gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Gpu Document Processing · gabrielmoreiraUse when processing large PDFs, document collections, or bulk text extraction tasks that benefit from GPU-accelerated processing. Triggers when the user provides large documents or needs bulk document analysis.
- ▌ Bacen Compliance Sentinel Rafael Mastronardi · gabrielmoreira bundleOrientação completa sobre conformidade com regulamentações do Banco Central do Brasil: Resolução CMN nº 4.893/2021 (Política de Segurança Cibernética), Resolução BCB nº 85/2021 (GRSIC), Open Finance Brasil (Resoluções BCB nº 32/2020 e atualizações), e demais normas prudenciais do BACEN. Cobre elaboração e revisão de Política de Segurança Cibernética, Plano de Ação e Resposta a Incidentes (PARI), Gestão de Riscos de Serviços de Informação e Comunicação (GRSIC), consentimento e compartilhamento de dados no Open Finance, requisitos de API, gestão de terceiros (outsourcing) e sanções do BACEN. Triggers: Bacen, Banco Central, CMN 4.893, Resolução 4.893, segurança cibernética bancária, PARI, GRSIC, Open Finance, Open Banking, compartilhamento de dados financeiros, consentimento Open Finance, API financeira, outsourcing bancário, risco cibernético, incidente cibernético banco, LGPD financeira, fintech compliance, instituição financeira, DICT, Pix segurança.
- ▌ Continuous Improvement Engine Scott Margetts · gabrielmoreira bundleCapture, structure, and recycle lessons from active and closed legal matters. Three modes: in-flight capture (triggered by scope changes, risk events, status updates — highest value), mid-matter review (phase gates or quarterly), and matter close retrospective (full structured findings). Lessons are formatted for immediate reuse, not filed and forgotten. Use when a risk materialises, a scope change lands, a phase completes, or a matter closes and you want to convert what happened into something useful for the next matter. Trigger on: 'capture a lesson', 'what did we learn', 'matter close', 'retrospective', 'lessons learned', 'what went wrong', 'what worked', 'phase gate review', 'debrief', 'extract the learning', 'close the matter', 'what should we do differently', 'pattern from this matter', 'improve the next one'.
- ▌ Eac Habre Jeanne Sulzer · gabrielmoreira bundleMéthodologie « verification-first » pour les Chambres Africaines Extraordinaires (procès Hissène Habré, Dakar). Toute citation est vérifiée (forumchambresafricaines.org, legal-tools.org). Couvre le jugement du 30 mai 2016, l'arrêt d'appel du 27 avril 2017 (réparations de 82,290 milliards FCFA pour 7 396 victimes), et la compétence universelle. Aide à la recherche, pas un conseil juridique. Fait partie de la bibliothèque open source « Skills for International Justice » — méthodologie : github.com/jeannesulzer/international-criminal-tribunals-skills
- ▌ Litigacion Latam Joselyne Garcia Montesdeoca · gabrielmoreira bundleAsesor experto en litigación bajo sistemas de derecho civil (civil law) en América Latina. Asiste a abogados litigantes, equipos legales internos y clientes directos con estrategia procesal, análisis de riesgos, opciones tácticas, plazos y orientación sobre el proceso civil en múltiples jurisdicciones. Al final de cada sesión redacta un correo electrónico claro que resume los hallazgos para el cliente.
- ▌ Matter Allocation Instruction · gabrielmoreira bundleFirm-matter matching, matter instruction drafting, firm onboarding checklist, and instruction audit for in-house legal ops teams. Match a new matter to the right panel firm by practice area, jurisdiction, complexity, and cost tier. Produce a structured matter instruction with scope, timeline, budget, staffing, and reporting requirements. Generate an onboarding checklist covering conflict clearance, engagement letter, OCG acknowledgment, e-billing setup, and platform access. Audit an existing instruction for completeness and produce a remediation note. Trigger on: 'which firm should handle this', 'instruct the firm', 'write the instruction', 'matter instruction template', 'onboard the firm', 'set up the matter', 'conflict check', 'e-billing setup', 'is our instruction complete', 'review our instruction', 'instruction gap', 'allocate this matter'.
- ▌ Regulatory Deal Card Generator Patrick Munro · gabrielmoreira bundleGenerates standalone interactive HTML "deal cards" that translate complex regulations into negotiation-ready reference tools, systematically distinguishing mandatory obligations from negotiable implementation choices. Use when the user needs an interactive regulatory guide for (1) contract negotiation support, (2) client education or internal training, (3) regulatory briefings for commercial stakeholders, or (4) structured comparison between required and flexible compliance paths. Primary focus on EU digital regulation (Data Act, AI Act, CRA, DORA, NIS2, GDPR) but the structural pattern transfers to any regulation where separating hard obligations from implementation choice is the point. Supports bilingual output where the jurisdiction calls for it.
- ▌ Runtime Admissibility Review · gabrielmoreira bundleDetermines whether a specific AI-agent action, output, recommendation, or proposed commitment remains admissible for execution or institutional reliance under current authority, delegated scope, evidence, facts, policy, risk, escalation, and revocation conditions. Use this Skill before an enterprise or regulated AI agent executes, updates records, triggers workflows, communicates externally, or before an institution relies on an agentic output in a way that creates consequence.
- ▌ Scsl Rscsl Special Court For Sierra Leone Jeanne Sulzer · gabrielmoreira bundleVerification-first methodology for the Special Court for Sierra Leone and its Residual Special Court. Citations are verified against rscsl.org and legal-tools.org. Covers Taylor, the AFRC/CDF/RUF cases, the child-soldier and forced-marriage holdings, the head-of-State immunity decision, and the fixed-term (no life) penalty regime. Research aid, not legal advice. Part of the open-source "Skills for International Justice" library — methodology: github.com/jeannesulzer/international-criminal-tribunals-skills
- ▌ Jep Jeanne Sulzer · gabrielmoreira bundleVerification-first methodology for the Jurisdicción Especial para la Paz (JEP), Colombia's transitional justice court under the 2016 Acuerdo Final with FARC-EP. Citations are verified against jep.gov.co before use. Covers the 11 macrocasos (from Caso 01 secuestro through Caso 11 violencia sexual, including Caso 03 falsos positivos), the three sanction tiers (propias, alternativas, ordinarias), TOAR, and the SIVJRNR sister bodies (CEV, UBPD). Guards the key structural distinctions (Sala de Reconocimiento vs Tribunal para la Paz; comparecientes FARC-EP vs Fuerza Pública vs terceros civiles; Acto Legislativo 01/2017 vs Ley Estatutaria 1957/2019). Research aid, not legal advice.
- ▌ Uk Citation Verification Matei Clej · gabrielmoreira bundleVerifies UK case-law citations, pinpoint references and quotations against the official public register — The National Archives' Find Case Law — and statutory references against legislation.gov.uk, before a document that cites them is relied on, served or filed. Every check returns a graded verdict: VERIFIED, MISMATCH (the citation resolves to a different case — the classic AI miscitation), NOT ON REGISTER, OUTSIDE COVERAGE (the register cannot answer — absence proves nothing), or UNCHECKABLE (a law-report citation). The grading exists because there are two ways to get this wrong: citing a case that does not exist, and accusing a real case of not existing. Use when asked to check citations, verify a case exists, confirm a quotation is verbatim, check a pinpoint paragraph, audit a draft's authorities, screen a document for hallucinated cases, or check a statutory provision is in force. Not a substitute for reading the judgment: existence is not authority.
- ▌ Growth Strategy Knowledge Builder · gabrielmoreira将增长目标、指标体系、渠道策略、实验计划、复盘结论、资源约束和停止条件,整理成符合 Agent Knowledge v0.6 document-first 标准、可被 AI 安全调用的增长策略知识库。适用于用户要求“整理增长知识库”“沉淀增长策略”“把增长计划变成项目资料”“维护增长实验资料包”的场景。
- ▌ Agent Prompt Quality Bar · gabrielmoreiraUniversal quality bar and final audit rubric for any agent system prompt. Activate this whenever you are unsure which archetype skill applies, or as a final review pass before writing the system prompt. It defines the required run contract, completion criteria, fallback paths, response format, and anti-patterns every produced agent prompt must satisfy.
- ▌ Matlab Log Tutor Sessions · gabrielmoreiraUse when starting, continuing, updating, exporting, or sharing a running transcript of a MATLAB AI tutoring session, especially when the transcript will be shared with an instructor, attached to a learner session report, or passed to an evaluation workflow for quality review.
- ▌ Simulink Linearize · gabrielmoreiraLinearize Simulink models. Use when obtaining linear time invariant or linear parameter varying models from Simulink models.
- ▌ Create Sdi Run · gabrielmoreiraImport data into the Simulation Data Inspector (SDI) from MAT, CSV, or Excel files, from workspace variables, or from a Simulink simulation. Use when the user wants to view a logged file in SDI, load a bench-test log, or verify what a just-completed `Simulink.sdi.createRun` or `sim(model)` produced. Covers the `'file'`, `'vars'`, and `'namevalue'` sources of `createRun`, the auto-populate behavior after `sim()`, and post-import verification. Not for comparing existing runs (use `Simulink.sdi.compareRuns`); not for streaming data live during a running simulation (use `Simulink.sdi.createRunOrAddToStreamedRun` — a separate API); and not for authoring Gherkin or Simulink Test test cases, assertions, or regression tests (use `testing-simulink-models`). Do not activate on test-authoring or verification prompts even when no test-authoring skill is available — say so and stop.
- ▌ Azure Kusto Irql · gabrielmoreiraCompose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Translates natural language hunting questions into composable IRQL pipelines using Get_*, Extract_*, and Enrich_* functions. WHEN: IRQL query, security hunt, threat hunting KQL, incident response query, compose hunting pipeline, failed logins, phishing investigation, lateral movement, process execution, file creation events.
- ▌ Azure Mgmt Botservice Py · gabrielmoreiraAzure Bot Service Management SDK for Python. Use for creating, managing, and configuring Azure Bot Service resources. Triggers: "azure-mgmt-botservice", "AzureBotService", "bot management", "conversational AI", "bot channels".
- ▌ 25 Voice Clone Podcast · gabrielmoreiraDung khi mot CA NHAN can AM THANH bang AI — clone giong noi, lam podcast, audiobook, voiceover cho video: 3 use case gom voiceover ngan cho TikTok va Reels, podcast 30-60 phut, audiobook; quy trinh thu mau giong, chinh cam xuc va toc do, cong bo dung luat, tai su dung 1 podcast thanh 10 clip ngan. Kich hoat khi user nhac 'voice clone', 'clone giong noi', 'ElevenLabs', 'lam podcast', 'audio AI', 'voiceover AI', 'ngai thu am moi ngay', 'cat podcast ra clip ngan'. Khong dung cho — video co hinh anh nguoi hoac avatar thi dung skill 24-ai-avatar-production; viet loi thoai va hook noi thi dung skill 04-script-video; viet bai dai dang chu thi dung skill 26-thought-leadership-content.
- ▌ Database Schema Validator · gabrielmoreiraValidates SQL schema files for compliance with internal safety and naming policies.
- ▌ Analyzing Uefi Bootkit Persistence · gabrielmoreira bundleAnalyzes UEFI bootkit persistence (SPI flash implants, ESP modifications, Secure Boot bypass, UEFI variable manipulation) using chipsec for firmware integrity verification, detecting known families like BlackLotus, LoJax, and MoonBounce. Use for UEFI malware analysis, firmware persistence investigation, or Secure Boot bypass detection.
- ▌ Auditing Cloud With Cis Benchmarks · gabrielmoreira bundleAudit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking remediation for continuous compliance. Use when conducting a cloud security audit, validating CIS benchmark compliance (CIS v5 AWS, v4 Azure, v4 GCP), or setting up continuous cloud compliance monitoring.
- ▌ Conducting Cloud Incident Response · gabrielmoreira bundleRespond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure. Use when CSPM alerts or audit logs show compromised cloud credentials, unauthorized IAM changes, or a breach spanning cloud services.
- ▌ Configuring Pfsense Firewall Rules · gabrielmoreira bundleConfigures pfSense firewall rules, NAT policies, IPsec/OpenVPN tunnels, and traffic shaping to enforce network segmentation and control traffic between zones such as DMZ, internal, guest, and IoT. Use when deploying a pfSense perimeter or internal firewall, setting up port-forwarding NAT, configuring site-to-site or remote-access VPNs, or applying QoS/bandwidth policies.
- ▌ Detecting Data And Model Poisoning · gabrielmoreira bundleIdentify poisoned training data and backdoored ML models across the pipeline using IBM's Adversarial Robustness Toolbox (activation clustering, spectral signatures, trigger reconstruction), Cleanlab for label-quality issues, and supply-chain checks like weight-hash verification and safetensors enforcement. Use before training or deploying on third-party/user-contributed data or downloaded checkpoints, during ML supply-chain reviews, or when investigating model misbehavior tied to specific inputs (suspected backdoor trigger).
- ▌ Detecting Email Account Compromise · gabrielmoreira bundleDetect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule, New-InboxRule), external mail forwarding rules, and unusual Microsoft Graph API access or OAuth token use. Use when investigating suspected business email compromise (BEC), account takeover, or mailbox persistence via malicious inbox rules.
- ▌ Detecting Insider Threat Behaviors · gabrielmoreira bundleDetect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft. Use when proactively threat-hunting for malicious or negligent insider activity, or when investigating a departing or disgruntled employee for potential data theft.
- ▌ Detecting Insider Threat With Ueba · gabrielmoreira bundleImplement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and alert on insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access. Use when building or tuning a UEBA pipeline rather than a one-off manual hunt.
- ▌ Detecting Model Extraction Attacks · gabrielmoreira bundleDetect MITRE ATLAS AML.T0024 attacks (model stealing, inversion, membership inference) performed via inference-API abuse, by monitoring per-principal query volume/distribution, rate-limiting and perturbing outputs, and red-teaming your model's extractability. Use for a public or partner inference API needing cloning/inversion/membership-inference detection, or a pre-deployment red-team exercise to measure extraction risk.
- ▌ Operationalizing Misp Threat Feeds · gabrielmoreira bundleStand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules. Use when maturing a MISP instance to actively drive detection, curating threat feeds with quality controls, or automating IOC-to-detection pipelines for the SIEM/IDS.
- ▌ Performing Blind Ssrf Exploitation · gabrielmoreira bundleDetect and exploit blind Server-Side Request Forgery (SSRF) using out-of-band techniques such as Burp Collaborator DNS interactions and timing analysis, to reach internal services and cloud metadata endpoints even when server responses are not reflected. Use when testing URL/webhook parameters, PDF generators, image processors, or import/preview features where SSRF output cannot be observed directly.
- ▌ Performing Steganography Detection · gabrielmoreira bundleDetects and extracts hidden data embedded in images, audio, and other media files using steganalysis tools such as StegDetect, zsteg, stegsolve, binwalk, steghide, and OpenStego to uncover covert communication channels. Use when investigating suspected data hiding or exfiltration via media files, espionage/insider-threat cases, or anomalies in media file properties found during standard file analysis.
- ▌ Scanning Iac And Images With Trivy · gabrielmoreira bundleScans container images, Infrastructure-as-Code (Terraform, CloudFormation, Kubernetes manifests, Dockerfile, Helm), filesystems, git repos, and SBOMs with Trivy's vuln, misconfig, secret, and license scanners. Use when building a CI/CD security gate that scans images before push, IaC before apply, or SBOMs for supply-chain weaknesses, and fails the build on policy violations.
- ▌ Securing Container Registry Images · gabrielmoreira bundleSecures container registry images (ECR, ACR, GCR, Docker Hub) by scanning with Trivy and Grype, signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that block unscanned or unsigned images. Use when establishing registry security controls or enforcing scan/signature checks before image promotion.
- ▌ Testing For Email Header Injection · gabrielmoreira bundleTests web application email functionality (contact forms, password reset, newsletter subscriptions) for CRLF/SMTP header injection using Burp Suite and OWASP ZAP, checking whether attackers can inject headers, modify recipients, or abuse forms for spam relay. Use when testing any user-input-driven email-sending feature during a penetration test.
- ▌ Long Horizon Prompting · gabrielmoreira bundleThis skill should be used when writing, enhancing, or evaluating the launch prompt for a long-running autonomous agent or a parallel multi-agent orchestration attacking a hard problem: pseudo-formal task briefs that define terms and an exact success predicate linguistically, enumerate non-counting outcomes, set persistence rules with explicit stop and return conditions and effort floors, manage a diverse portfolio of parallel approaches with an approach registry and blocked-route bookkeeping, and gate the return on adversarial audit. Route agent topology and coordination protocols to multi-agent-patterns, runtime control surfaces and loop governance to harness-engineering, evaluator and quality-gate construction to evaluation, judge design to advanced-evaluation, and compaction or memory mechanics to context-compression and memory-systems.
- ▌ Redteam Cache Poison Detail Pack · gabrielmoreiraDomain routing and boundary guidance for authorized web cache poisoning testing, including unkeyed headers, unkeyed parameters, cache deception, and CDN-specific behavior. Use when a task belongs to the cache poisoning domain and needs scope, evidence, pivot, or exit criteria.
- ▌ Redteam Clickjacking Detail Pack · gabrielmoreiraDomain routing and boundary guidance for authorized clickjacking testing, including missing X-Frame-Options, CSP frame-ancestors bypasses, and drag-and-drop hijacking. Use when a task belongs to the clickjacking domain and needs scope, evidence, pivot, or exit criteria.
- ▌ Nano Banana Pro Openrouter · gabrielmoreiraDeterministic OpenRouter image generation adapter for Nano Banana Pro / Gemini image models. Use as skill_exec when a meta-skill needs local image files and structured IMAGE_READY records without spawning an LLM agent.
- ▌ Openrouter Video Generator · gabrielmoreiraGenerate or declare an OpenRouter video asset for AwesomeWebpageMetaSkill using a parent-leased Provider Settings connection and configured non-secret model/output values.
- ▌ Short Drama Delivery Audit · gabrielmoreiraInternal deterministic delivery gate for meta-short-drama. Verifies real-provider image/video receipts, parent-owned paid-submission dispositions, runtime fallback evidence, decodability, and content-versus-final duration with ffprobe.
- ▌ Bias Detection Design · gabrielmoreiraDesigning review workflows to surface and mitigate bias in AI outputs.
- ▌ Transparency Patterns · gabrielmoreiraShowing users what the AI knows, doesn't know, and how confident it is.
- ▌ Agent Role Design · gabrielmoreiraDefining what each agent does, knows, and owns in a multi-agent system.
- ▌ Handoff Protocols · gabrielmoreiraDesigning smooth transitions between agents and between AI and humans.
- ▌ Human In The Loop · gabrielmoreiraDesigning intervention points where humans review, approve, or redirect agent work.
- ▌ Constraint Specification · gabrielmoreiraDefining output format, length, tone, and content boundaries within prompts.
- ▌
- ▌ Setting Up A Custom REST Source · gabrielmoreiraConnect an arbitrary REST API to the PostHog data warehouse as a Custom source by authoring a JSON manifest, with no per-source code. Use when the user points at an API that has no built-in PostHog connector — "import data from this REST API", "sync my internal API", "connect this API from its docs", "build a custom data warehouse source" — and gives a docs URL or a natural-language description of the endpoints. Walks through drafting the RESTAPIConfig manifest (auth — bearer, API key, HTTP basic, or OAuth2 client credentials / refresh token — pagination, record path, incremental cursor, parent/child fan-out), validating it, test-reading live rows to verify the field mappings, and creating the source. If the API already has a native PostHog connector, use setting-up-a-data-warehouse-source instead — this skill checks the connector registry first and only handles APIs with no native connector.
- ▌ Retentioneering Contributing · gabrielmoreira bundleHelp the user turn their Retentioneering ideas, friction reports, bug findings, or feature needs into high-quality upstream contributions: from capturing and validating the idea, through minimal reproductions and issue drafts, to preparing, testing, and submitting a pull request that follows this repository's conventions. Use when the user says they found a bug, wants a feature, wrote a workaround worth upstreaming, or asks how to contribute, open an issue, or make a PR to retentioneering-tools.
- ▌ Threejs Procedural Planets · gabrielmoreira bundleAuthor procedural planetary bodies in Three.js. Use for spherical terrain, continents, ridges, craters, biome masks, coastlines, material variation, analytic normals, altitude LOD, and bodies that must hold up from orbit through close approach.
- ▌ Powershell Profile · gabrielmoreiraPowerShell profile engineering, PSReadLine configuration, prompt customization, git worktree detection, Start-Copilot script, and symlink management
- ▌ Typescript CLI · gabrielmoreiraProcess pools, atomic caching, rate limiting, graceful shutdown, file matching, and Windows gotchas
- ▌ Tracing Recompositions At Runtime · gabrielmoreiraUse this skill to instrument a Jetpack Compose composable with `@TraceRecomposition` from `skydoves/compose-stability-analyzer` so per-recomposition diffs (which state or parameter changed, what value transition) print to logcat under the `Recomposition` tag. Works in release-with-debug-symbols builds where Android Studio Layout Inspector cannot reach, and feeds the IntelliJ / Android Studio plugin's live recomposition heatmap (green under 10, yellow 10–50, red 50+). Covers the Gradle plugin setup, the `ComposeStabilityAnalyzer.setEnabled(BuildConfig.DEBUG)` runtime gate that keeps the instrumentation out of production, and the handoff to debug-time Layout Inspector and CI `stabilityCheck`. Use when the user mentions `@TraceRecomposition`, "trace recomposition", "compose-stability-analyzer", "recomposition logcat", "recomposition heatmap", "release-mode recomposition counts", or needs to confirm a stability fix in a release-like build.
- ▌ Using Strong Skipping Correctly · gabrielmoreiraUse this skill to reason about Jetpack Compose's Strong Skipping Mode — the default since Kotlin 2.0.20 — including what it changes about skippability, when it does and does not auto-`remember` lambdas, and which escape hatches (`@DontMemoize`, `@NonSkippableComposable`, `@NonRestartableComposable`, `@ReadOnlyComposable`) apply where. Covers verifying the mode is active, auditing lambda capture sites, and the gaps where strong skipping does not memoize (`LazyListScope.items {}`, `Modifier.pointerInput {}`, object expressions, non-@Composable scopes). Use when the developer asks "do I still need @Stable?", "does this composable skip?", "why does this still recompose despite strong skipping", "when do I need @DontMemoize or @NonSkippableComposable?", is migrating from older Compose, or sees auto-remembered lambdas in compiler output.
- ▌ Using Stability Analyzer Ide Plugin · gabrielmoreiraUse this skill to install and operate the `skydoves/compose-stability-analyzer` IntelliJ / Android Studio plugin so the developer sees Compose stability feedback live in the editor instead of waiting for a Gradle build. Covers installing the plugin from disk, configuring the `Settings → Tools → Compose Stability Analyzer` panel, reading the four gutter colors (green stable, red unstable, yellow runtime, gray no-params), the per-parameter hover documentation, the inline parameter hint badges, and the `UnstableComposable` weak-warning inspection with its `@Suppress("NonSkippableComposable")` and `@Suppress("ParamsComparedByRef")` quick fixes. Use when the user mentions gutter icons, inline hints, the stability inspection, the IDEA plugin, real-time stability feedback while editing, or asks why a composable is flagged as non-skippable in the editor.
- ▌ Syncfusion Maui Toolkit Cards · gabrielmoreira bundleImplements Syncfusion .NET MAUI Cards (SfCards) - dismissible card views and swipeable card stacks. Use when working with cards, card views, card layouts, swipeable cards, dismissible cards, or card stacks in .NET MAUI. Covers card customization, card events, card data binding, and interactive card components with swipe functionality.
- ▌ Syncfusion Maui Toolkit Chips · gabrielmoreira bundleImplements Syncfusion .NET MAUI Chips (SfChip or SfChipGroup). Use when working with chips, tags, tag controls, selection chips, input chips, or filter chips in .NET MAUI applications. Covers chip types, chip customization, chip events, chip selection, chip groups, remove chips, close button chips, and chip data binding.
- ▌ Syncfusion Maui Toolkit Popup · gabrielmoreira bundleImplements Syncfusion .NET MAUI Popup (SfPopup) control for displaying alert messages, custom views, and modal dialogs. Use when working with popups, overlays, dialogs, modal windows, alert boxes, or confirmation dialogs in .NET MAUI applications. Covers positioning (center, absolute, relative to view), layout customization (header, footer, content templates), animations, and modal behavior.
- ▌ Identity Locked Density Reset Recap Hero · gabrielmoreira bundleCreate original short videos using the 时尚密度复位|身份锁定、拼贴回顾与英雄主标 Creative DNA for MiniMax H3 or Seedance 2.0. Use when the user wants identity-locked style modules, a deliberate density reset, a recap collage, and a final hero lockup with new subjects and surfaces.
- ▌ Create Adr · gabrielmoreiraCreates Architecture Decision Records (ADRs) to document significant architectural choices and their rationale for future team members. Use when the user says "write an ADR", "document this decision", "record why we chose X", "add an architecture decision record", "create an ADR for", or wants to capture the reasoning behind a technical choice so the team understands it later. Do NOT use when the decision hasn't been made yet (use create-rfc instead), for implementation planning (use technical-design-doc-creator), or for general documentation.
- ▌ Create Rfc · gabrielmoreiraCreates structured Request for Comments (RFC) documents for proposing and deciding on significant changes. Use when the user says "write an RFC", "create a proposal", "I need to propose a change", "draft an RFC", "document a decision", or needs stakeholder alignment before making a major technical or process decision. Do NOT use for TDDs/implementation docs (use technical-design-doc-creator instead), README files, or general documentation.
- ▌ Positioning Icp · gabrielmoreiraWhen the user wants to define their ideal customer profile, position an AI product, build messaging architecture, or validate product-market fit. Also use when the user mentions 'ICP,' 'ideal customer profile,' 'positioning,' 'PMF,' 'product-market fit,' 'messaging,' 'buyer persona,' 'enrichment signals,' 'market positioning,' or 'competitive positioning.' This skill covers market positioning, ICP definition, messaging architecture, and PMF validation for AI-native products. Do NOT use for technical implementation, code review, or software architecture.
- ▌ Test Strategy Reviewer · gabrielmoreiraReview test strategy, 测试策略评审。Use when: 测试策略写完后,需要审查风险覆盖、独立测试分层、阶段化执行规则、环境策略与入口/出口标准是否成立。
- ▌ Excalidraw MCP Diagramming · gabrielmoreiraCreate and edit diagrams on a live Excalidraw canvas using the Excalidraw MCP server. Use when asked to draw, diagram, sketch, or visualise architectures, workflows, data flows, system designs, flowcharts, mind maps, or sequence diagrams. Trigger phrases include "create an excalidraw", "draw me a diagram", "make a flowchart", "visualise the system", "diagram this architecture", "export to PNG/SVG". Can export to PNG, SVG, .excalidraw file, or a shareable URL. Do NOT use for Draw.io or diagrams.net output (use drawio-mcp-diagramming instead).
- ▌ Terraform Provider Upgrade · gabrielmoreiraSafe Terraform provider upgrades with automatic resource migration, breaking change detection, and state management using moved blocks. Use when upgrading provider versions, handling removed resources, migrating deprecated syntax, or performing major version upgrades.
- ▌ Agentic Actions Auditor · gabrielmoreiraAudits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct expression injection, dangerous sandbox configurations, and wildcard user allowlists. Use when reviewing workflow files that invoke AI coding agents, auditing CI/CD pipeline security for prompt injection risks, or evaluating agentic action configurations.
- ▌ Secure Workflow Guide · gabrielmoreiraGuides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas. Use when securing a smart contract end to end rather than hunting one bug, checking a project on every check-in or before deployment, triaging a Slither report, or asking where to start on smart contract security.
- ▌ Spec To Code Compliance · gabrielmoreiraCheck code against the documentation that specifies it - which requirements hold, which the code contradicts, which are absent, and what the code does that no document mentions. Use when comparing an implementation against a whitepaper, protocol spec, or design document.
- ▌ Linkedin Account Research · gabrielmoreira bundleWhen a seller, SDR, or founder wants a B2B account brief built from a company's public LinkedIn presence — its page, posts, open jobs, employees, and visible profiles. Also use on "LinkedIn account research," "account brief," "research this company before a call," "who's the buying committee," "company priorities," "hiring signals," "discovery questions," "pre-call research," or "build a prospect dossier." Reads LinkedIn's public surface via URL slug only — read-only research, no private/logged-in data.
- ▌ Research Arxiv Scout · gabrielmoreiraDiscovers and triages recent arXiv papers for AI/ML, agents, and software/QA. Use when scouting categories, arXiv IDs, or source lists.
- ▌ Software Code Review · gabrielmoreiraApplies systematic code review patterns and checklists. Use when reviewing PRs or diffs for correctness, security, readability, maintainability, and AI-generated changes.
- ▌ Software Crypto Web3 · gabrielmoreiraGuides secure blockchain development across EVM, Bitcoin, Solana, Cosmos, and TON. Use when building contracts, wallets, custody flows, bridges, or on-chain backends.
- ▌ Software UX Research · gabrielmoreiraGuides user research methods and research ops. Use when running interviews, usability tests, surveys, or A/B tests to de-risk product decisions.
- ▌ Openviking Context Database · gabrielmoreiraUse OpenViking from OpenClaw through @openviking/openclaw-plugin: long-term memory, session archives, resource and Agent Skill import, semantic recall, recall trace debugging, and externalized tool-result recovery. Prefer this skill when the user wants to use, query, debug, or operate OpenViking context from an OpenClaw agent. For first-time plugin installation, use the install-openviking-memory skill instead.
- ▌ Comm Lit Review · gabrielmoreira bundleCommunications-domain literature review with Claude-style knowledge-base-first retrieval. Use when the task is about communications, wireless, networking, satellite/NTN, Wi-Fi, cellular, transport protocols, congestion control, routing, scheduling, MAC/PHY, rate adaptation, channel estimation, beamforming, or communication-system research and the user wants papers, related work, a survey, or a landscape summary.
- ▌ Wb Preview Url Modifier · gabrielmoreiraCovers the PreviewUrlModifier extension point in Website Builder. Use when a user wants to inject custom query parameters into live preview URLs — e.g. signed tokens, tenant identifiers, feature flags — from their Webiny project. Handles the full registration pattern: implementing the interface, wiring via createFeature + RegisterFeature, and registering via webiny.config.tsx. Supports async modifier methods (e.g. remote token fetch).
- ▌ Creating Agent Skill · gabrielmoreiraCreate and review Agent Skills that follow the open Agent Skills specification and best practices. Use when a user asks to create a new skill, build skill instructions, generate a SKILL.md file, review an existing skill for compliance, or improve skill quality. Covers skill structure, naming conventions, progressive disclosure, writing effective descriptions, creating actions and standards, and validation.
- ▌ React State Management · gabrielmoreiraMaster modern React state management with Redux Toolkit, Zustand, Jotai, and React Query. Use when setting up global state, managing server state, or choosing between state management solutions.
- ▌ Python Performance Optimization · gabrielmoreiraProfile and optimize Python code using cProfile, memory profilers, and performance best practices. Use when debugging slow Python code, optimizing bottlenecks, or improving application performance.
- ▌ Team Composition Analysis · gabrielmoreiraDesign optimal team structures, hiring plans, compensation strategies, and equity allocation for early-stage startups from pre-seed through Series A. Use this skill when planning headcount, determining which roles to hire next, setting compensation or equity ranges, designing org structure, or building a hiring budget aligned to funding milestones.
- ▌ Competition Queue Worker Drift · gabrielmoreiraInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for queues, async workers, cron jobs, delayed tasks, retry behavior, worker-only config drift, and payload-to-side-effect chains. Use when the user asks to trace a queue payload, inspect async job execution, explain worker-only behavior, follow retries or dead-letter handling, or connect an enqueued item to a later file, cache, email, or privilege-bearing side effect. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- ▌ Narrative Resonance Monitor · gabrielmoreiraUse when the user asks to "measure how our narrative is landing", "track echo rate against our canon lexicon", or "check how AI answer engines describe our brand"; produces a resonance report — echo rate (overlap of market language with the narrative-registry canon lexicon, method declared), AI-answer perception via tavily.py --answer (proxy-labeled), share-of-voice on a locked competitor panel (reusing share-of-voice-tracker), and resonance signals from bluesky.py / gdelt.py / pageviews.py — every number labeled Measured / proxy / User-provided, feeding the TALE E dimension and the upstream of the E1 evidence-integrity veto. Not for rebuilding share-of-voice machinery — use share-of-voice-tracker; not for own-site GA4/GSC analytics — use performance-monitor; not for scoring TALE profile result — use narrative-quality-auditor; not for adjudicating claims — use offer-claims-registry. 回声率/AI回答感知/份额之声/共鸣信号
- ▌ Hive Terminal Tools Troubleshooting · gabrielmoreiraRead when a terminal-tools call returned something surprising — empty stdout despite no error, exit_code is null, output_handle came back expired, "too many jobs" / "session busy" / "too many PTYs", warning was set unexpectedly, semantic_status disagrees with exit_code. Diagnostic recipes only — load on demand. Don't preload; the foundational skill covers the happy path.
- ▌ Agui Dotnet Reasoning · gabrielmoreiraSurface a reasoning/thinking model's intermediate thoughts separately from its final answer with the AG-UI .NET SDK — so a client can show the agent "thinking" before it responds, and handle that reasoning trace correctly across turns. USE FOR: distinguishing the model's reasoning trace from its answer on the client by matching TextReasoningContent vs TextContent in each ChatResponseUpdate's Contents; rendering thinking and answer in different ways as they stream; deciding whether to carry the reasoning text into later turns (whether to append/resend the model's reasoning back into conversation history). DO NOT USE FOR: plain text streaming with no reasoning display (use agui-dotnet-streaming-chat); tools, shared state, interrupts, multimodal, generative UI, or protobuf.
- ▌ Abstract Trimmer · gabrielmoreiraPrecision editing tool that reduces abstract word count through intelligent compression techniques, maintaining scientific rigor while meeting strict journal and conference requirements.
- ▌ Patent Assistant · gabrielmoreiraAssists R&D teams with patent technical disclosure drafting and patent/novelty search analysis; use when users ask to write a patent disclosure, structure an invention description, search related patents, or assess novelty.
- ▌ Biopython Alignment · gabrielmoreiraSequence alignment and alignment file processing with Biopython (Bio.Align/Bio.AlignIO), triggered when you need global/local pairwise alignment, MSA read/write/format conversion, or alignment statistics/filtering.
- ▌ Biopython Structure · gabrielmoreiraUse Bio.PDB to parse and analyze protein structures (PDB/mmCIF) for structural bioinformatics tasks; use when you need structure parsing, geometry calculations, or structural comparison/superposition.
- ▌ Data Stats Analysis · gabrielmoreiraPerform statistical tests, hypothesis testing, correlation analysis, and multiple testing corrections using scipy and statsmodels. Works with ANY LLM provider (GPT, Gemini, Claude, etc.).
- ▌ Volcano Plot Script · gabrielmoreiraGenerate R/Python code for volcano plots from DEG (Differentially Expressed Genes) analysis results. Triggered when user needs visualization of gene expression data, p-value vs fold-change scatter plots, publication-ready figures for bioinformatics analysis.
- ▌ Acronym Unpacker · gabrielmoreiraIntelligent medical abbreviation disambiguation tool that resolves ambiguous acronyms using clinical context, specialty-specific knowledge, and document-level semantic analysis.
- ▌ Biopython Entrez · gabrielmoreiraUse Bio.Entrez to access NCBI databases (e.g., PubMed/GenBank) for searching, fetching summaries, and downloading records when your workflow needs to call the NCBI E-utilities API over the network.
- ▌ Patent Landscape · gabrielmoreiraUse when analyzing biotech patent landscapes, identifying white spaces in pharmaceutical IP, tracking competitor patents, or assessing freedom to operate for drug development. Provides comprehensive patent analysis and strategic insights for life sciences innovation.
- ▌ Reference Finder · gabrielmoreiraAutomatically finds and ranks PubMed references for each sentence in scientific text; use when you need titles, DOIs, and brief recommendation reasons from the PubMed E-utilities API.
- ▌ Reference Search · gabrielmoreiraMulti-database literature search and search-strategy design that outputs structured, reproducible result lists; use when you need reference retrieval, systematic searching, review topic selection, or to construct a traceable search strategy.
- ▌ Sample Size Basic · gabrielmoreiraBasic sample size estimator for clinical research planning. Computes per-group and total N for two-sample/paired t-tests, chi-square tests, and proportion comparisons, reporting alpha, power, effect size, and statistical assumptions summary for grant proposals and preliminary ...
- ▌ Calling MCP Tools Via Subprocess · gabrielmoreiraBypasses a flaky MCP broker by spawning the server directly.
- ▌ Tres Report Advisor · gabrielmoreiraRecommend the right TRES Finance report for any user question. Trigger this skill whenever a user asks which report to use, what report contains certain data, how to get specific information out of TRES, or compares two reports. Also trigger when the user describes a goal (e.g. "month-end close", "auditor needs proof", "tax filing", "reconciliation") without naming a specific report. Trigger phrases include "which report", "what report", "how do I export", "where can I find", "I need a report for", "what's the difference between", "best report for", "auditor asked for", or any question about getting data out of TRES Finance.
- ▌ Tres Wallets Upload · gabrielmoreiraUpload and onboard multiple on-chain wallets or exchange accounts into Tres Finance. Use this skill whenever the user wants to add wallets, onboard wallets, import wallets, upload wallet addresses, ingest wallets, or connect exchanges into Tres — whether from a file (CSV/Excel) or by typing them manually. This skill guides Claude through the full flow: wallet type selection → input collection → validation → preview with editable HTML table → exchange credential collection (if exchange) → user confirmation → batch creation via the TRES MCP API. Always trigger this skill for wallet onboarding, wallet data ingestion, or any request to "add wallets to Tres".