gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Clay Cost Tuning · gabrielmoreiraOptimize Clay credit spending with provider key management, waterfall tuning, and budget controls. Use when analyzing Clay costs, reducing credit consumption, or implementing spending alerts and caps. Trigger with phrases like "clay cost", "clay billing", "reduce clay costs", "clay pricing", "clay expensive", "clay budget", "clay credits".
- ▌ Clay Hello World · gabrielmoreiraSend your first record to Clay and get enriched data back. Use when starting a new Clay integration, testing webhook setup, or verifying that enrichment columns are working. Trigger with phrases like "clay hello world", "clay example", "clay quick start", "first clay enrichment", "test clay webhook".
- ▌ Clay Rate Limits · gabrielmoreiraHandle Clay rate limits, webhook throttling, and credit pacing strategies. Use when hitting 429 errors, managing webhook submission rates, or optimizing throughput within Clay's plan limits. Trigger with phrases like "clay rate limit", "clay throttling", "clay 429", "clay slow", "clay records per hour".
- ▌ Compliance Audit · gabrielmoreiraPerforms regulatory gap analysis across 7 compliance frameworks with a scored report card and prioritized remediation roadmap. Use when assessing a website or application for GDPR, CCPA, ADA, PCI-DSS, CAN-SPAM, COPPA, or SOC 2 compliance. Trigger with "/compliance-audit" or "audit my website for regulatory compliance".
- ▌ Contract Compare · gabrielmoreiraCompares two contract versions side-by-side to detect added, removed, and modified clauses with favorability analysis. Use when a user receives a revised contract or redline and needs to understand what changed and who each change favors. Trigger with "/contract-compare" or "compare these two contracts".
- ▌ Exa Debug Bundle · gabrielmoreiraCollect Exa debug evidence for support tickets and troubleshooting. Use when encountering persistent issues, preparing support tickets, or collecting diagnostic information for Exa problems. Trigger with phrases like "exa debug", "exa support bundle", "collect exa logs", "exa diagnostic".
- ▌ Exa Install Auth · gabrielmoreiraInstall the exa-js SDK and configure API key authentication. Use when setting up a new Exa integration, configuring API keys, or initializing Exa in a Node.js/Python project. Trigger with phrases like "install exa", "setup exa", "exa auth", "configure exa API key", "exa-js".
- ▌ Exa Sdk Patterns · gabrielmoreiraApply production-ready exa-js SDK patterns with type safety, singletons, and wrappers. Use when implementing Exa integrations, refactoring SDK usage, or establishing team coding standards for Exa. Trigger with phrases like "exa SDK patterns", "exa best practices", "exa code patterns", "idiomatic exa", "exa wrapper".
- ▌ Executive Digest · gabrielmoreiraGenerate the daily executive digest — a single WhatsApp summary of everything needing attention: stalled scheduling, pending intros, unanswered emails, promised follow-ups, open Todoist tasks, and upcoming calendar events. Use when running the daily digest cron, or when user asks for a status digest, daily summary, "what's pending", or "catch me up".
- ▌ Figma Load Scale · gabrielmoreira bundleLoad test Figma API integrations and plan for scale. Use when benchmarking API throughput, testing rate limit behavior, or planning capacity for high-volume Figma integrations. Trigger with phrases like "figma load test", "figma scale", "figma benchmark", "figma capacity", "figma throughput".
- ▌ Ga4 Realtime API · gabrielmoreiraPull current-session / active-user data from the GA4 Realtime endpoint — a separate API surface from runReport with different metrics, dimensions, and freshness guarantees (~30 min rolling window instead of T-48h). Trigger with "GA4 realtime", "active users right now", "GA4 current sessions", "who's on my site now".
- ▌ Groq Cost Tuning · gabrielmoreira bundleOptimize Groq costs through model routing, token management, and usage monitoring. Use when analyzing Groq billing, reducing API costs, or implementing usage monitoring and budget alerts. Trigger with phrases like "groq cost", "groq billing", "reduce groq costs", "groq pricing", "groq expensive", "groq budget".
- ▌ Groq Hello World · gabrielmoreira bundleCreate a minimal working Groq chat completion example. Use when starting a new Groq integration, testing your setup after installing the SDK, or learning the basic Groq API request/response pattern before building something larger. Trigger with phrases like "groq hello world", "groq example", "groq quick start", "simple groq code".
- ▌ Groq Rate Limits · gabrielmoreira bundleImplement Groq rate limit handling with backoff, queuing, and header parsing. Use when handling rate limit errors, implementing retry logic, or optimizing API request throughput for Groq. Trigger with phrases like "groq rate limit", "groq throttling", "groq 429", "groq retry", "groq backoff".
- ▌ Hex Debug Bundle · gabrielmoreiraCollect Hex debug evidence for support tickets and troubleshooting. Use when encountering persistent issues, preparing support tickets, or collecting diagnostic information for Hex problems. Trigger with phrases like "hex debug", "hex support bundle", "collect hex logs", "hex diagnostic".
- ▌ Hex Install Auth · gabrielmoreiraInstall and configure Hex SDK/CLI authentication. Use when setting up a new Hex integration, configuring API keys, or initializing Hex in your project. Trigger with phrases like "install hex", "setup hex", "hex auth", "configure hex API key".
- ▌ Hex Sdk Patterns · gabrielmoreiraApply production-ready Hex SDK patterns for TypeScript and Python. Use when implementing Hex integrations, refactoring SDK usage, or establishing team coding standards for Hex. Trigger with phrases like "hex SDK patterns", "hex best practices", "hex code patterns", "idiomatic hex".
- ▌ Miro Cost Tuning · gabrielmoreiraOptimize Miro API costs through credit monitoring, request reduction, and plan selection based on the credit-based rate limiting model. Trigger with phrases like "miro cost", "miro billing", "reduce miro costs", "miro pricing", "miro credits usage".
- ▌ Miro Hello World · gabrielmoreiraCreate a minimal working Miro example with real board and item operations. Use when starting a new Miro integration, testing your setup, or learning the Miro REST API v2 item model. Trigger with phrases like "miro hello world", "miro example", "miro quick start", "first miro board", "create miro sticky note".
- ▌ Plugin Validator · gabrielmoreira bundleValidate automatically validates AI assistant code plugin structure, schemas, and compliance when user mentions validate plugin, check plugin, or plugin errors. runs comprehensive validation specific to AI assistant-code-plugins repository standards. Use when validating configurations or code. Trigger with phrases like 'validate', 'check', or 'verify'.
- ▌ Ramp Cost Tuning · gabrielmoreiraRamp cost tuning — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp cost tuning", "ramp-cost-tuning", "corporate card API".
- ▌ Ramp Hello World · gabrielmoreiraRamp hello world — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp hello world", "ramp-hello-world", "corporate card API".
- ▌ Ramp Rate Limits · gabrielmoreiraRamp rate limits — corporate card and expense management API integration. Use when working with Ramp for card management, expenses, or accounting sync. Trigger with phrases like "ramp rate limits", "ramp-rate-limits", "corporate card API".
- ▌ Validate Skillmd · gabrielmoreira bundleValidate a SKILL.md file against the four-tier validation system: Tier 0 (locate), Tier 1 (standard or marketplace grading per the IS 100-point rubric), Tier 2 (static production gate — allowed-tools accuracy, auth protocol, dead code, tool safety, orchestration bounds), and Tier 3 (JRig 7-layer behavioral eval, opt-in via --thorough). Use when creating a new skill, checking skill quality, preparing for marketplace submission, running deep quality analysis, or gating a skill for production. Trigger with "validate this skill", "grade my skill", "deep eval", "check SKILL.md", "validate thorough", "/validate-skillmd".
- ▌ Validator Expert · gabrielmoreira bundleValidate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices. Generates weighted scores (0-100%) with actionable remediation plans. Use when asked to validate a deployment, run a production readiness check, audit security posture, or verify compliance for Vertex AI agents. Trigger with "validate deployment", "production readiness", "security audit", "compliance check", "is this agent ready for prod", "check my ADK agent", "review before deploy", or "production readiness check". Make sure to use this skill whenever validating ADK agents for Agent Engine.
- ▌ Plan Putaway · gabrielmoreira bundlePlan putaway from received goods, storage requirements, location rules, capacity, priorities, and exceptions.
- ▌ Creator Owned Product Launch Plan · gabrielmoreira bundlePlan creator-owned product launches. Use when Codex is asked to launch a creator digital product, course, merch drop, paid community, membership, bundle, preorder, waitlist, offer page, content sequence, email sequence, fulfillment plan, support plan, or product launch calendar.
- ▌ Product Analytics Instrumentation · gabrielmoreira bundleDesign, audit, and improve product analytics instrumentation, event taxonomy, telemetry schemas, funnels, activation metrics, retention metrics, tracking plans, observability events, QA, and data quality. Use when Codex is asked about product analytics events, app/game telemetry, funnel instrumentation, analytics implementation, event naming, properties, user identity, or measurement-ready product design.
- ▌ Eeat Content Quality Audit · gabrielmoreiraSystematic content quality audit based on 80 CORE-EEAT standards, evaluating content's GEO (Generative Engine Optimization) and SEO (Search Engine Optimization) potential. Features 8-dimension scoring, weighted total calculation, veto item detection, and priority improvement recommendations. Applicable for pre-publication checks, competitive analysis, and AI citation potential assessment.
- ▌ Dpdata Minimizer · gabrielmoreiraMinimize geometries with dpdata minimizer plugins via System.minimize(), including how minimizers relate to drivers (ASEMinimizer needs a dpdata Driver) and how to list supported minimizers (ase/sqm). Use when doing geometry optimization/minimization through dpdata Python API.
- ▌ Contributing To Awesome Claude · gabrielmoreiraUse when writing, testing, or preparing ANY contribution or pull request to the JSONbored/awesome-claude (HeyClaude) repo — adding a community content entry (agent/MCP server/skill/hook/command/rule/guide/collection/statusline), or making a platform/code change (website, registry package, MCP package, scripts). The repo has two separate review paths: a private, one-shot "HeyClaude submission gate" that decides single-file content PRs, and the shared gittensory-orb bot that posts an advisory readiness/linked-issue comment on platform/code PRs but does not itself merge or close content PRs. Unlike JSONbored/gittensory and JSONbored/metagraphed, a linked issue is OPTIONAL here — do not import their mandatory-linked-issue rule into this repo. Invoke for any "contribute to / open a PR against / submit an entry to / fix a bug in awesome-claude (HeyClaude)" task.
- ▌ Contributor Pipeline Gardening · gabrielmoreiraMaintenance of the contributor issue pipeline for JSONbored/awesome-claude (HeyClaude) — closing issues that are already done but not marked so, and keeping a small, high-value contributor-available backlog stocked with real website/content/feature/bugfix work. Runs every ~24h via a dedicated scheduled task. Invoke for "run the issue gardening", "audit open issues for stale/complete ones", "generate new contributor issues", or any recurring/scheduled run of this process. `reference.md` (next to this file) has the exhaustive label/milestone/ template detail — read it before doing real work, not just this file. This is the awesome-claude-specific instance; JSONbored/loopover and JSONbored/metagraphed each have their own separate copy with different conventions and a much larger backlog target — do not cross-apply either repo's specifics to this one without being asked.
- ▌ Interactive Fiction · gabrielmoreiraDiagnose branching narrative problems. Use when choices feel meaningless, when branching is unmanageable, when player agency conflicts with authored story, or when interactive elements break narrative flow.
- ▌ Positional Revelation · gabrielmoreiraGenerate stories where ordinary people become crucial through their structural position in systems. Use when you want protagonists who aren't chosen ones but accidental pivots, when mundane jobs should reveal conspiracies, or when you need structurally inevitable involvement rather than coincidence.
- ▌ Settlement Design · gabrielmoreiraDesign cities, towns, and settlements for fictional worlds. Use when creating urban environments, mapping city districts, or when settlements need realistic layered development and spatial logic.
- ▌ Godot Best Practices · gabrielmoreira bundleGuide AI agents through Godot 4.x GDScript coding best practices including scene organization, signals, resources, state machines, and performance optimization. This skill should be used when generating GDScript code, creating Godot scenes, designing game architecture, implementing state machines, object pooling, save/load systems, or when the user asks about Godot patterns, node structure, or GDScript standards. Keywords: godot, gdscript, game development, signals, resources, scenes, nodes, state machine, object pooling, save system, autoload, export, type hints.
- ▌ Kayba Stage 7 Fixer · gabrielmoreiraImplement the approved fixes from the action plan and log all changes. Trigger when the user says "run stage 7", "implement fixes", "apply action plan", or when invoked by the kayba-pipeline orchestrator. Requires eval/action_plan.md to exist.
- ▌ Archeologue Gallica · gabrielmoreira bundleArchéologie des sources juridiques anciennes via Gallica (BNF, API stables, sans clé) : débats parlementaires du JO depuis 1871 (genèse des lois de la IIIe République), notes d'arrêt et doctrine d'origine dans les recueils Sirey et Dalloz, Bulletins civil et criminel anciens, Recueil Lebon, JO Lois et décrets 1881-2015, thèses et traités du XIXe-début XXe, Gazette des tribunaux, Bulletin de l'Inspection du travail. Déclencher dès que l'utilisateur cherche l'origine historique d'un texte, d'un concept ou d'une jurisprudence : « débats de la loi de 1884 », « note de Josserand », « que disait la doctrine en 1900 », « première apparition de la notion de… », « généalogie / histoire de l'article… », « arrêt ancien », « thèse d'avant-guerre », « Gallica », « BNF », ou toute recherche juridique antérieure aux bases modernes (Légifrance ne remonte pas avant l'époque contemporaine, Judilibre non plus). Déclencher aussi en COMPLÉMENT de travaux-preparatoires quand la loi étudiée est antérieure à 1958.
- ▌ Incident Reporting Navigator · gabrielmoreira bundleUse when a security incident, data breach, or actively exploited vulnerability raises the question "who must we notify, where, and by when?" Screens one incident across the EU reporting regimes — NIS2, GDPR, DORA, and the Cyber Resilience Act — determines which duties fire for each involved entity's roles, resolves the receiving authority per regime and member state from served national law, and produces a deadline table in which every duty, authority, and deadline is cited from official publisher text fetched live through the Ansvar Gateway MCP connector. Never answers from model memory.
- ▌ Risk And Issues Manager Scott Margetts · gabrielmoreira bundleRAID log methodology with decision extraction from emails and meeting notes. Use when asked to identify risks, log assumptions, track issues, extract decisions from correspondence, create or update a RAID log, escalate a risk to an issue, assess project risks, validate or challenge assumptions, or capture scope-relevant decisions. Also triggers when the user pastes email chains and asks what decisions were made, or needs to find buried decisions and untested assumptions in correspondence. Trigger on: 'risk report', 'RAID log', 'what are the risks', 'what decisions were made', 'update the risk register', 'what assumptions are we making', 'what could go wrong', 'flag any issues', 'extract decisions from these emails'.
- ▌ Scope Change Controller Scott Margetts · gabrielmoreira bundleScope management for legal matters — baseline capture, in-flight change control, OOS documentation, and scope retrospective. Use when asked to review scoping assumptions, assess whether work is in or out of scope, draft a scope change notice, track scope changes, prepare an OOS justification, run an OOS report, prepare a scope call agenda, or review what changed on a matter. Trigger on: 'scope change', 'out of scope', 'OOS', 'scope creep', 'is this in scope', 'the client wants us to also', 'additional work', 'scope review', 'what changed from the original scope', 'we need to revisit the quote', 'the budget assumed', 'OOS report', 'scope call with the client', 'run a scope report'.
- ▌ Tech Contract Negotiation Patrick Munro · gabrielmoreira bundleSystematic contract negotiation strategies for technology services agreements with German/EU law specificity. Provides three-position framework (provider-favorable, balanced, client-favorable), deal-size calibration (€100K to €10M+), five-tier objection handling with regulatory leverage (GDPR, DORA, NIS2, BGB), concession packaging, and position matrices for liability, IP, payment, SLA, data protection, and termination. Use when: (1) Developing negotiation strategies for SaaS, cloud, or managed services agreements, (2) Preparing position papers and fallback positions, (3) Responding to counterparty objections, (4) Structuring concession packages that protect core economics, (5) Calibrating tactics to deal size and leverage, or (6) Applying German contract law constraints (BGB §§ 305-310 AGB, § 309 Nr. 7 liability limits, § 288 statutory interest).
- ▌ Mariadb Operator Pr Review · gabrielmoreiraPerform a structured maintainer-style PR review for the mariadb-operator repository. Gathers PR context, triages the change, and evaluates correctness, safety, pitfalls, backwards compatibility and code quality against the project conventions documented in AGENTS.md. Use whenever the user mentions a mariadb-operator PR number or URL and wants any kind of judgment on it — "review this PR", "what do you think of #1234", "is this safe to merge", "assess this diff", "take a look at this change" — even if they don't literally say "review".
- ▌ Mcloud Deployments · gabrielmoreiraExecute mcloud deployments commands to list deployments, retrieve deployment details, and fetch build logs. Use when listing deployments, checking deployment status, or reading build output for debugging build failures.
- ▌ Using Medusa Cloud · gabrielmoreiraManages Medusa Cloud resources through the Cloud CLI (mcloud). Use when deploying, debugging deployments, managing environments, environment variables, or any Medusa Cloud operation. CRITICAL for mcloud commands, deployment failures, build logs, Cloud setup, and CI/CD workflows.
- ▌ Building With Medusa · gabrielmoreiraLoad automatically when planning, researching, or implementing ANY Medusa backend features (custom modules, API routes, workflows, data models, module links, business logic). REQUIRED for all Medusa backend work in ALL modes (planning, implementation, exploration). Contains architectural patterns, best practices, and critical rules that MCP servers don't provide.
- ▌ Engagement Reporting · gabrielmoreiraCreates source-grounded internal or external weekly engagement status reports with optional Outlook draft creation.
- ▌ Azure Cosmos DB Py · gabrielmoreiraBuild Azure Cosmos DB NoSQL services with Python/FastAPI following production-grade patterns. Use when implementing database client setup with dual auth (DefaultAzureCredential + emulator), service layer classes with CRUD operations, partition key strategies, parameterized queries, or TDD patterns for Cosmos. Triggers on phrases like "Cosmos DB", "NoSQL database", "document store", "add persistence", "database service layer", or "Python Cosmos SDK".
- ▌ Azure Eventgrid Py · gabrielmoreiraAzure Event Grid SDK for Python. Use for publishing events, handling CloudEvents, and event-driven architectures. Triggers: "event grid", "EventGridPublisherClient", "CloudEvent", "EventGridEvent", "publish events".
- ▌ Pydantic Models Py · gabrielmoreiraCreate Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants. Use when defining API request/response schemas, database models, or data validation in Python applications using Pydantic v2.
- ▌ Agency Behavioral Nudge Engine · gabrielmoreiraBehavioral psychology specialist that adapts software interaction cadences and styles to maximize user motivation and success.
- ▌ Agency Data Analytics Reporter · gabrielmoreiraExpert data analyst transforming raw data into actionable business insights. Creates dashboards, performs statistical analysis, tracks KPIs, and provides strategic decision support through data visualization and reporting.
- ▌ Agency Performance Benchmarker · gabrielmoreiraExpert performance testing and optimization specialist focused on measuring, analyzing, and improving system performance across all applications and infrastructure
- ▌ Agency Social Media Strategist · gabrielmoreiraExpert social media strategist for LinkedIn, Twitter, and professional platforms. Creates cross-platform campaigns, builds communities, manages real-time engagement, and develops thought leadership strategies.
- ▌ Agent Maintained Docs · gabrielmoreiraUse when creating new files, modifying existing files, adding new folders, or making structural changes to a codebase and you want documentation that agents (and humans) can grep/search to navigate the project.
- ▌ Brainstorming Planner · gabrielmoreiraUse when starting a complex project, task, or feature to deeply clarify requirements, identify scope boundaries, map dependencies, and structure work into phases before any coding begins.
- ▌ Expert Persona Skills · gabrielmoreiraUse when you need Claude to operate with domain expertise outside of software engineering — such as trademark law, go-to-market strategy, product management, security review, or any specialized field — and you want to write a short skill file that activates that expertise.
- ▌ Hooks And Enforcement · gabrielmoreiraUse when setting up guardrails for AI coding agents to enforce quality, security, and auditability requirements that must never be bypassed, or when configuring Claude Code lifecycle hooks in settings.json.
- ▌ Draft Sep · gabrielmoreiraResearch and draft a Specification Enhancement Proposal following the MCP SEP governance process
- ▌ Microservices Decomposition · gabrielmoreiraDesign a microservices decomposition for a monolith or new system, defining service boundaries, ownership, communication patterns, and migration plan. Use when asked to decompose a monolith, define service boundaries, design a microservices architecture, or plan a strangler-fig migration. Produces a bounded context map, service inventory table, communication pattern decisions, data ownership matrix, migration roadmap, and risk register.
- ▌ Detecting Secure Boot Bypass · gabrielmoreira bundleDetect UEFI Secure Boot bypasses and bootkits such as BlackLotus and Bootkitty by verifying Secure Boot state, checking dbx revocation currency, and hashing EFI boot binaries against known-bad sets using mokutil, efi-readvar/dbxtool, CHIPSEC, sbverify/pesign, and Windows Confirm-SecureBootUEFI. Use when auditing fleet dbx rollout after a bootkit advisory or hunting for pre-OS persistence on a suspected-compromised endpoint.
- ▌ Exploiting Adcs With Certipy · gabrielmoreira bundleUse Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials, golden certificate forgery, and PKINIT/Schannel auth. Use during authorized penetration tests to escalate a domain foothold to Domain Admin, or to validate that certificate template ACLs and CA hardening detect these attacks.
- ▌ Hunting Saas Sso Token Abuse · gabrielmoreira bundleHunts for stolen-session and OAuth/PRT token replay (T1550.001) by correlating Microsoft Entra ID SigninLogs SessionId/UniqueTokenIdentifier fields and Okta System Log sso/session events to spot impossible travel, refresh-token reuse, and token use from anomalous ASNs. Use when hunting MFA-bypass via stolen cookies/tokens, investigating impossible-travel alerts, or scoping SaaS lateral movement after phishing.
- ▌ Implementing Cloud Waf Rules · gabrielmoreira bundleDeploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive reduction. Use when deploying new apps behind a cloud WAF, when pentests reveal injection/XSS flaws, when facing bot or credential-stuffing traffic, or when compliance (e.g. PCI-DSS) mandates a WAF.
- ▌ Securing AWS Iam Permissions · gabrielmoreira bundleHardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies. Use when reducing the blast radius of compromised AWS identities, auditing overly permissive IAM policies, or setting up permission boundaries and Access Analyzer findings review across cloud accounts.
- ▌ Securing Kubernetes On Cloud · gabrielmoreira bundleHardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for AKS), RBAC scoping, image admission controls, and runtime security monitoring. Use when deploying a new managed Kubernetes cluster with security requirements or hardening an existing EKS, AKS, or GKE cluster after an audit or pentest finding.
- ▌ Redteam Crypto Detail Pack · gabrielmoreiraDomain routing and boundary guidance for authorized cryptography weakness testing, including weak algorithms, padding oracles, key management errors, insecure randomness, and hash collision risks. Use when a task belongs to the cryptography testing domain and needs scope, evidence, pivot, or exit criteria.
- ▌ Redteam Mobile Detail Pack · gabrielmoreiraDomain routing and boundary guidance for authorized mobile application security testing, including insecure storage, certificate pinning bypass, exposed components, and binary reverse engineering. Use when a task belongs to the mobile testing domain and needs scope, evidence, pivot, or exit criteria.
- ▌ Redteam Postex Detail Pack · gabrielmoreiraDomain routing and boundary guidance for authorized post-exploitation testing after initial access, including privilege escalation, persistence, lateral movement, data collection, and cleanup considerations. Use when a task belongs to the post-exploitation domain and needs scope, evidence, pivot, or exit criteria.
- ▌ Video Template Frame Electric Studio · gabrielmoreiraUse this plugin when the user wants a "Electric Studio Frame" HyperFrames motion video — Two-panel split with quote as hero — white/blue panels open from center, accent bar grows, quote reveals line by line.
- ▌ Vibe Project Builder · gabrielmoreiraBuild a standalone phone-first HTML App with an SVG icon, Xiaowan skill, Agent-callable tools, reusable connectors, real data paths, and optional SQLite, then validate, publish, and add it to the Android home screen as an independent plugin. Use when the user asks "做*工具", "创建*应用", "创建*app", "做*app", "开发*插件", "搭建*助手", "build * tool", or "create * app", and for existing projects the user wants Xiaowan to operate directly.
- ▌ Paper Section Author · gabrielmoreiraWrite one publication-style research-paper section as a bounded, citation-grounded LaTeX fragment from a writing plan, outline, citation plan, and optional figure/table context.
- ▌ Video Still Animator · gabrielmoreiraTurn a single still image (PNG/JPG) into a short MP4 with a slow Ken-Burns zoom and a silent audio track. Pure ffmpeg wrapper. Designed as the on_failure substitute for AI video-gen steps that get blocked by content moderation: when seedance refuses, this skill emits a valid replacement clip from the already-generated still so a downstream merge can still produce a complete deliverable.
- ▌ Meta Migration Assistant · gabrielmoreiraUse this meta-skill instead of answering directly when the user needs a concrete migration plan that benefits from multi-skill orchestration across migration classification, authoritative guide lookup, optional repo diff inspection, and step-by-step validation planning.
- ▌ Meta Web To PDF Briefing · gabrielmoreiraRender a topic into a distributable PDF briefing in three steps: web search → bullet summary → styled PDF. Trigger when the user asks for a PDF briefing on a single topic.
- ▌ Design System Governance · gabrielmoreiraDefine how the system evolves — contribution model, versioning, deprecation, and change management. Use when multiple teams contribute. For driving uptake use `design-system-adoption` (designer-toolkit); for design file history use `version-control-strategy` (design-ops).
- ▌ Design System Adoption · gabrielmoreiraCreate adoption strategy and enablement materials to drive design system usage. Use when the system exists but teams ignore it. For contribution and versioning rules, use `design-system-governance` (design-systems).
- ▌ Animation Principles · gabrielmoreiraApply animation principles — easing, staging, follow-through — to one specific UI motion. Use when tuning how an animation feels. For product-wide duration and easing tokens use `motion-system` (design-systems); for a full interaction spec use `micro-interaction-spec`.
- ▌ Interfaces That Feel · gabrielmoreiraApply an emotional resonance lens to a UI that is technically correct but flat, prescribing changes at the copy, motion, and interaction layer. Use when a design tests fine but lands cold. For the polish-perception argument, use `aesthetic-usability` (ui-design).
- ▌ Evaluate Pattern Adoption · gabrielmoreira bundleRun or plan this repository's pattern-adoption evidence evaluation locally with signed-in Codex agents. Use when asked to refresh stale evidence, assess stable or exploratory patterns, evaluate one or all catalog patterns, discover possible new patterns, or prepare a reviewable evidence PR without model-backed GitHub Actions or provider API keys.
- ▌ Organizing Conversations Code · gabrielmoreiraFile layout for the conversations product. Use when adding, moving, renaming, or reviewing files under products/conversations/ — especially frontend components, scenes, helpers, and tests. Conversations React components live in their own folder under products/conversations/frontend/components/, never as loose files in components/ or at the frontend root. Expand this skill as more conversations layout rules land.
- ▌ Copying Endpoints Across Projects · gabrielmoreiraCopy a PostHog endpoint (a saved HogQL/insight query exposed as an API route) to another project in the same organization, or duplicate it under a new name in the same project. Use when the user wants to duplicate an endpoint, promote an endpoint from staging to production, replicate an endpoint's query/variables/freshness config in another workspace, or clone an endpoint to iterate on it. Unlike feature flags and experiments, endpoints have NO native cross-project copy tool — this skill covers the read-then-recreate flow (endpoint-get then endpoint-create), the active-project switching it requires, name-collision checks, and the safe defaults (land unmaterialised in the target, verify with endpoint-run). Does not cover editing endpoint versions (see managing-endpoint-versions) or authoring a brand-new endpoint from scratch (see creating-an-endpoint).
- ▌ Exploring Endpoint Execution Logs · gabrielmoreiraExplore and diagnose a PostHog endpoint's execution logs — error messages, failed runs, cache misses, slow runs, or unexpected row counts during endpoint invocations. Use when the user says "my endpoint is failing", "show me the logs for endpoint X", "what error did endpoint Y produce", "why did endpoint Z return no rows", "is this endpoint hitting cache", or "check the last N runs". Focused on a single named endpoint's runtime log entries, not project-wide auditing or query performance profiling.
- ▌ Copying Flags Across Projects · gabrielmoreiraCopy a feature flag from one PostHog project to one or more target projects in the same organization. Use when the user wants to duplicate a flag, promote a flag from staging to production, sync flags across projects, or replicate a flag configuration in a different workspace. Covers cohort remapping, scheduled-change handling, encrypted payloads, and the safe defaults (disabled in target, no scheduled changes).
- ▌ Finding Deleted Feature Flags · gabrielmoreiraFind feature flags that were soft-deleted in the active project within a recent time window. Use when the user asks "what flags were deleted in the last N days", "show me recently deleted feature flags", "who deleted flag X", "audit recent flag deletions", or anything similar. Handles the non-obvious gotcha that system.feature_flags exposes the deleted boolean but does not expose a deletion timestamp — the actual deleted-at time lives in the per-flag activity log and must be cross-referenced.
- ▌ Exploring MCP Intent Clusters · gabrielmoreiraExplore PostHog MCP intent clusters — agent goals grouped by semantic similarity, with each cluster's tool distribution and error rates, plus the tool-centric pivot (capture rate per intent, discovery rate against the advertised catalog, description fit, tool overlaps). Use when the user asks "what are agents trying to do with the MCP?", "group the intents", "which goals fail most?", "what does each cluster route to?", "when agents have this intent do they find my tool?", "which tools get mixed up?", wants to recompute the clustering, or pastes an MCP analytics intent-clustering URL.
- ▌ Testing Anti Patterns · gabrielmoreiraReviews test code to identify and fix common testing anti-patterns including flaky tests, over-mocking, brittle assertions, test interdependency, and hidden test logic. Flags bad patterns, explains the specific defect, and provides corrected implementations. Use when reviewing test code, debugging intermittent or unreliable test failures, or when the user mentions flaky tests, test smells, brittle tests, test isolation issues, mock overuse, slow tests, or test maintenance problems.
- ▌ Test Patterns · gabrielmoreiraApplies proven testing patterns — Arrange-Act-Assert (AAA), Given-When-Then, Test Data Builders, Object Mother, parameterized tests, fixtures, spies, and test doubles — to help write maintainable, reliable, and readable test suites. Use when the user asks about writing unit tests, integration tests, or end-to-end tests; structuring test cases or test suites; applying TDD or BDD practices; working with mocks, stubs, spies, or fakes; improving test coverage or reducing flakiness; or needs guidance on test organization, naming conventions, or assertions in frameworks like Jest, Vitest, pytest, or similar.
- ▌ Windows Safety Guide · gabrielmoreiraOne-click deployment Skill for Windows security policies, daily security audits, behavior auditing, file baselines, logging and nightly audit task management
- ▌ Threejs Water Optics · gabrielmoreira bundleBuild production analytic and bounded water in Three.js. Use for shared multi-wave displacement and normals, bounded RGBA heightfield pool simulation, local drops, object-driven ripples, differential-area caustics, ray-traced pool/water/sphere volume optics, derivative-filtered normal bands, analytic sky reflection, side-aware Fresnel, heuristic screen refraction, Beer-Lambert absorption, and crest foam.
- ▌ Screenpipe Chats · gabrielmoreiraSearch what was said in existing screenpipe, Codex, Claude, Cursor, and Gemini CLI chats, then continue or steer one exact chat when the user explicitly asks. Use for requests about finding another agent conversation, recalling what an agent said, or sending work to one.
- ▌ Offensive Data Exfiltration · gabrielmoreiraDense methodology covering DNS exfiltration (dnscat2, iodine, dns2tcp), HTTPS tunneling (domain fronting, CDN abuse, legitimate service channels), ICMP tunneling (icmpsh, ptunnel-ng), cloud storage dead drops (S3 presigned URLs, Azure Blob SAS tokens, GCS signed URLs), email-based exfil (SMTP, EWS, draft method), steganography (image, audio, document metadata), encoding/encryption (base64 chunking, XOR, AES), covert channels (custom protocol tunneling, HTTP header encoding, timing channels), and data staging (compression, splitting, encryption). Tools: dnscat2, iodine, dns2tcp, PacketWhisper, chisel, stunnel, icmpsh, ptunnel-ng, steghide, zsteg, OpenStego. MITRE ATT&CK: T1048 (Exfiltration Over Alternative Protocol), T1041 (Exfiltration Over C2 Channel), T1567 (Exfiltration Over Web Service), T1029 (Scheduled Transfer), T1030 (Data Transfer Size Limits), T1132 (Data Encoding), T1001 (Data Obfuscation). Use when planning or executing data exfiltration during authorized red team engagements or post-exploitation
- ▌ Protein Classification Analysis · gabrielmoreiraProtein Classification Analysis - Classify protein: ChEMBL protein classification, UniProt entry, InterPro domains, and Ensembl biotypes. Use this skill for protein science tasks involving search protein classification get uniprotkb entry by accession query interpro get info biotypes. Combines 4 tools from 4 SCP server(s).
- ▌ Protein Solubility Optimization · gabrielmoreiraProtein Solubility Optimization - Optimize protein solubility: calculate properties, predict solubility, predict hydrophilicity, and suggest mutations. Use this skill for protein engineering tasks involving calculate protein sequence properties predict protein function ComputeHydrophilicity zero shot sequence prediction. Combines 4 tools from 3 SCP server(s).
- ▌ Syncfusion Maui Circular Charts · gabrielmoreira bundleImplements Syncfusion .NET MAUI Circular Charts (SfCircularChart) including pie, doughnut, and radial bar chart types. Use when implementing circular data visualization, pie charts, doughnut charts, or radial bar charts. Ideal for percentage breakdowns, category comparisons, part-to-whole relationships, or displaying proportional data in circular format.
- ▌ Syncfusion Maui Getting Started · gabrielmoreira bundleSets up and configures Syncfusion .NET MAUI components. Use when setting up, configuring, installing, or licensing Syncfusion .NET MAUI applications. Covers installation (NuGet, installers), licensing (generation, registration, errors), themes (Material, Cupertino, customization), AI service integration (Azure OpenAI, Claude, Gemini, DeepSeek, Groq), and package upgrades.
- ▌ Syncfusion Maui Markdown Viewer · gabrielmoreira bundleImplements Syncfusion .NET MAUI MarkdownViewer (SfMarkdownViewer) for rendering Markdown content with full formatting support. Use when displaying markdown files, documentation, release notes, or help content in MAUI apps. Covers markdown rendering, appearance customization, CSS styling, and content sources (string/file/URL/resource).
- ▌ Syncfusion Maui Pull To Refresh · gabrielmoreira bundleImplements the Syncfusion .NET MAUI PullToRefresh (SfPullToRefresh) control for interactive content refreshing. Use when working with pull-to-refresh, refresh controls, swipe to refresh, or updating content on pull gestures. Covers scenarios for refreshing ListView, DataGrid, or any scrollable content, customizing refresh indicators, MVVM refresh patterns, and pull-to-refresh events.
- ▌ Syncfusion Maui Smart Scheduler · gabrielmoreira bundleImplements Syncfusion .NET MAUI AI-Powered Scheduler (SfSmartScheduler). Use when implementing natural language appointment scheduling, AI-powered scheduling, resource-aware booking, or conflict detection in MAUI apps. Covers AI scheduling, natural language CRUD operations, resource booking, and appointment summarization.
- ▌ Syncfusion Maui Sunburst Charts · gabrielmoreira bundleImplements Syncfusion .NET MAUI Sunburst Chart (SfSunburstChart) for hierarchical data visualization using a radial, multi-level circular layout. Use this for sunburst charts, radial hierarchical charts, multi-level pie charts, or hierarchical data visualization with drill-down capabilities. Ideal for visualizing organizational structures, file systems, or nested categorical data.