gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Procore Cost Tuning · gabrielmoreiraProcore cost tuning — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals. Trigger with phrases like "procore cost tuning", "procore-cost-tuning".
- ▌ Procore Hello World · gabrielmoreiraProcore hello world — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals. Trigger with phrases like "procore hello world", "procore-hello-world".
- ▌ Procore Rate Limits · gabrielmoreiraProcore rate limits — construction management platform integration. Use when working with Procore API for project management, RFIs, or submittals. Trigger with phrases like "procore rate limits", "procore-rate-limits".
- ▌ Ramp CI Integration · gabrielmoreiraRamp ci integration — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp ci integration", "ramp-ci-integration", "corporate card API".
- ▌ Ramp Local Dev Loop · gabrielmoreiraRamp local dev loop — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp local dev loop", "ramp-local-dev-loop", "corporate card API".
- ▌ Ramp Prod Checklist · gabrielmoreiraRamp prod checklist — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp prod checklist", "ramp-prod-checklist", "corporate card API".
- ▌ Replit Debug Bundle · gabrielmoreiraCollect Replit diagnostic info for debugging deployments, workspace issues, and support tickets. Use when encountering persistent issues, preparing support tickets, or collecting system state for troubleshooting Replit problems. Trigger with phrases like "replit debug", "replit support bundle", "collect replit logs", "replit diagnostic", "replit troubleshoot".
- ▌ Retellai Load Scale · gabrielmoreira bundleRetell AI load scale — AI voice agent and phone call automation. Use when working with Retell AI for voice agents, phone calls, or telephony. Trigger with phrases like "retell load scale", "retellai-load-scale", "voice agent".
- ▌ Running Chaos Tests · gabrielmoreira bundleExecute chaos engineering experiments to test system resilience. Use when performing specialized testing. Trigger with phrases like "run chaos tests", "test resilience", or "inject failures".
- ▌ Running Smoke Tests · gabrielmoreira bundleExecute fast smoke tests validating critical functionality after deployment. Use when performing specialized testing. Trigger with phrases like "run smoke tests", "quick validation", or "test critical paths".
- ▌ Runway Debug Bundle · gabrielmoreiraRunway debug bundle — AI video generation and creative AI platform. Use when working with Runway for video generation, image editing, or creative AI. Trigger with phrases like "runway debug bundle", "runway-debug-bundle", "AI video generation".
- ▌ Runway Install Auth · gabrielmoreiraRunway install auth — AI video generation and creative AI platform. Use when working with Runway for video generation, image editing, or creative AI. Trigger with phrases like "runway install auth", "runway-install-auth", "AI video generation".
- ▌ Runway Sdk Patterns · gabrielmoreiraRunway sdk patterns — AI video generation and creative AI platform. Use when working with Runway for video generation, image editing, or creative AI. Trigger with phrases like "runway sdk patterns", "runway-sdk-patterns", "AI video generation".
- ▌ Sentry Debug Bundle · gabrielmoreira bundleCollect diagnostic information for Sentry troubleshooting and support tickets. Use when events are not appearing in Sentry, SDK initialization seems broken, DSN connectivity fails, source maps are not resolving, or preparing a support request. Trigger with "sentry debug info", "sentry diagnostics", "debug bundle", "sentry support ticket".
- ▌ Sentry Install Auth · gabrielmoreira bundleInstall and configure Sentry SDK authentication with DSN setup. Use when setting up Sentry error tracking, configuring DSN, or initializing Sentry in a Node.js or Python project. Trigger with "install sentry", "setup sentry", "sentry auth", "configure sentry DSN".
- ▌ Sentry Sdk Patterns · gabrielmoreira bundleBest practices for using Sentry SDK in TypeScript and Python. Use when implementing structured error context with scopes, breadcrumb strategies, beforeSend/beforeBreadcrumb filtering, custom fingerprinting, user context, or performance span creation. Trigger: "sentry best practices", "sentry patterns", "sentry sdk usage", "sentry scope", "sentry breadcrumbs", "sentry beforeSend", "sentry fingerprint".
- ▌ Serpapi Cost Tuning · gabrielmoreiraOptimize SerpApi costs by reducing credit consumption and choosing the right plan. Use when analyzing search usage, reducing monthly costs, or implementing credit-saving strategies. Trigger: "serpapi cost", "serpapi pricing", "reduce serpapi costs", "serpapi credits".
- ▌ Serpapi Hello World · gabrielmoreiraRun your first SerpApi search -- Google, Bing, or YouTube results as JSON. Use when starting with SerpApi, testing search queries, or learning the structured result format. Trigger: "serpapi hello world", "serpapi example", "serpapi first search".
- ▌ Shipwright Pipeline · gabrielmoreira bundleAutonomous app builder that converts plain-English descriptions into fully built, tested applications. Use when the user wants to build a new app, scaffold a project, generate a full-stack application, or create an app from a description. Trigger with "build me an app", "create a new app", "shipwright build", "scaffold a project", "generate an application".
- ▌ Shopify Cost Tuning · gabrielmoreira bundleOptimize Shopify app costs through plan selection, API usage monitoring, and Shopify Plus upgrade analysis. Use when analyzing API spend, choosing between Shopify plans, or reducing billable API calls. Trigger with phrases like "shopify cost", "shopify billing", "shopify pricing", "shopify Plus worth it", "shopify API usage", "reduce shopify costs".
- ▌ Shopify Hello World · gabrielmoreira bundleCreate a minimal working Shopify app that queries products via GraphQL Admin API. Use when starting a new Shopify integration, testing your setup, or learning basic Shopify API patterns. Trigger with phrases like "shopify hello world", "shopify example", "shopify quick start", "simple shopify app", "first shopify API call".
- ▌ Shopify Rate Limits · gabrielmoreira bundleHandle Shopify API rate limits for both REST (leaky bucket) and GraphQL (calculated query cost). Use when hitting 429 errors, implementing retry logic, or optimizing API request throughput. Trigger with phrases like "shopify rate limit", "shopify throttling", "shopify 429", "shopify THROTTLED", "shopify query cost", "shopify backoff".
- ▌ Speak Common Errors · gabrielmoreira bundleDiagnose and fix common Speak API errors: authentication failures, audio format issues, rate limits, and session management problems. Use when implementing common errors features, or troubleshooting Speak language learning integration issues. Trigger with phrases like "speak common errors", "speak common errors".
- ▌ Speak Data Handling · gabrielmoreira bundleHandle student audio data, assessment records, and learning progress with GDPR/COPPA compliance. Use when implementing data handling, or managing Speak language learning platform operations. Trigger with phrases like "speak data handling", "speak data handling".
- ▌ Speak Observability · gabrielmoreira bundleMonitor Speak API health, assessment latency, session metrics, and pronunciation score distributions. Use when implementing observability, or managing Speak language learning platform operations. Trigger with phrases like "speak observability", "speak observability".
- ▌ Supabase Load Scale · gabrielmoreira bundleUse when preparing a Supabase project for production load — traffic spikes, connection-limit tuning, read replicas for analytics queries, CDN caching for Storage, regional Edge Function deployment, or partitioning large tables. Covers read replicas, Supavisor connection pooling, compute-size upgrades, Storage CDN, Edge Function regions, and table partitioning. Trigger with phrases like "supabase scale", "supabase read replica", "supabase connection pooling", "supabase compute upgrade", "supabase CDN storage", "supabase edge function regions", "supabase partitioning", "supavisor", "supabase pool mode".
- ▌ Testing Mobile Apps · gabrielmoreira bundleExecute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".
- ▌ Vastai Debug Bundle · gabrielmoreiraCollect Vast.ai debug evidence for support tickets and troubleshooting. Use when encountering persistent issues, preparing support tickets, or collecting diagnostic information for Vast.ai problems. Trigger with phrases like "vastai debug", "vastai support bundle", "collect vastai logs", "vastai diagnostic".
- ▌ Vastai Install Auth · gabrielmoreiraInstall and configure Vast.ai CLI and REST API authentication. Use when setting up a new Vast.ai integration, configuring API keys, or initializing Vast.ai GPU cloud access in your project. Trigger with phrases like "install vastai", "setup vastai", "vastai auth", "configure vastai API key", "vastai gpu setup".
- ▌ Vastai Sdk Patterns · gabrielmoreiraApply production-ready Vast.ai SDK patterns for Python and REST API. Use when implementing Vast.ai integrations, refactoring SDK usage, or establishing coding standards for GPU cloud operations. Trigger with phrases like "vastai SDK patterns", "vastai best practices", "vastai code patterns", "idiomatic vastai".
- ▌ Vercel Debug Bundle · gabrielmoreira bundleCollect Vercel debug evidence for support tickets and troubleshooting. Use when encountering persistent issues, preparing support tickets, or collecting diagnostic information for Vercel problems. Trigger with phrases like "vercel debug", "vercel support bundle", "collect vercel logs", "vercel diagnostic".
- ▌ Vercel Install Auth · gabrielmoreiraInstall Vercel CLI and configure API token authentication. Use when setting up Vercel for the first time, creating access tokens, or initializing a project with vercel link. Trigger with phrases like "install vercel", "setup vercel", "vercel auth", "configure vercel token", "vercel login".
- ▌ Vercel Sdk Patterns · gabrielmoreira bundleProduction-ready Vercel REST API patterns with typed fetch wrappers and error handling. Use when integrating with the Vercel API programmatically, building deployment tools, or establishing team coding standards for Vercel API calls. Trigger with phrases like "vercel SDK patterns", "vercel API wrapper", "vercel REST API client", "vercel best practices", "idiomatic vercel API".
- ▌ Vertex Infra Expert · gabrielmoreira bundleExecute use when provisioning Vertex AI infrastructure with Terraform. Trigger with phrases like "vertex ai terraform", "deploy gemini terraform", "model garden infrastructure", "vertex ai endpoints terraform", or "vector search terraform". Provisions Model Garden models, Gemini endpoints, vector search indices, ML pipelines, and production AI services with encryption and auto-scaling.
- ▌ Webflow Cost Tuning · gabrielmoreiraOptimize Webflow costs through plan selection, CDN read optimization, bulk endpoint usage, and API usage monitoring with budget alerts. Use when analyzing Webflow billing, reducing API costs, or implementing usage monitoring for Webflow integrations. Trigger with phrases like "webflow cost", "webflow billing", "reduce webflow costs", "webflow pricing", "webflow budget".
- ▌ Reacnetgenerator · gabrielmoreiraRun ReacNetGenerator on reactive MD trajectories to generate reaction networks and reports. Use when the user wants to analyze LAMMPS dump/xyz/bond trajectories with ReacNetGenerator. Handles LAMMPS dump quirks like x/y/z vs xs/ys/zs by converting to x/y/z (orthorhombic + triclinic supported via reacnet-md-tools). Can infer atomname order from a LAMMPS data file. Runs via local reacnetgenerator if available or via `uvx --from reacnetgenerator ...`. Writes outputs into `out/<input_basename>/` with logs and a summary.
- ▌ Openbabel · gabrielmoreiraA versatile CLI tool for converting molecular file formats, generating 3D atomic coordinates from SMILES, rendering 2D chemical structure images, and preparing or extracting structures for computational workflows. USE WHEN you need to convert between chemical file formats (e.g., xyz, pdb, mol, smi, gjf), generate 3D structures from SMILES using `--gen3d`, render molecule images (PNG/SVG), or extract geometries from simulation logs to build new inputs.
- ▌ Requirements Analysis · gabrielmoreira bundleDiagnose requirements problems and guide discovery of real needs and constraints
- ▌ Dotnet Testing Bogus Fake Data · gabrielmoreira bundle使用 Bogus 產生擬真假資料的專門技能。當需要產生真實感的姓名、地址、電話、Email、公司資訊等測試資料時使用。涵蓋 Faker 類別、多語言支援、自訂規則、大量資料產生等。 Make sure to use this skill whenever the user mentions Bogus, Faker, fake data, realistic test data, generating names/addresses/emails, or seed data, even if they don't explicitly ask for fake data guidance. Keywords: bogus, faker, fake data, 假資料, 擬真資料, realistic data, fake name, fake address, fake email, Faker<T>, RuleFor, Generate, faker.Name, faker.Address, faker.Internet, 產生假資料, generate fake data, seed data
- ▌ Domain Selection · gabrielmoreiraWhen the user wants to choose an SEO-friendly domain for a new site—brand vs keyword domain, TLD selection, or domain best practices. Also use when the user mentions "domain choice," "pick domain," "SEO-friendly domain," "brand domain," "EMD," "PMD," "exact match domain," "partial match domain," "TLD," ".ai domain," ".com vs .io," "domain length," "domain history," or "defensive domain registration." For migration, use rebranding-strategy.
- ▌ Clone Ad · gabrielmoreiraClone an existing video ad for a different product or offer. Analyzes the source video's style, pacing, camera work, dialogue, and tone, then adapts and generates a new Seedance 2.0 video customized for the user's product. End-to-end workflow: input video → analysis → adapted prompt → generation → delivery. Use when someone says "clone this ad", "make this ad but for my product", "recreate this video for my brand", or provides a video ad and a product image asking for a similar video.
- ▌ Eu AI Act Classification · gabrielmoreira bundleClassify AI systems under the EU AI Act (Regulation (EU) 2024/1689) and determine compliance obligations. Use when asked to assess AI risk level, check if an AI system is prohibited, determine high-risk status, identify GPAI model obligations, map provider/deployer responsibilities, or build an AI Act compliance roadmap. Covers the full classification decision tree (Prohibited → High-Risk → Limited → Minimal → GPAI), obligations by role (provider, deployer, importer, distributor), compliance timelines, and DACH-specific considerations (German works council, BaFin, BSI, BNetzA). Triggers on phrases like "classify this AI system", "is this high-risk under the AI Act", "AI Act risk assessment", "EU AI Act compliance", "prohibited AI practice", "GPAI obligations", "AI Act timeline".
- ▌ Icelandic Contract Review · gabrielmoreira bundleUse this skill when asked to review, analyze, or draft a contract governed by Icelandic law. Triggers on requests involving Icelandic commercial agreements, consumer contracts, sales agreements, service contracts, or any contract where Icelandic mandatory rules may apply.
- ▌ Legal AI Model Router Stephane Boghossian · gabrielmoreira bundleRoutes any legal task to the right LLM, like OpenRouter but for legal work and grounded in benchmarks instead of brand loyalty. Built from mid-2026 legal evals (legalbenchmarks.ai, Vals AI × Stanford LegalBench across 124 models, Harvey's Legal Agent Benchmark, the Atticus Project's CUAD/MAUD/ACORD) plus translation evidence (WMT25, SwiLTra-Bench, ArabLegalEval). Covers five verticals: contract drafting, info extraction, legal research, contract review, and legal translation (including Arabic/MENA). Each asks up to four questions (cost, speed, accuracy/stakes, privacy/jurisdiction/language), then returns a primary model, a fallback, what to avoid, and what a human must verify. Core principle: capability is not controllability, so every route ends with a verification step. Not legal advice; a lawyer owns the output.
- ▌ Legitimate Interest · gabrielmoreira bundleGDPR Legitimate Interest Assessment (LIA) — Guided assessment for Art. 6(1)(f) GDPR using the EDPB three-step test. Based on EDPB Guidelines 1/2024, EDPB Opinion 28/2024 (AI models), the OSS Case Digest on Legitimate Interest (McIntyre 2026), CNIL AI guidance (June 2025), ICO guidance, and key CJEU case law. Use when: (1) user needs to assess whether legitimate interest is appropriate, (2) user asks about Art. 6(1)(f), "Interessenabwägung", "berechtigtes Interesse", "balancing test", or "LIA", (3) user wants to document a legitimate interest assessment, (4) user mentions the three-step test, (5) user evaluates necessity or proportionality under Art. 6(1)(f), (6) user discusses direct marketing, fraud prevention, IT security, employee monitoring, AI training, web scraping, or credit checks in context of legal basis, (7) user handles a right to object (Art. 21), (8) user asks about children's data, profiling, or cross-border data sharing under legitimate interest, (9) user compares legitimate interest against o
- ▌ Mediation Problem Generator · gabrielmoreira bundleCreate original, competition-ready commercial mediation problems and confidential packets with iterative validation. Use when a user provides a topic, industry, dispute sketch, or existing general-information packet and wants a public packet plus confidential packets for both sides—or one named side. Build a narrow but workable settlement corridor; verify factual and numerical consistency, information asymmetry, balance, originality, and commercial feasibility; and revise until deterministic and semantic exit criteria pass. Do not use merely to summarize an existing packet or to advise parties in a real dispute. Requires local file access; Python 3 is recommended for bundled deterministic checks, with disclosed manual fallbacks when unavailable.
- ▌ Mediation Problem Validator · gabrielmoreira bundleEvaluate completed mediation-competition problems consisting of general information and confidential packets for both sides. Use when asked to validate, audit, score, quality-control, or assess competition readiness; identify factual, numerical, chronological, authority, commercial-logic, or confidentiality defects; test mediation usefulness, BATNAs, settlement corridors, information asymmetry, and opportunities for firmness, cooperation, imagination, and clarification; or produce an author-only validation report. Perform a qualified partial review when packets are missing. Diagnose by default; do not generate a new problem or edit source packets unless repairs are expressly requested. Requires access to all supplied files and a host capable of reading their formats; otherwise disclose the unreviewed material and resulting limits.
- ▌ Mcq Generator · gabrielmoreira bundleAI-assisted generation of MCQs (multiple-choice questionnaires) with export to Moodle (GIFT, XML), Wooclap (Excel), Kahoot!, and Word. Supports light MCQs (gamified) and in-depth MCQs (evaluative), with single-answer and multiple-answer formats.
- ▌ Matlab Coach Debugging · gabrielmoreiraUse when tutoring a learner through MATLAB debugging, error interpretation, failed tests, incorrect outputs, array-shape problems, indexing mistakes, function argument issues, or code repair practice. Use for guided debugging sessions, debugging drills, teach-the-agent critique, and evidence-based MATLAB troubleshooting.
- ▌ Mbse Workflow · gabrielmoreiraUse this skill for guided MBSE work in MATLAB — starting a new project, resuming work mid-workflow on an existing project, or answering orientation questions about how the MBSE skills fit together. Trigger when the user says they want to create, start, or set up a new MBSE project; work on a model-based systems engineering / RFLPV project; or asks which skill covers which phase. Walks through phases one at a time — propose → approve → generate → run → confirm. Use proactively whenever someone mentions starting or continuing an MBSE project.
- ▌ Continual Learn · gabrielmoreiraPersist learning across turns by actively maintaining MENTAL_MODEL.md in the workspace. Use for iterative coding, debugging, benchmarking, or any feedback-driven task; read and update the file with actual filesystem writes before every response, never just hidden/internal memory.
- ▌ Azure AI Voicelive Py · gabrielmoreiraBuild real-time voice AI applications using Azure AI Voice Live SDK (azure-ai-voicelive). Use this skill when creating Python applications that need real-time bidirectional audio communication with Azure AI, including voice assistants, voice-enabled chatbots, real-time speech-to-speech translation, voice-driven avatars, or any WebSocket-based audio streaming with AI models. Supports Server VAD (Voice Activity Detection), turn-based conversation, function calling, MCP tools, avatar integration, and transcription.
- ▌ Azure Storage Blob Py · gabrielmoreiraAzure Blob Storage SDK for Python. Use for uploading, downloading, listing blobs, managing containers, and blob lifecycle. Triggers: "blob storage", "BlobServiceClient", "ContainerClient", "BlobClient", "upload blob", "download blob".
- ▌ Azure Storage Blob Rust · gabrielmoreiraAzure Blob Storage library for Rust. Upload, download, and manage blobs and containers. Triggers: "blob storage rust", "BlobClient rust", "upload blob rust", "download blob rust", "storage container rust", "BlobServiceClient rust".
- ▌ Fine Tuning With Trl · gabrielmoreiraFine-tune LLMs using reinforcement learning with TRL - SFT for instruction tuning, DPO for preference alignment, PPO/GRPO for reward optimization, and reward model training. Use when need RLHF, align model with preferences, or train from human feedback. Works with HuggingFace Transformers.
- ▌ Analyzing Kubernetes Audit Logs · gabrielmoreira bundleParses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules from the event patterns. Use when investigating a suspected cluster compromise, reconstructing what an attacker did through the API server, or writing Kubernetes-specific detection content. Keywords: audit policy, audit log, kube-apiserver, exec into pod, RBAC change, anonymous access, detection rules. Do not use for syscall-level detection inside a running container - use detecting-container-runtime-threats-with-falco. '
- ▌ Analyzing Linux Kernel Rootkits · gabrielmoreira bundleDetect kernel-level rootkits in Linux memory dumps using Volatility3 linux plugins (check_syscall, lsmod, hidden_modules), rkhunter system scanning, and /proc vs /sys discrepancy analysis to identify hooked syscalls, hidden kernel modules, and tampered system structures.
- ▌ Configuring Hsm For Key Storage · gabrielmoreira bundleConfigures Hardware Security Modules for cryptographic key storage using the PKCS#11 standard interface, covering key generation, signing, encryption, and key management on physical HSMs and SoftHSM2 for development. Use when protecting cryptographic keys so they never leave a hardened device boundary, or when building and testing PKCS#11-based key management workflows.
- ▌ Detecting Golden Ticket Forgery · gabrielmoreira bundleDetect Kerberos Golden Ticket forgery (e.g. Mimikatz-forged tickets) by analyzing Windows Event ID 4769 for RC4 encryption downgrades (0x17), abnormal ticket lifetimes, and krbtgt account anomalies using Splunk and Elastic SIEM queries. Use when investigating suspected forged Kerberos tickets or krbtgt credential theft in Active Directory.
- ▌ Detecting Kerberoasting Attacks · gabrielmoreira bundleDetect Kerberoasting attacks by monitoring for anomalous Kerberos TGS requests (Event ID 4769) targeting service accounts with SPNs, which attackers request offline to crack service account passwords. Use when hunting for MITRE T1558 credential access activity or investigating suspected service account password cracking attempts in Active Directory Kerberos logs.
- ▌ Detecting Pass The Hash Attacks · gabrielmoreira bundleDetect Pass-the-Hash (T1550.002) attacks by analyzing NTLM authentication patterns, flagging Type 3 logons using NTLM where Kerberos would be expected, and correlating with credential-dumping indicators. Use when threat hunting for lateral movement via stolen NTLM hashes, triaging EDR/SIEM alerts on suspicious NTLM logons, scoping compromise during incident response, or validating detection coverage in a purple team exercise.
- ▌ Detecting Service Account Abuse · gabrielmoreira bundleDetect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk, Elastic Security, Sysmon, Velociraptor) and Sigma detection rules. Use when hunting for service-account misuse or investigating a service account performing unexpected interactive logons.
- ▌ Detecting Shadow It Cloud Usage · gabrielmoreira bundleDetect unauthorized SaaS and cloud service usage (shadow IT) by parsing proxy access logs, DNS query logs, and firewall/netflow data with Python pandas to aggregate traffic by domain, classify domains against known SaaS categories, and score risk by data volume and user count. Use when auditing an organization for unsanctioned cloud/SaaS usage or generating a shadow IT discovery report with remediation recommendations.
- ▌ Detecting Stuxnet Style Attacks · gabrielmoreira bundleDetects sophisticated cyber-physical attacks that follow the Stuxnet pattern of modifying PLC logic while spoofing sensor readings to hide the manipulation, using PLC logic integrity monitoring (Claroty xDome, Nozomi Guardian) and physics-based process anomaly detection. Use when hunting for IT-to-OT lateral movement or discrepancies between PLC program state and physical process behavior in ICS/SCADA environments.
- ▌ Enumerating Cloud With Cloudfox · gabrielmoreira bundleRun CloudFox's read-only Describe/List/Get enumeration (all-checks, role-trusts, secrets, endpoints, and permissions commands) to map AWS and Azure attack paths and surface exploitable misconfigurations. Use immediately after obtaining a cloud credential to build situational awareness, find exposed resources and secrets, or map sts:AssumeRole trust relationships for lateral-movement/privilege-escalation planning.
- ▌ Exploiting Idor Vulnerabilities · gabrielmoreira bundleIdentifies and exploits Insecure Direct Object Reference (IDOR) vulnerabilities by manipulating object identifiers (numeric IDs, UUIDs, slugs) in API requests and URLs, using Burp Suite proxy history, Intruder, and the Authorize extension to test object-level authorization across sessions. Use during authorized penetration tests or bug bounty work to validate that CRUD endpoints and multi-tenant applications enforce per-object access control.
- ▌ Fleet Hunting With Velociraptor · gabrielmoreira bundleDeploy a Velociraptor server and agents, then author VQL (Velociraptor Query Language) artifacts and run them as fleet-wide hunts, on-demand forensic collections, or standalone offline collectors. Use when hunting a TTP across hundreds or thousands of endpoints, collecting forensic artifacts during incident response without re-imaging, or generating collectors for unmanaged/air-gapped hosts.
- ▌ Implementing Saml Sso With Okta · gabrielmoreira bundleImplement SAML 2.0 Single Sign-On using Okta as the Identity Provider, covering SP-initiated and IdP-initiated flows, attribute mapping, certificate management, SHA-256 signature enforcement, and Single Logout. Use when configuring Okta SAML SSO for an application, hardening SAML certificate rotation and signing, or testing and troubleshooting SAML assertion flows with a tracer tool.
- ▌ Performing Kerberoasting Attack · gabrielmoreira bundlePerform Kerberoasting, a post-exploitation technique that enumerates Active Directory service accounts with Service Principal Names (SPNs), requests their Kerberos TGS tickets, and cracks the NTLM-encrypted tickets offline to recover service account credentials. Use during authorized red team engagements or penetration tests to assess AD privilege escalation and credential access risk from weak service account passwords.
- ▌ Performing Ssl Stripping Attack · gabrielmoreira bundleSimulates SSL stripping / HTTPS downgrade attacks using sslstrip, Bettercap, and mitmproxy in authorized lab environments to test HSTS enforcement, certificate validation, and HTTPS upgrade mechanisms. Use when performing an authorized penetration test to validate HSTS preloading and TLS certificate handling, demonstrate downgrade-attack risk to stakeholders, or train SOC teams to detect SSL stripping indicators in network traffic.
- ▌ Securing Helm Chart Deployments · gabrielmoreira bundleSecures Helm chart deployments by verifying chart signatures and provenance, rendering and linting templates for misconfiguration, enforcing pod security contexts through values.yaml, moving secrets into an external store instead of Helm values, and scoping RBAC for Helm operations in CI/CD. Use when deploying charts to Kubernetes or reviewing chart provenance, templates, or release RBAC. Keywords: Helm, provenance file, helm verify, helm lint, values.yaml, Tiller-less, release RBAC, external secrets. Do not use for scanning the rendered manifests themselves - use scanning-kubernetes-manifests-with-kubesec.
- ▌ Testing For Xss Vulnerabilities · gabrielmoreira bundleTests web applications for reflected, stored, and DOM-based Cross-Site Scripting by injecting JavaScript payloads with Burp Suite (XSS extensions, Active Scan++) and browser tools, then bypassing sanitization and CSP to demonstrate session hijacking and user impersonation. Use for OWASP WSTG client-side injection testing or when evaluating input sanitization and output encoding coverage.
- ▌ Credential Setup With Computer Use · gabrielmoreiraGuides n8n credential setup through Computer Use browser tools. Use when a user needs OAuth apps, API keys, client IDs, client secrets, or other credential values from an external service console.
- ▌ Redteam Container Detail Pack · gabrielmoreiraDomain routing and boundary guidance for authorized container and orchestration security testing, including Docker escape, Kubernetes privilege escalation, image vulnerabilities, and service mesh bypasses. Use when a task belongs to the container testing domain and needs scope, evidence, pivot, or exit criteria.
- ▌ Redteam Injection Detail Pack · gabrielmoreiraDomain routing and boundary guidance for authorized general injection testing outside SQL injection, including NoSQL, LDAP, XPath, and expression language injection. Use when a task belongs to the general injection domain and needs scope, evidence, pivot, or exit criteria.
- ▌ Audiocraft Audio Generation · gabrielmoreiraAudioCraft: MusicGen text-to-music, AudioGen text-to-sound.
- ▌ Awesomewebpagemetaskill · gabrielmoreiraBuild a local multimedia webpage project from a user topic, audience, language, style, and media preferences by framing requirements, researching, planning, acquiring media, generating files, packaging, validating, repairing, and delivering usage guidance.
- ▌ Meta Security Review Bundle · gabrielmoreiraCompose three independent security gates over a candidate operation — policy/governance review, secret/credential scan, and audit-log emit — then arbitrate the verdicts with a strict priority rule (governance DENY > scanner WARN > ALLOW). Use when reviewing a proposed code change, script, or environment manipulation for safety.
- ▌ Consent And Agency · gabrielmoreiraDesigning for informed user consent, opt-out, and human override.
- ▌ Error Personality · gabrielmoreiraHow the AI communicates mistakes, uncertainty, and limitations gracefully.
- ▌ Critique Brand Consistency · gabrielmoreiraCritique a rendered screen against mood.md, voice.md, and tokens.md. Use when those brand files exist and you are checking compliance. For defining the visual language itself, use `illustration-style` (ui-design).
- ▌ Generating Clickhouse Query Performance Reports · gabrielmoreira bundleProduce and structure slow-query performance reports for PostHog's production ClickHouse (US and EU). Use when asked for a slow query report, query performance analysis over the last N days, per-team query cost, OOM or timeout investigation, cluster cost/memory regressions, or materialization candidates. Covers the modern `query_log_archive` source (typed `lc_*` columns, multi-day retention), how to categorize and attribute slow queries, root-cause patterns (unmaterialized JSONExtract, high-cardinality breakdowns, heavy joins), and the report structure. Runs queries via the `querying-production-databases-via-metabase` skill.
- ▌ Setting Up Support Slack Locally · gabrielmoreiraConnect a real Slack workspace to local PostHog Conversations (the SupportHog Slack app) so Slack messages become support tickets and replies post back. Use when the user wants to test the conversations Slack integration locally, hits "Support Slack OAuth client ID is not configured", gets a white screen or "Network error" on the OAuth callback, or asks how to set SUPPORT_SLACK_APP_CLIENT_ID / a tunnel for supporthog Slack events. Covers the Slack app + scopes, the SUPPORT_SLACK_* dynamic settings, and the key split: localhost for OAuth and the UI, a public tunnel only for inbound events.
- ▌ Consuming Endpoints From Client Code · gabrielmoreiraWire a PostHog endpoint into a client app or SDK. Covers fetching the OpenAPI spec, generating a typed client with openapi-generator or @hey-api/openapi-ts, sending the right auth header, shaping the variables payload (HogQL code_name vs insight breakdown property), handling rate-limit and materialised-endpoint error responses. Use when the user says "how do I call my endpoint", "generate a client for this", or "what auth header do I use".
- ▌ Authoring Error Tracking Alerts · gabrielmoreiraAuthor error tracking alerts that fire when an issue is created, reopened, or starts spiking. Use when the user asks to set up error notifications, route exceptions to Slack/webhook/Linear, or evaluate which error events are worth alerting on. Covers trigger-event selection, integration choice, dedup against existing alerts, and shipping with the canonical message body shape.
- ▌ Choosing Trend Or Slope View · gabrielmoreiraClarify how to visualize change over a time range before building a trend. Use whenever the user asks how much something changed, grew, dropped, improved, or regressed between two points or periods — "how much did X change from A to B", "before vs after", "start vs end", "week over week", "compare this month to last", "change over time" — or mentions a "slope chart" / "slopegraph". Two readings of "change" need different charts: the whole trend (a line, every interval) versus just the two endpoints (a slope, start vs end). Ask which they want, then render it. Not for choosing a saved insight ChartDisplayType in the insight editor.
- ▌ Exploring Autocapture Events · gabrielmoreiraGuides exploration of $autocapture events captured by posthog-js to understand user interactions, find CSS selectors (especially data-attr attributes), evaluate selector uniqueness, query matching clicks ad-hoc, and create actions. Use when the user asks about autocapture data, wants to find what users are clicking, needs to build actions from click events, asks about elements_chain, wants to build a trend or funnel filtered by clicks or other autocapture interactions, asks which properties autocapture sends, or asks how to filter $autocapture events. Only applies to projects using posthog-js autocapture.
- ▌ Preserving State Across Reloads · gabrielmoreiraUse this skill to keep Jetpack Compose state alive across HotSwan hot reloads by understanding the three escalating tiers Compose HotSwan uses (tier 1 targeted recomposition, tier 2 composition reset, tier 3 Activity.recreate) and choosing edits and state holders that stay inside tier 1 where scroll position, lazy items, dialog state, and per-composable remember values all survive. Explains which edits force escalation, which state holders survive each tier, and how to hoist transient UI state when the iteration loop must escalate. Use when the developer says "scroll jumped to top after a hot reload", "lost dialog state", "lazy column re-fetched", "tab selection reset", asks why HotSwan reload escalated to tier 2 or 3, plans a refactor and needs to know which scope it touches, or wants to know which state holders survive composition reset.
- ▌ Understanding Hot Reload Limits · gabrielmoreiraUse this skill to teach Claude exactly which Kotlin and Compose changes hot-reload under Compose HotSwan and which trigger a full incremental rebuild fallback. Root cause is Android Runtime (ART) class schema immutability; only method bodies are mutable at runtime, so any change to fields, signatures, constructors, interfaces, inline functions, or new resource ids forces a rebuild. Covers the supported-changes table, the rebuild-forcing list, the diff-then-batch workflow that keeps a hot-reload session inside the fast path, and the inline-function and new-resource-id pitfalls. Trigger when the user asks "why did this rebuild?", "why isn't this hot reloading?", wants to learn HotSwan's boundaries before adopting it, or when reviewing a refactor that risks pushing a hot-reload session into a full rebuild.
- ▌ Acquire Codebase Knowledge · gabrielmoreiraSystematically map codebase architecture, technical stack, and coding conventions by analyzing documentation and source code. Use when you need to understand or document an unfamiliar project.
- ▌ Gsd Context Health Monitor · gabrielmoreiraMonitors context complexity and triggers state dumps before quality degrades. Prevents context rot by identifying warning signs like circular debugging or confusion.
- ▌ Syncfusion Maui Linear Progressbar · gabrielmoreira bundleImplements Syncfusion .NET MAUI Linear ProgressBar (SfLinearProgressBar) control. Use when working with progress bars, progress indicators, loading indicators, determinate/indeterminate progress, or buffer progress visualization. Covers progress tracking, multi-segment progress, animated progress, and gradient progress bars.
- ▌ Direct Seedance Handdrawn Live Fusion · gabrielmoreira bundleCreate a Seedance 2.0 prompt for a rough hand-drawn luminous entity that physically contacts a live-action space, continuously transforms while remaining traceable, escapes through adjacent geography, and is followed by a slightly delayed handheld camera. Use for playful 4–15 second mixed-media clips; not for horror, polished CG, unrelated cuts, or simple visual filters.
- ▌ Direct Seedance Minimalist Product Ad · gabrielmoreira bundleTurn real product images and a verified brief into a clean Seedance 2.0 minimalist product film. Use for 4–15 second e-commerce or launch ads that require faithful product color/material/geometry, independent anchor-image roles, product-specific actions, restrained camera, readable integrated copy, sound, and a stable closing frame; not for talking-head ads or invented product features.
- ▌ Auth Tool Cloudbase · gabrielmoreira bundleCloudBase auth provider configuration and login-readiness guide. This skill should be used when users need to inspect, enable, disable, or configure auth providers, publishable-key prerequisites, login methods, SMS/email sender setup, or other provider-side readiness before implementing a client or backend auth flow.
- ▌ Data Model Creation · gabrielmoreira[Deprecated] Optional advanced tool for complex data modeling. For simple MySQL table creation, use relational-database-tool directly; for PostgreSQL / CloudBase PG schema work, use postgresql-development. New environments should use PostgreSQL DDL via queryPgDatabase/managePgDatabase — see postgresql-development skill instead.
- ▌ Guardrails Reviewer · gabrielmoreiraReview Project Guardrails, 工程规范评审。Use when: Guardrails 创建或更新后需要作为项目级治理基线做准出,检查触发判定、生成模式、事实标准、下游工作流钩子与规则可执行性。
- ▌ Azure Apim Architecture · gabrielmoreiraAnalyzes and explains Azure API Management architecture decisions for enterprise API marketplace implementations using VNet Internal mode, Front Door, hybrid authentication, and multi-environment strategies. Use when discussing APIM component selection, network topology, cost optimization, or comparing alternatives like workspaces vs instances, VNet Internal vs External mode, or Front Door vs Application Gateway.
- ▌ Guidelines Advisor · gabrielmoreiraSmart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Use when asking whether a smart contract project follows development best practices, reviewing on-chain/off-chain split, upgradeability, or delegatecall proxy patterns against guidelines, or seeking recommendations on contract design, inheritance, events, documentation, dependencies, or test strategy.
- ▌ Trigger Realtime And Frontend · gabrielmoreiraTrigger.dev client/frontend surface: subscribe to runs in realtime (runs.subscribeToRun and the @trigger.dev/react-hooks hook useRealtimeRun), consume metadata and AI/text streams in React (useRealtimeStream), trigger tasks from the browser (useTaskTrigger, useRealtimeTaskTrigger), and mint scoped frontend credentials with auth.createPublicToken / auth.createTriggerPublicToken. Load when wiring a frontend (React/Next.js/Remix) or backend-for-frontend to show live run progress, status badges, token streams, trigger buttons, or wait-token approval UIs. NOT for writing the backend task itself (streams.define / metadata.set is trigger-authoring-tasks territory); this is the consumer side.