all publishers

gabrielmoreira

@gabrielmoreira source repo

21,231 published skills · page 196 of 213

  1. ▌
    News · gabrielmoreira
    Fetch and summarize the latest news from trusted sources across politics, finance, society, world, tech, sports, and entertainment. Use when the user asks for latest news, headlines, or news in a specific category.
    17 repo stars
  2. ▌
    Short Drama Image Prompts · gabrielmoreira bundle
    为短剧人物、造型、地点、道具和状态编写或修改可直接复制的图片提示词 Markdown。用户提到角色设定图、三视图、参考图、场景板、道具图、风格帧、Look Development、状态变体或局部编辑提示词时使用;不生成图片,也不调用供应商。
    17 repo stars
  3. ▌
    Short Drama Novel Analyze · gabrielmoreira bundle
    把长篇小说、连载网文或多集散稿拆成可追溯的原著分析:章节索引、改编价值快评、逐章功能提取、剧情单元与节奏聚合、人物与设定归并,最后给出改编价值判定与分集候选,交给 $short-drama-develop 立契约。用户说“导入这本小说”“拆这本书”“分析原著”“这本书能不能改短剧”“先看看值不值得拆”“把长篇拆成分集候选”,或直接给出小说文件路径时使用。只做只读的结构化分析,不写剧本、不建资产、不生成媒体,也不替创作者决定改编方案。
    17 repo stars
  4. ▌
    Short Drama Video Prompts · gabrielmoreira bundle
    把短剧分镜和冻结关键帧写成可直接复制的视频提示词 Markdown,也可按用户要求写时间线配乐/主题曲意图。用户提到文生/图生视频动作、人物表演、运镜、口型、环境运动、镜头时长、起止状态、把分镜转成视频提示词或写配乐提示词时使用;不生成媒体、不创作歌词、不改分镜边界。
    17 repo stars
  5. ▌
    Story Long Analyze · gabrielmoreira bundle
    长篇网文拆文。深度拆解爆款长篇小说的黄金三章、人设架构、爽点设计、节奏控制。单一深度拆解管道:跑完黄金三章(Stage 1)后产出快速预览报告并询问是否继续全量拆解,确认后从 Stage 2 续跑逐章摘要、聚合分析、设定关系、汇总报告,全程产物落盘 拆文库/{书名}/。触发方式:/story-long-analyze、/长篇拆文、「帮我拆这本书」「拆这本书」「分析黄金三章」「深度拆解」「完整拆解」「系统拆解」或提供小说文本文件路径——全部进入同一管道。
    17 repo stars
  6. ▌
    Src Hunter · gabrielmoreira bundle
    实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份 HackerOne 真实 High/Critical 已披露案例、77,000+ WooYun 案例统计、国产 OA / 中间件指纹库、银行 / 电信行业垂直 playbook。当用户提到 "src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试" 或问"如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF" 时触发。
    17 repo stars
  7. ▌
    Memory To Skill · gabrielmoreira
    Turn workflows from your MemSearch memory into reusable skills. Use when the user asks to make/create/extract/distill a skill from what they just did or from past work, review skill candidates, install a distilled skill, or 'turn this into a skill'. Manages MemSearch procedural-memory candidates under .memsearch/skill-candidates/, not the host agent's own skills system.
    17 repo stars
  8. ▌
    Triage Image Cves · gabrielmoreira
    Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity. Lists the 3 most-recent published tags and lets the user pick which to scan, validates each finding is real and reachable, and proves candidate fixes in an isolated git worktree (rebuild image + re-scan + tests + container smoke-run + codebase diff) before proposing anything — fixes are NEVER auto-applied; the user decides per finding. Use when the user asks to grype-scan the image, triage container/image vulnerabilities, or check a shipped Docker image for CVEs.
    17 repo stars
  9. ▌
    Git Workflow And Versioning · gabrielmoreira
    Structures git workflow practices. Use when making any code change. Use when committing, branching, resolving conflicts, splitting uncommitted work in a messy working tree into clean atomic commits, opening or reviewing a pull request (PR), pushing to a remote, or when you need to organize work across multiple parallel streams. Use when cutting a release, choosing a semantic version bump, tagging, or writing a changelog.
    17 repo stars
  10. ▌
    Agui Dotnet Unit Tests · gabrielmoreira
    Author unit tests for the AG-UI .NET SDK (the *.UnitTests projects), following the SDK's serialization and compatibility conventions. USE FOR: adding unit-test coverage for a new type/method in AGUI.Abstractions/Formatting/Protobuf/Client/Server, event serialization round-trips, JsonDocument property-name assertions, backward-compatibility fixtures against TypeScript JSON, protobuf codec round-trips, client builder/handler tests, server ChatResponseUpdate conversion tests, SSE formatter tests. DO NOT USE FOR: HTTP pipeline / WebApplicationFactory end-to-end tests (use the agui-dotnet-integration-tests skill), cross-language TS↔C# server-parity tests (use the cross-language test skill).
    17 repo stars
  11. ▌
    Agui Dotnet Wire Types · gabrielmoreira
    Add or modify a wire/protocol type in the AG-UI .NET SDK AGUI.Abstractions package — a new event, message, or content-part type, the AOT source-gen serializer context, or a polymorphic JSON converter, keeping it AOT-safe, JSON-wire-compatible with the TypeScript reference, and PublicAPI-clean. USE FOR: adding an AG-UI event type, adding a message role or input-content type, editing AGUIJsonSerializerContext, editing BaseEventJsonConverter / AGUIMessageJsonConverter / AGUIInputContentJsonConverter, fixing PublicAPI.Unshipped analyzer build failures on protocol types, wire-format round-trip serialization. DO NOT USE FOR: writing integration/SSE tests (use agui-dotnet-integration-tests), server hosting/endpoint code, or non-Abstractions packages.
    17 repo stars
  12. ▌
    Sendmux MCP Setup · gabrielmoreira
    Configure hosted or local Sendmux MCP servers for mailbox, management, and sending tools.
    17 repo stars
  13. ▌
    Mailbox · gabrielmoreira
    Use this skill whenever the user needs ANY mailbox/email operation — checking, reading, searching, sending, replying, forwarding, organizing or deleting email, managing threads, connecting a personal mailbox, or registering a new mailbox. This skill is the single entry point for email tasks and orchestrates qwenpawmail-mcp for nine supported personal-mail domains.
    17 repo stars
  14. ▌
    Cre Closing · gabrielmoreira
    CRE Closing management suite — 2 specialist skills for closing checklist coordination and funds flow preparation for multifamily acquisitions.
    17 repo stars
  15. ▌
    Codebase Navigation · gabrielmoreira
    Use this skill when exploring an unfamiliar codebase, tracing code paths, or answering questions about how the system works. Read before writing, and build a mental model of the architecture before making changes.
    17 repo stars
  16. ▌
    PDF Processing Pro · gabrielmoreira bundle
    综合办公文员与软件开发工程师当需要批量处理PDF表单、提取表格或进行OCR识别时,使用内置脚本一键完成自动化提取与数据校验,彻底告别繁琐的手动录入,让复杂文档工作流高效、稳健落地。
    17 repo stars
  17. ▌
    Video Creation Pro · gabrielmoreira bundle
    电商运营与自媒体创作者在为美妆、家居、智能硬件等商品制作短视频时,请使用此技能。10大AI智能体协同,从卖点提炼、分镜生图到音效字幕,一键调用COZE API自动合成高质量商品视频,彻底告别本地代码依赖,轻松实现从创作、质检到数据迭代的全流程闭环。
    17 repo stars
  18. ▌
    Xiaohongshu Makeup · gabrielmoreira bundle
    自媒体创作者与电商运营在推广美妆护肤产品时,当需要创作或优化小红书笔记、生成AI配图提示词时,使用此技能可一键生成高转化爆款笔记、吸睛标题与精准标签,自动产出专业文生图提示词,轻松打造小红书爆款内容。
    17 repo stars
  19. ▌
    Safety Guardrails · gabrielmoreira bundle
    Flags risky shell commands and unsafe tree ops.
    17 repo stars
  20. ▌
    Subagent Strategy · gabrielmoreira
    Delegates research and parallel work to sub-agents.
    17 repo stars
  21. ▌
    Traceability Gate · gabrielmoreira
    Enforces parent-link lineage across requirement layers.
    17 repo stars
  22. ▌
    Tiktok Category Strategy · gabrielmoreira bundle
    Use when a user wants to evaluate, enter, position, or operate a TikTok or TikTok Shop category and needs market, product, shop, content, creator, competition, or category strategy.
    17 repo stars
  23. ▌
    Wobbling Ty Constraint Order · gabrielmoreira
    Use when a user asks to wobble ty constraint ordering, check constraint-set or TDD ordering determinism, test reversed constraint/typevar IDs, or investigate nondeterministic ty inference and mdtest results.
    17 repo stars
  24. ▌
    Fortigate Ops · gabrielmoreira
    FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and manager-vs-device drift detection. Use when asking what a FortiGate is ACTUALLY doing right now, whether a tunnel is up, or whether the device matches FortiManager's intent.
    17 repo stars
  25. ▌
    Gitlab Devops · gabrielmoreira
    GitLab DevOps operations — issues, merge requests, CI/CD pipelines, repository browsing, labels, milestones, releases, and wiki management. Use when querying GitLab project status, monitoring pipeline executions, browsing repository files, creating issues for network findings, opening merge requests for config changes, or managing project metadata.
    17 repo stars
  26. ▌
    Junos Network · gabrielmoreira
    Juniper JunOS device automation via PyEZ/NETCONF — CLI execution, configuration management, Jinja2 template rendering, device facts, batch operations, config diff and rollback comparison (10 tools). Use when managing Juniper routers, pushing JunOS configs, running show commands on Juniper devices, or comparing rollback versions
    17 repo stars
  27. ▌
    Msgraph Files · gabrielmoreira
    Read OneDrive and SharePoint files via the Microsoft 365 MCP server — list folder contents, fetch item metadata, inspect versions and sharing permissions. Use when locating a document in OneDrive/SharePoint, checking who a file is shared with, or reviewing file version history
    17 repo stars
  28. ▌
    Msgraph Visio · gabrielmoreira
    Upload and retrieve Visio (.vsdx) and other diagram files in OneDrive/SharePoint via the Microsoft 365 MCP server. Use when publishing a generated topology diagram to OneDrive, or fetching an existing .vsdx for reference
    17 repo stars
  29. ▌
    Pyats Network · gabrielmoreira
    Network device automation via pyATS - run show commands, ping, apply config, learn config/logging, list devices, run Linux commands, execute dynamic tests on Cisco IOS-XE/NX-OS devices. Use when running CLI commands on routers or switches, checking interface status, applying configuration changes, or collecting device data via pyATS.
    17 repo stars
  30. ▌
    Pyats Routing · gabrielmoreira
    CCIE-level routing protocol analysis - OSPF, BGP, EIGRP, IS-IS, static routes, RIB/FIB verification, redistribution audit, and convergence validation. Use when analyzing routing tables, debugging OSPF neighbors, checking BGP peering, verifying route redistribution, or validating convergence after changes.
    17 repo stars
  31. ▌
    Splunk Search · gabrielmoreira
    Execute and validate SPL (Search Processing Language) queries.
    17 repo stars
  32. ▌
    Telemetry Ops · gabrielmoreira
    Comprehensive network telemetry and event collection across multiple protocols.
    17 repo stars
  33. ▌
    Token Tracker · gabrielmoreira
    Track token consumption, enforce session budgets, and display cost for every NetClaw interaction.
    17 repo stars
  34. ▌
    Vault Secrets · gabrielmoreira
    Manage HashiCorp Vault KV secrets with strict value protection.
    17 repo stars
  35. ▌
    Project Onboarding · gabrielmoreira
    项目接入辅助 Skill - 提供 ProjectSetup Agent 的 schema 定义、subAgent prompt 模板和质量标记规范。 触发关键词: project-onboarding, 项目接入辅助, 接入schema, component-map
    17 repo stars
  36. ▌
    Unity Skills Index · gabrielmoreira
    Index of all Unity Skills modules with per-module mode labels (SA/FA/Mixed). Use to find which module covers a task before loading its doc.
    17 repo stars
  37. ▌
    27 Atc Ddd · gabrielmoreira bundle
    Query the WHO ATC/DDD Classification System. Use whenever the user asks about ATC codes, drug classification hierarchy, Defined Daily Doses (DDD), or wants to look up drugs by ATC class or find the ATC code for a drug name.
    17 repo stars
  38. ▌
    Ttd · gabrielmoreira bundle
    Query the Therapeutic Target Database (TTD) for drug-target-disease interaction data. Use this skill when the user asks about therapeutic targets, drugs, diseases, or their relationships — including target-drug mappings, clinical status of drugs, disease indications, UniProt/gene associations, and pathway annotations. Triggers on queries like "what drugs target EGFR", "which diseases is Imatinib used for", "find targets for lung cancer", or any lookup involving TTD IDs, gene symbols, drug names, or disease names.
    17 repo stars
  39. ▌
    Emoji Get Name · gabrielmoreira
    Returns a specific emoji by its CLDR snake_case name. The name is case-insensitive.
    17 repo stars
  40. ▌
    Emoji Get Random · gabrielmoreira
    Returns a randomly selected emoji with its full metadata.
    17 repo stars
  41. ▌
    Emoji Get Search · gabrielmoreira
    Search for emojis whose name or category contains the given query string (case-insensitive). Returns a list of all matches.
    17 repo stars
  42. ▌
    Evolve Skills · gabrielmoreira bundle
    Analyze recent project artifacts and Session Audit Reports (SA1, SA2, SA3...) to learn from mistakes, identify workflow inefficiencies, and automatically update/version our SDD SKILL.md files. Handles multiple session audits and TEMP milestones.
    17 repo stars
  43. ▌
    Generate Spec · gabrielmoreira bundle
    Transform an approved milestone document into a detailed implementation specification with strict, machine-readable requirement traceability and semantic FR IDs. Highly robust, preventing placeholder and TODO leaks.
    17 repo stars
  44. ▌
    Graph Context · gabrielmoreira bundle
    Ingest skeleton.md files into Ladybug graph for AEF projects with V1 schema (File, Symbol, IMPORTS nodes and edges).
    17 repo stars
  45. ▌
    Session Audit · gabrielmoreira bundle
    Capture any session (milestone, hotfix, manual edits, external reports) into Session Audit Reports (M{X}SA{Y}.md) that drive documentation updates, skill evolution, and quality monitoring. Use when the user says "session-audit", "document this session", "capture this session".
    17 repo stars
  46. ▌
    Excalidraw Diagram · gabrielmoreira
    Generate Excalidraw diagrams from text content. Supports three output modes - Obsidian (.md), Standard (.excalidraw), and Animated (.excalidraw with animation order). Triggers on "Excalidraw", "diagram", "standard excalidraw", "animate".
    17 repo stars
  47. ▌
    Mermaid Visualizer · gabrielmoreira
    Transform text content into professional Mermaid diagrams for presentations and documentation. Use when users ask to visualize concepts, create flowcharts, or make diagrams from text. Supports process flows, system architectures, comparisons, mindmaps, and more with built-in syntax error prevention.
    17 repo stars
  48. ▌
    Execute Plan · gabrielmoreira
    Execute an approved implementation plan exactly and safely. Use for ExecPlan-style plan execution, resumable phase checklists, multi-hour implementation work, migrations, significant refactors, and plans that require verification checkpoints, status tracking, and final reporting.
    17 repo stars
  49. ▌
    Tdd Dev Cycle · gabrielmoreira
    测试驱动开发 (TDD) 主干工作循环,包含分析、测试编写、开发、验证及带熔断的修复机制。
    17 repo stars
  50. ▌
    Oneshot Website · gabrielmoreira
    Generate immersive, one-shot single-file HTML websites with embedded CSS and JS. No external images. Hostable on CodePen or Vercel. Use for writeup showcases, AI capability demos, and portfolio pieces.
    17 repo stars
  51. ▌
    Project Learner · gabrielmoreira
    结构化交互式学习助手,当用户希望学习项目相关知识、特定代码文件或底层技术时使用此技能,它会将学习过程记录为持久化的 Markdown 日志
    17 repo stars
  52. ▌
    Long Audio To Obsidian · gabrielmoreira bundle
    将语音转写项目输出的复杂文件结构整理合并为适合 Obsidian 归档的 Markdown 文档
    17 repo stars
  53. ▌
    Hyperframes Animation · gabrielmoreira bundle
    All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus Lottie, Three.js, Anime.js, CSS keyframes, Web Animations API, TypeGPU). Use for any motion or animation task: pick 2-4 rules and compose, or load a blueprint, or look up runtime-specific API (e.g. GSAP eases / Lottie player / Three.js mixer). HyperFrames-native: single paused timeline, seek-safe, deterministic.
    17 repo stars
  54. ▌
    Consult Zai · gabrielmoreira
    Dual-AI code analysis pairing z.ai GLM 5.2 with Claude code-searcher — a lightweight two-model second opinion. Use for a quick z.ai-backed check on a code question.
    17 repo stars
  55. ▌
    Capabilities · gabrielmoreira
    Your capability catalog — read this at boot. Lists the temporal date-range skills and the external integrations (reached via the loopback broker) available to you as a spawned worker, and exactly how to call each. Read-only. Consult it whenever you're unsure what tools/integrations you have or how to invoke them.
    17 repo stars
  56. ▌
    Md Hive Sync · gabrielmoreira
    Munder Difflin hive sync — runs the start-of-task hive protocol steps: reads memory.md, checks inbox/ for new messages, and reminds you to record durable facts in memory.md and write coordination files before ending. Use when asked to "sync with the hive", "check my inbox", "hive status", or "hive sync". Proactively suggest at the start of a new task if you haven't checked your hive inbox in this conversation. (munder-difflin)
    17 repo stars
  57. ▌
    Breaking Change Recovery · gabrielmoreira
    Execute the six-phase breaking-change recovery workflow. Invoked from workflow-resilience Tier-3 escalation or manually when a merged commit breaks the runtime, schema, or governance pipeline.
    17 repo stars
  58. ▌
    Manager Ticket Lifecycle · gabrielmoreira
    The GitHub issue IS the baton. Manager creates tickets, pre-assigns roles, enforces status transitions through the Agile workflow.
    17 repo stars
  59. ▌
    Openrouter Free Failover · gabrielmoreira
    Configure and maintain optimal OpenRouter free model failover for OpenClaw. Prioritized cascade of free models ranked by coding capability, with automatic failover on rate limits, downtime, and errors. Load this skill when configuring models, troubleshooting model availability, or refreshing the free model inventory.
    17 repo stars
  60. ▌
    Role Consultant Critique · gabrielmoreira
    Perform independent post-execution critique, risk scoring, and recommendation synthesis without changing implementation scope.
    17 repo stars
  61. ▌
    Sdd Implement · gabrielmoreira
    Implement a task with automated LLM-as-Judge verification for critical steps
    17 repo stars
  62. ▌
    Uni Agent · gabrielmoreira bundle
    统一智能体协议适配层。一套 API 调用所有 Agent 协议(ANP/MCP/A2A/AITP 等)。当用户需要调用 Agent、跨协议通信、连接工具时触发此技能。
    17 repo stars
  63. ▌
    Sentry · gabrielmoreira bundle
    Inspect Sentry issues, summarize production errors, and pull health data via the Sentry API (read-only). Use when user says "check Sentry", "what errors in production?", "summarize Sentry issues", "recent crashes", or "production error report". Requires SENTRY_AUTH_TOKEN. Do NOT use for setting up Sentry SDK, configuring alerts, or non-Sentry error monitoring.
    17 repo stars
  64. ▌
    Cookie Debugging · gabrielmoreira
    Uses Chrome DevTools MCP for inspecting, debugging, and testing cookies, session state, authentication issues, and cookie consent compliance. Use when diagnosing 401/403 errors, authentication redirects, session expiration, Cookie/Set-Cookie header issues, cookie banner consent conformance, or third-party cookie/SameSite/Partitioned cookie warnings.
    17 repo stars
  65. ▌
    Optimizing Performance · gabrielmoreira
    Analyzes and optimizes application performance across frontend, backend, and database layers. Use when diagnosing slowness, improving load times, optimizing queries, reducing bundle size, or when asked about performance issues.
    17 repo stars
  66. ▌
    Openspec Bootstrap Opsx · gabrielmoreira
    Bootstrap OPSX architecture map from existing codebase using a structured five-phase workflow (init → scan → map → review → promote).
    17 repo stars
  67. ▌
    Engine Lab · gabrielmoreira
    Build and debug the Dagger engine from the workspace source with the EngineLab tools — the sandbox equivalent of the ./hack/dev + ./hack/with-dev loop. Read before using the engine-lab tools to run commands against a live from-source engine, poke its debug/pprof endpoints, run engine tests, or re-run repros after editing engine code.
    17 repo stars
  68. ▌
    Databricks Dbsql · gabrielmoreira bundle
    Databricks SQL (DBSQL) advanced features and SQL warehouse capabilities. This skill MUST be invoked when the user mentions: "DBSQL", "Databricks SQL", "SQL warehouse", "SQL scripting", "stored procedure", "CALL procedure", "materialized view", "CREATE MATERIALIZED VIEW", "pipe syntax", "|>", "geospatial", "H3", "ST_", "spatial SQL", "collation", "COLLATE", "ai_query", "ai_classify", "ai_extract", "ai_gen", "AI function", "http_request", "remote_query", "read_files", "Lakehouse Federation", "recursive CTE", "WITH RECURSIVE", "multi-statement transaction", "temp table", "temporary view", "pipe operator". SHOULD also invoke when the user asks about SQL best practices, data modeling patterns, or advanced SQL features on Databricks.
    17 repo stars
  69. ▌
    Aurakit · gabrielmoreira
    Sonnet Amplified fullstack engine. 34 modes, SEC-01~15 OWASP security, 13 runtime hooks, 75% token reduction. Install: npx @smorky85/aurakit
    17 repo stars
  70. ▌
    Doc Ocr · gabrielmoreira
    文档文字识别。用户提供 PDF/扫描件/图片(合同、发票、书页、截图),需要提取文字、转成可编辑文本时使用。扫描件自动 OCR(macOS Vision,中英文)。Document OCR: extract editable text from PDFs, scans, and images (contracts, invoices, book pages, screenshots) via macOS Vision.
    17 repo stars
  71. ▌
    Skyvern · gabrielmoreira
    AI-powered browser automation — navigate sites, fill forms, extract structured data, log in with stored credentials, and build reusable multi-step workflows using natural language. Install: pip install skyvern && skyvern setup
    17 repo stars
  72. ▌
    Tubeify · gabrielmoreira
    Remove pauses, filler words (um, uh), and dead air from raw YouTube recordings via the Tubeify API. Use when the user wants to edit a video, clean up audio, trim silences, or polish a raw recording for YouTube.
    17 repo stars
  73. ▌
    Bigdata Skill · gabrielmoreira
    Pull Bigdata.com (RavenPack) financial and news data via the official `bigdata-client` SDK and `/v1/*` REST endpoints — structured financials, prices, analyst estimates, daily entity-sentiment series, annotated chunk search, screener — when the Bigdata MCP returns only pre-synthesized tearsheets but you need the machine-readable substrate. Use when the user mentions Bigdata.com, RavenPack, a `bd_v2_` key, the bigdata MCP, rp_entity_id, chunk/query_unit cost, or wants structured financials, fundamentals, prices, sentiment, or annotated news.
    17 repo stars
  74. ▌
    Pol Probe Advisor · gabrielmoreira
    Select the right Proof of Life (PoL) probe based on hypothesis, risk, and resources. Use this to match the validation method to the real learning goal, not tooling comfort.
    17 repo stars
  75. ▌
    Problem Statement · gabrielmoreira bundle
    Write a user-centered problem statement with who is blocked, what they are trying to do, why it matters, and how it feels. Use when framing discovery, prioritization, or a PRD.
    17 repo stars
  76. ▌
    Incremental Coding · gabrielmoreira
    Build in verifiable increments. Never implement more than can be tested right now. Ship partial working systems over complete broken ones.
    17 repo stars
  77. ▌
    Security Hardening · gabrielmoreira
    Applies OWASP Top 10, secrets management, and least-privilege principles before any code ships. Security is a build step, not an afterthought.
    17 repo stars
  78. ▌
    Estimate · gabrielmoreira
    Estimates task effort by analyzing complexity, dependencies, historical velocity, and risk factors. Produces a structured estimate with confidence levels.
    17 repo stars
  79. ▌
    Run History Skill Builder · gabrielmoreira bundle
    Turn a completed task, browser flow, artifact pipeline, failure-recovery trace, or repeatedly refined workflow into a new reusable skill package or a reviewed skill-design plan. Use when the user asks to make a new skill from real run history, extract a reusable workflow from conversation/logs/files, summarize lessons into a new skill, or produce a plan before writing files. Do not use to upgrade an existing skill or to execute the business workflow itself.
    17 repo stars
  80. ▌
    Vectorization · gabrielmoreira
    Design, implement, optimize, and review SIMD code in .NET. USE FOR: vectorizing scalar loops with TensorPrimitives, Vector64/128/256/512, or platform hardware intrinsics; reviewing existing SIMD code, including Vector<T>, for contract equivalence, tail handling, memory safety, portability, fallbacks, and measured performance. DO NOT USE FOR: performance work unrelated to SIMD or vectorization.
    17 repo stars
  81. ▌
    Maui Data Binding · gabrielmoreira
    Guidance for .NET MAUI XAML and C# data bindings — compiled bindings, INotifyPropertyChanged / ObservableObject, value converters, binding modes, multi-binding, relative bindings, fallbacks, and MVVM best practices. USE FOR: setting up compiled bindings with x:DataType, implementing INotifyPropertyChanged or CommunityToolkit ObservableObject, creating IValueConverter / IMultiValueConverter, choosing binding modes, configuring BindingContext, relative bindings, binding fallbacks, StringFormat, code-behind SetBinding with lambdas, and enforcing XC0022/XC0025 warnings. DO NOT USE FOR: CollectionView item templates and layouts (use maui-collectionview), Shell navigation data passing (use maui-shell-navigation), dependency injection (use maui-dependency-injection), or animations triggered by property changes (use .NET MAUI animation APIs).
    17 repo stars
  82. ▌
    Assertion Quality · gabrielmoreira
    Analyze assertion quality, depth, variety, and false confidence in existing tests. ALWAYS USE when asked about weak, shallow, trivial, always-true, self-referential, assertion-free, presence/truthiness-only, or insufficiently diverse assertions, including MSTest, Jest, pytest, and Go. DO NOT USE for direct fixes: writing-mstest-tests owns supplied MSTest assertions; code-testing-agent owns new cases. Use test-gap-analysis when asked whether tests would catch a production change, and test-anti-patterns for general severity-ranked audits.
    17 repo stars
  83. ▌
    Coverage Analysis · gabrielmoreira
    Activation requires either supplied .NET coverage reports/percentages/line, branch, or condition metrics, or an explicit request to collect .NET coverage for analysis. USE FOR: interpreting that evidence, including Cobertura data, partial conditions, plateaus, target arithmetic, project-wide coverage-backed CRAP, and coverage-backed refactoring safety. Analyze supplied reports directly without rerunning tests or installing tools. DO NOT USE FOR: requests with neither coverage evidence nor explicit coverage-collection intent, including hypothetical change-survival questions (use test-gap-analysis); CRAP or refactoring safety for one named target (use crap-score); or requests owned by test-tagging, find-untested-sources, test-anti-patterns, run-tests, or code-testing-agent.
    17 repo stars
  84. ▌
    Test Gap Analysis · gabrielmoreira
    Pseudo-mutation analysis ONLY: answer whether tests would catch a bug if production code changed, which meaningful changes would still pass, or which caller-visible mutations existing assertions would miss; verify candidates when requested, then optionally close verified gaps. Activate for behavioral blind spots or missing edge cases tied to production behavior. Polyglot. DO NOT USE FOR: suite organization, taxonomy, metadata, or distribution reports (test-tagging); .NET line-vs-branch or Cobertura interpretation, arithmetic, plateaus, project-wide coverage gaps, or coverage-backed test/CRAP priorities (coverage-analysis; use native coverage tooling outside .NET); named-target CRAP (crap-score); new suites (code-testing-agent); assertion/smell audits; or mutation tools.
    17 repo stars
  85. ▌
    IOS Memgraph Analysis · gabrielmoreira bundle
    Use when capturing or analyzing an iOS .memgraph, especially when the task mentions a memory leak, heap growth, persistent memory increase, ownership path, or matched-capture comparison with Apple CLI tools. Covers unambiguous Simulator capture, leaks/heap/vmmap/malloc_history evidence, raw artifact preservation, and same-flow verification. Use debugging-instruments for interactive Xcode Memory Graph, Instruments, generic retain-cycle inspection, or LLDB work.
    17 repo stars
  86. ▌
    Rootnode Domain Business Strategy · gabrielmoreira
    Specialized business strategy prompt methodology for Claude. Provides 11 tested approaches (3 identity, 4 reasoning, 4 output formats) for consulting, M&A, corporate strategy, and strategic planning tasks. Use when building prompts for deal evaluation, due diligence, portfolio strategy, business model analysis, board narratives, investment cases, market entry plans, or strategic options assessments. Trigger on: "build a prompt for M&A analysis," "due diligence prompt," "board narrative," "investment case," "market entry strategy," "strategic options," "portfolio strategy prompt," "business model analysis prompt," "consulting-style analysis." Do NOT use for evaluating or scoring existing prompts (use rootnode-prompt-validation if available) or for auditing Claude Projects (use rootnode-project-audit if available).
    17 repo stars
  87. ▌
    Rootnode Domain Research Analysis · gabrielmoreira
    Specialized research and analysis prompt methodology for Claude. Provides 11 tested approaches (3 identity, 4 reasoning, 4 output) for data analysis, policy research, systematic evidence review, investigative research, and research-specific deliverables. Use when building prompts for quantitative data interpretation, evidence-based policy recommendations, literature reviews, causal analysis, hypothesis-driven investigation, or briefing documents. Trigger on: "prompt for data analysis," "research prompt," "policy brief prompt," "literature review prompt," "prompt for investigating," "systematic review prompt," "build a prompt for evidence synthesis," "causal analysis prompt," "briefing document prompt." Also use when user describes a research or analytical task and needs a structured Claude prompt for it. Do NOT use for evaluating existing prompts (use rootnode-prompt-validation if available) or auditing Claude Projects (use rootnode-project-audit if available).
    17 repo stars
  88. ▌
    Teamshare CLI · gabrielmoreira
    Use when the user wants to interact with Teamshare capabilities, especially Teamshare Base multi-dimensional tables: files, directories, sheets, fields, records, views, forms, dashboards, or dashboard widgets. Load this skill first to route to the right Teamshare sub-skill. Also trigger for localized requests in the user's language that refer to Teamshare or Teamshare Base.
    17 repo stars
  89. ▌
    Dt Sec Contextualization · gabrielmoreira bundle
    Resolve security signals, IoC matches, or Smartscape nodes to runtime Dynatrace entities and connect findings on different entity levels through a shared runtime entity. Covers identity-to-Smartscape mapping (incl. container-image digest/ID to workload), cross-level topology (K8s pod detection vs. node CVE via pod-to-node), per-entity risk summarization, and coverage match recipes shared by dt-sec-insights. Trigger: "map these findings to workloads/hosts", "which workload does this container image run as", "do these findings relate through the same runtime entity", "enrich this IoC match with entity context", "which threat report mentions this IoC". Queries security.events ONLY for THREAT_REPORT IoC enrichment (matched IoC to attributing reports); Do NOT use for broad security.events posture/overview (use dt-sec-insights), general DQL (use dt-dql-essentials), IoC hunting in logs/spans (use dt-sec-ioc-hunting), or K8s observability outside the security cross-level context (use dt-obs-kubernetes).
    17 repo stars
  90. ▌
    Electron Chromium Upgrade · gabrielmoreira
    Guide for performing Chromium version upgrades in the Electron project. Use when working on the roller/chromium/main branch to fix patch conflicts during `e sync --3`. Covers the patch application workflow, conflict resolution, analyzing upstream Chromium changes, and proper commit formatting for patch fixes.
    17 repo stars
  91. ▌
    Hunt Business Logic · gabrielmoreira
    Hunting skill for business logic vulnerabilities. Built from 12 public bug bounty reports. Covers coupon-race-stacking (Instacart, Stripe, Reverb), negative-quantity-in-cart price tampering (Upserve, Eternal/Zomato), decimal/fraction price-field overflow (Shipt), client-side checkout amount trust on PayPal redirect (WordPress.org), price-per-unit mass-assignment (Krisp), and archived-price swap / cart-TOCTOU (Stripe). Use when hunting business logic — heavy emphasis on financial-impact-demonstrated cases.
    17 repo stars
  92. ▌
    Hunt Captcha Bypass · gabrielmoreira
    Hunt CAPTCHA Bypass — 6 distinct patterns: (1) CAPTCHA field simply omitted from the request (server-side validation absent), (2) CAPTCHA token replayed from a solved challenge (no single-use enforcement), (3) CAPTCHA response accepted on a different endpoint than it was solved on (no binding to action/session), (4) static or predictable CAPTCHA values accepted (e.g. '0', 'null', empty string), (5) audio/accessibility CAPTCHA trivially solvable programmatically, (6) CAPTCHA only enforced after N failures (first N requests bypass it). Detection: intercept a successful form submission, remove the CAPTCHA field entirely, replay — if it still succeeds, server-side validation is absent. Medium severity standalone; High when it removes the only rate-limit gate protecting a login, registration, or payment endpoint.
    17 repo stars
  93. ▌
    Hunt HTML Injection · gabrielmoreira
    Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an attacker to inject arbitrary HTML tags (but not necessarily JavaScript). Lower severity than XSS but enables phishing, UI manipulation, and credential harvesting via injected forms. Use when testing text-display surfaces (search results, profile fields, comments, error messages, feedback forms). For markup that executes JavaScript, escalate to hunt-xss.
    17 repo stars
  94. ▌
    Hunt HTTP Smuggling · gabrielmoreira
    Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy and back-end server disagree on where one request ends and the next begins (Content-Length vs Transfer-Encoding header parsing inconsistency). CL.TE: front-end uses CL, back uses TE → smuggle by sending TE: chunked but with body that fits CL count. TE.CL: opposite. H2.CL: HTTP/2 downgrade, smuggle CL into HTTP/1.1 back-end. Detection tools: Burp HTTP Request Smuggler extension, smuggler.py, h2csmuggler. Confirm: time-delay technique (smuggled GET with 30s timeout) — if front-end returns slow on next victim request, smuggling works. Validate: cache poisoning chain (smuggle request that gets cached for victim), credential theft (smuggle X-Forwarded-For override that captures next user's cookies), bypass auth (smuggled internal-path request). Real paid examples from major CDN deployments. Use when hunting H1 paid programs running CDN+origin stacks, when targeting load balancer / WAF bypass.
    17 repo stars
  95. ▌
    Hunt Race Condition · gabrielmoreira
    Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Kettle DEF CON 2023 "Smashing the State Machine"; RyotaK / Flatt Security 10,000-request first-sequence-sync expansion 2024). Covers coupon double-redemption, gift-card double-spend, MFA-OTP-validate race, account-create race, faucet/crypto token double-mint, email-activation race, vote/upvote inflation, password-reset token race, rate-limit bypass via concurrent requests. Use when hunting race conditions, TOCTOU bugs, MFA-bypass-via-timing.
    17 repo stars
  96. ▌
    Identity Provider Recon · gabrielmoreira bundle
    Organization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint only, never credential submission. Covers domain-to-tenant resolution (Microsoft getuserrealm.srf Managed/Federated namespace check, Entra OIDC metadata tenant-GUID extraction, Autodiscover v2), keyless Microsoft tenant-federation mapping (GetFederationInformation SOAP -> sibling-domain discovery, discover-only ROE, FEDERATED_WITH provenance edge held out of attack-path pivoting), Okta org-slug derivation + OIDC fingerprint + governed custom-domain enumeration, ADFS passive/active fingerprint + version inference, Google Workspace MX-correlated detection, generic OIDC (Auth0/Keycloak/Ping Identity/OneLogin/Duo) discovery, SAML metadata (5 paths), Azure AD Seamless-SSO Negotiate-challenge detection, Microsoft Defender for Identity (MDI) sensor-API presence check, the user-enumeration oracle methodology for Microsoft GetCredentialType (IfExistsResult sema
    17 repo stars
  97. ▌
    Eliza App Development · gabrielmoreira
    Use when building or changing an elizaOS-based application in this repository. Covers eliza app architecture, monorepo layout, local versus remote versus cloud routing, where to edit features, and non-negotiable runtime constraints. Eliza is the product name of this particular eliza app checkout.
    17 repo stars
  98. ▌
    Conventions Improver · gabrielmoreira
    Audit and improve project conventions files (AGENTS.md, CLAUDE.md, GEMINI.md). Scans for all conventions files, evaluates quality against a scoring rubric, outputs a quality report, then makes targeted improvements with user approval. Use when asked to check, audit, update, or improve AGENTS.md or similar files.
    17 repo stars
  99. ▌
    Type Design Analyzer · gabrielmoreira
    Analyzes type design quality by rating encapsulation, invariant expression, usefulness, and enforcement. Helps design types that make invalid states unrepresentable. Use when reviewing new types or data models.
    17 repo stars
  100. ▌
    Simple Issue Description · gabrielmoreira bundle
    Turn a rough bug report, feature request, support note, or pull request into a short, plain-language issue focused on the problem and desired behavior. Use when a contributor asks to simplify an issue, explain what a PR is for, create the corresponding issue for a PR, remove implementation detail from a report, or invokes /simple-issue-description.
    17 repo stars