markdown business plan, formula-driven Excel workbook, and CSV roadmap from a URL or description.
- ▌ Report Writer · gabrielmoreiraGenerate professional reports from analysis results. Use when user needs to create formatted documents summarizing findings.
- ▌ Csharp MCP Server Generator · gabrielmoreiraGenerate a complete MCP server project in C# with tools, prompts, and proper configuration
- ▌ Dependency Management · gabrielmoreiraVersion pinning, vulnerability scanning, monorepo patterns, and upgrade workflows
- ▌ Micro Learning · gabrielmoreiraContent chunking, mobile-first learning, spaced delivery, engagement patterns, and platform best practices
- ▌ Component Design Systems · gabrielmoreiraBuilding and maintaining scalable component libraries, design tokens, accessibility, and cross-team collaboration patterns
- ▌ Agent Observability Session Classify · gabrielmoreiraClassify whether user intent was satisfied in a Datadog Agent Observability trace or session. Three modes: (1) session_id — classify a single CMD+I assistant session with RUM; (2) trace_id — classify a single Agent Observability trace without RUM; (3) ml_app — sample and classify multiple sessions or traces from a given LLM app. Output is compact by default (verdict + one-sentence reason). Use when evaluating satisfaction, classifying sessions/traces, labeling data, or generating signal for agent-observability-eval-pipeline or agent-observability-trace-rca.
- ▌ Patentfig · gabrielmoreiraGenerate patent-office-compliant figures via the PatentFig AI API — patent line art from text (PNG or SVG), vectorize drawings to SVG/DXF/vector PDF, AI-upscale images, and convert to filing-ready TIFF/PDF/PNG. Use when the user asks for patent drawings, patent figures, invention diagrams, USPTO/EPO-compliant line art, vectorizing a drawing for CAD, or preparing figures for a patent filing. Requires a PATENTFIG_API_KEY environment variable.
- ▌ Figma Implement Motion · gabrielmoreiraTranslates Figma motion and animations into production-ready application code. Use when implementing animation/motion from a Figma design — user mentions "implement this motion", "add animation from Figma", "animate this component", provides a Figma URL whose node is animated, or when `get_design_context` returns motion data or instructs you to call `get_motion_context`.
- ▌ Frontend Dev Guidelines · gabrielmoreira bundleFrontend development guidelines for React/TypeScript applications. Modern patterns including Suspense, lazy loading, useSuspenseQuery, file organization with features directory, MUI v7 styling, TanStack Router, performance optimization, and TypeScript best practices. Use when creating components, pages, features, fetching data, styling, routing, or working with frontend code.
- ▌ Autocoverage · gabrielmoreiraUse when a user asks to generate or improve unit tests with measurable coverage gains using a strict staged workflow (build -> baseline -> plan -> generate -> verify -> coverage delta). Trigger phrases: generate unit tests, improve coverage, write tests for uncovered code, make PR-ready tests. Do not use for integration/E2E testing, production refactoring, or planning-only requests without code generation intent.
- ▌ Mermaid Expert · gabrielmoreiraCreate Mermaid diagrams for flowcharts, sequences, ERDs, and architectures. Masters syntax for all diagram types and styling.