all publishers

gabrielmoreira

@gabrielmoreira source repo

21,231 published skills · page 68 of 213

  1. ▌
    Run Automation Suite · gabrielmoreira
    Run local Appium test scripts against Kobiton devices. Guides through app upload, device selection, capability parsing, and local execution. Use when the user asks to run mobile tests, validate an APK or IPA on Kobiton devices, or kick off an Appium suite from a local script directory. Trigger with "run kobiton tests" or "execute appium on kobiton".
    17 repo stars
  2. ▌
    Statistical Significance Calculator · gabrielmoreira
    Configure and manage - Calculate statistical significance calculator operations. Auto-activating skill for Data Analytics. Triggers on: statistical significance calculator, statistical significance calculator Part of the Data Analytics skill category. Use when working with statistical significance calculator functionality. Trigger with phrases like "statistical significance calculator", "statistical calculator", "statistical".
    17 repo stars
  3. ▌
    Analyze Logistics Waste · gabrielmoreira bundle
    Analyze logistics waste from process maps, movement, waiting, rework, defects, excess inventory, overprocessing, and source evidence.
    17 repo stars
  4. ▌
    Research Canadian Material Handling Safety · gabrielmoreira
    Prepare Canadian material-handling safety research briefs for warehouse movement, storage, lifting, traffic, and ergonomic risks.
    17 repo stars
  5. ▌
    Research Canadian Powered Equipment Safety · gabrielmoreira
    Prepare Canadian powered industrial equipment safety research briefs for forklifts, lift trucks, conveyors, AGVs, AMRs, and ASRS interfaces.
    17 repo stars
  6. ▌
    Testing Simulink Models · gabrielmoreira
    Tests Simulink models using either ephemeral Gherkin-based tests (model_test) for quick validation or persistent tests (Simulink Test API) authored from requirements or behavioral specs. Requires Simulink Test.
    17 repo stars
  7. ▌
    Implementing Data Loss Prevention With Microsoft Purview · gabrielmoreira bundle
    Implements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including sensitivity labels, custom sensitive information types with regex, endpoint DLP rules, and Activity Explorer monitoring. Use when stopping PII/PHI/PCI exfiltration, configuring sensitivity labels, or investigating DLP incidents for policy tuning.
    17 repo stars
  8. ▌
    Implementing Epss Score For Vulnerability Prioritization · gabrielmoreira bundle
    Queries FIRST's Exploit Prediction Scoring System (EPSS) API to fetch exploitation-probability and percentile scores for CVEs, then uses those scores to prioritize vulnerability remediation. Use when triaging or ranking a vulnerability backlog by real-world 30-day exploitation likelihood rather than CVSS severity alone.
    17 repo stars
  9. ▌
    Large Excel Analysis And Formatting · gabrielmoreira
    用于处理多Sheet大型Excel文件,支持大文件Parquet格式转换提速,并使用openpyxl生成带条件高亮和自定义样式的格式化Excel报告及下载链接。
    17 repo stars
  10. ▌
    Multi Sheet Reading And Analysis · gabrielmoreira
    用于读取多工作表Excel文件,动态评估数据量以启用Parquet大文件优化,并执行正则清洗、分类汇总、线性拟合及生成带格式的图表与结果文件。
    17 repo stars
  11. ▌
    Dynamic Workflows · gabrielmoreira
    Designs and runs task-specific JavaScript harnesses with the `workflow` tool. Use for broad, long-running, highly structured, or adversarial work that benefits from many isolated agents: exhaustive audits, root-cause investigations, research, large triage queues, competing proposals, repeated verification, and independent changes across disjoint files. Covers decomposition patterns, agent and model routing, structured handoffs, failure handling, and the workflow runtime API.
    17 repo stars
  12. ▌
    Exploiting Arbitrary Write To Execution · gabrielmoreira
    Methodology for converting an arbitrary-write (write-what-where) or write-anything-anywhere primitive into code execution during authorized engagements, covering target selection among GOT/PLT entries, .fini_array/.dtors, __malloc_hook/__free_hook, the atexit/__exit_funcs handler list, and __printf_arginfo_table, plus how mitigations (Full RELRO, pointer mangling) change which target is viable and how to confirm hijacked control flow.
    17 repo stars
  13. ▌
    Exploiting Linux Kernel Vulnerabilities · gabrielmoreira
    Methodology for discovering and exploiting Linux kernel memory-corruption vulnerabilities (UAF, OOB read/write, race/TOCTOU, type confusion) during authorized engagements, covering reachability analysis, building stable read/write primitives from a single bug, defeating KASLR/SMEP/SMAP/KPTI, slab/buddy heap grooming, and pivoting to ring-0 code execution or credential overwrite for local privilege escalation.
    17 repo stars
  14. ▌
    Performing Cloud Native Forensics With Falco · gabrielmoreira
    Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.
    17 repo stars
  15. ▌
    Performing Post Quantum Cryptography Migration · gabrielmoreira
    Assesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when planning or executing the transition from classical to post-quantum cryptographic algorithms across enterprise infrastructure.
    17 repo stars
  16. ▌
    Deploying Active Directory Honeytokens · gabrielmoreira
    Deploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.
    17 repo stars
  17. ▌
    Implementing Aqua Security For Container Scanning · gabrielmoreira
    Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
    17 repo stars
  18. ▌
    Deploying Osquery For Endpoint Monitoring · gabrielmoreira
    Deploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying.
    17 repo stars
  19. ▌
    Performing Service Account Audit · gabrielmoreira
    Audit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
    17 repo stars
  20. ▌
    Analyzing Ransomware Encryption Mechanisms · gabrielmoreira
    Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility.
    17 repo stars
  21. ▌
    Testing Android Intents For Vulnerabilities · gabrielmoreira
    Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage. Use when assessing Android app attack surface through exported components, testing intent-based data flows, or evaluating IPC security. Activates for requests involving Android intent security, IPC testing, exported component analysis, or Drozer assessment.
    17 repo stars
  22. ▌
    Performing Ot Vulnerability Scanning Safely · gabrielmoreira
    Perform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
    17 repo stars
  23. ▌
    Analyzing Web Server Logs For Intrusion · gabrielmoreira
    Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.
    17 repo stars
  24. ▌
    Extracting Memory Artifacts With Rekall · gabrielmoreira
    Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and dlllist to extract forensic artifacts from Windows memory images. Use during incident response memory analysis.
    17 repo stars
  25. ▌
    Implementing Security Chaos Engineering · gabrielmoreira
    Implements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess. Use when validating SOC detection coverage and resilience.
    17 repo stars
  26. ▌
    Hunting For Defense Evasion Via Timestomping · gabrielmoreira
    Detect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-forensic timestomping activity.
    17 repo stars
  27. ▌
    Performing Reflected File Download · gabrielmoreira
    Identifying and exploiting Reflected File Download (RFD) where an endpoint reflects attacker-controlled input into a downloadable response with an attacker-controlled filename and extension, enabling command execution on the victim's machine when the file is run.
    17 repo stars
  28. ▌
    Graphical Abstract Generator · gabrielmoreira
    Converts a biomedical study storyline into a graphical abstract and, when direct image capability is available, generates the graphical abstract directly; otherwise it falls back to prompts, Mermaid flowcharts, or designer-facing briefs.
    17 repo stars
  29. ▌
    Title And Abstract Optimizer · gabrielmoreira
    Optimizes manuscript titles and abstracts for information density, factual accuracy, and submission fit in biomedical research writing.
    17 repo stars
  30. ▌
    Gsva Analysis And Visualization · gabrielmoreira
    Use this skill to run GSVA or ssGSEA pathway-level differential analysis from a bulk expression matrix and a sample group file, then generate a heatmap from the saved GSVA result object. Trigger keywords: GSVA, ssGSEA, pathway enrichment, KEGG pathway analysis, MSigDB. NOT for: gene-level differential expression, single-cell analysis, methylation analysis, clinical diagnosis.
    17 repo stars
  31. ▌
    Preprint Surveillance Finder · gabrielmoreira
    Tracks the latest preprints and emerging research topics related to your topic across bioRxiv, medRxiv, and arXiv. Use when a user wants to discover what is being published right now before it reaches journals, monitor competitor directions, spot new methodology trends, or get an early-warning scan of a research area. Triggers on phrases like "what's new in X", "latest preprints on Y", "emerging topics in Z", "monitor bioRxiv for", or "what are people working on in this field".
    17 repo stars
  32. ▌
    Translational Study Blueprint · gabrielmoreira
    Designs a translational blueprint for moving a biomedical finding toward diagnosis, prognosis, treatment response prediction, patient stratification, or therapeutic development, with explicit translational milestones, validation thresholds, and feasibility-sensitive route framing.
    17 repo stars
  33. ▌
    Case Control Study Quality Assessment Nos · gabrielmoreira
    Clinical Research Bias Assessment - Case-Control Study (NOS) v2.3.0. Use when you need to assess the bias of a case-control study using the Newcastle-Ottawa Scale (NOS) criteria, or when evaluating the quality of a medical paper.
    17 repo stars
  34. ▌
    Hello Secure · gabrielmoreira
    A simple skill demonstrating clawdstrike security
    17 repo stars
  35. ▌
    Cherry Skill Marketplace · gabrielmoreira
    当用户明确要求搜索、安装、查看、卸载或创建 Skill,或内置 Skill / 工具出现能力缺口、无法完成当前任务时触发。通过 `mcp__skills__search_skills` 搜索并用 `mcp__skills__install_skill` 安装;已安装 Skill 的查看和删除通过产品清单导航到 Skills UI;没有合适结果时调用内置 `skill-creator` 创建并验证自定义 Skill,再继续原任务。普通任务仍先尝试内置能力。
    17 repo stars
  36. ▌
    Resource Pool Optimizer · gabrielmoreira
    Optimize shared resource pools across multiple construction projects. Balance resource allocation, minimize conflicts, and maximize utilization across the portfolio.
    17 repo stars
  37. ▌
    Microsoft Graph API · gabrielmoreira
    Comprehensive Microsoft Graph API reference for M365 service integration
    17 repo stars
  38. ▌
    Msal Authentication · gabrielmoreira
    Microsoft Authentication Library (MSAL) patterns for React/SPA applications with Entra ID
    17 repo stars
  39. ▌
    Terminal Command Safety · gabrielmoreira
    Safe terminal command patterns — backtick escaping, output capture, and hang prevention
    17 repo stars
  40. ▌
    Universal Audit Pattern · gabrielmoreira
    Systematic project audit pattern — version consistency, terminology, fact inventory, cross-references
    17 repo stars
  41. ▌
    Coaching Techniques · gabrielmoreira
    GROW model, active listening, developmental feedback, and team growth approaches
    17 repo stars
  42. ▌
    Learning Psychology · gabrielmoreira
    Help humans learn through partnership, not instruction.
    17 repo stars
  43. ▌
    Deep Work Optimization · gabrielmoreira
    Focus blocks, distraction management, and flow state triggers for cognitively demanding work
    17 repo stars
  44. ▌
    Github Readme Override · gabrielmoreira
    GitHub README display rules — which README renders when multiple exist, profile READMEs, org READMEs
    17 repo stars
  45. ▌
    Draw Io Diagram Generator · gabrielmoreira bundle
    Use when creating, editing, or generating draw.io diagram files (.drawio, .drawio.svg, .drawio.png). Covers mxGraph XML authoring, shape libraries, style strings, flowcharts, system architecture, sequence diagrams, ER diagrams, UML class diagrams, network topology, layout strategy, the hediet.vscode-drawio VS Code extension, and the full agent workflow from request to a ready-to-open file.
    17 repo stars
  46. ▌
    Brand Asset Management · gabrielmoreira
    Brand hierarchy, visual identity, asset deployment, platform-specific branding guidelines
    17 repo stars
  47. ▌
    Document Banner Pastel · gabrielmoreira
    Hand-authored pastel SVG banners for documentation — 1200×240 with content-specific iconography, complementary to algorithmic banner muscles
    17 repo stars
  48. ▌
    Seek And Analyze Video · gabrielmoreira
    Seek and analyze video content using Memories.ai Large Visual Memory Model for persistent video intelligence
    17 repo stars
  49. ▌
    Node Winget Collision · gabrielmoreira
    Node.js installed via winget collides with nvm — path priority, shim conflicts, resolution steps
    17 repo stars
  50. ▌
    Pat Expiration Silent · gabrielmoreira
    Personal Access Token expiration fails silently — 401 errors with no expiry message, pre-check pattern
    17 repo stars
  51. ▌
    Linkedin Post Formatter · gabrielmoreira
    Format and draft compelling LinkedIn posts using Unicode bold/italic styling, visual separators, structured sections, and engagement-optimized patterns. USE FOR: draft LinkedIn post, format text for LinkedIn, create social media post, write thought leadership post, convert content to LinkedIn format, LinkedIn carousel text, Unicode bold italic formatting.
    17 repo stars
  52. ▌
    Distribution Security · gabrielmoreira
    Defense-in-depth, PII protection, secrets scanning, and secure packaging for distributed software
    17 repo stars
  53. ▌
    Subagent Orchestrator · gabrielmoreira
    Coordinate quota-aware parallel subagents for large, multi-file Antigravity tasks.
    17 repo stars
  54. ▌
    Buzz Hn · gabrielmoreira
    Hacker News post crafter — given a product, feature, or story produces a ready-to-post HN submission (title ≤80 chars, no marketing), honest body text with technical depth, no outbound links, predicted reception analysis, and comment-response templates for likely pushback. Use when asked to "write an HN post", "craft a Show HN", "prepare our Hacker News launch", or "help me post on HN".
    17 repo stars
  55. ▌
    Blog Figure Svg · gabrielmoreira
    Stop using stock photos. Generate accessible, lightweight SVG figures for any blog or CMS - flow diagrams, comparison bar charts, taxonomy/Venn diagrams, annotated terminal mocks, and 1600x840 OG feature cards. Hand-authored SVG (no embedded fonts, no external assets, no AI-image latency) with a consistent palette, screen-reader metadata (title + desc + aria-labelledby), and a figcaption-required handoff to the writer. Rasterizes to compressed PNG ready for Ghost, WordPress, Webflow, or any static-site generator. Built for content marketers, indie hackers, and dev-tool blogs that want unique illustrations on every post without paying a designer or burning Midjourney credits. Trigger when the user says: 'add a figure to the post', 'illustrate this comparison', 'draw a flow diagram for X', 'make a feature/OG image', or any request to produce a chart/diagram for editorial use.
    17 repo stars
  56. ▌
    SEO Blog Writer · gabrielmoreira
    Turn a single long-tail query into a publish-ready blog post that ranks in search and gets quoted by AI assistants. Runs the full pipeline: classify the topic, research it against real sources, draft clean HTML, scrub LLM-tell vocabulary and typography, audit for AI-SEO (TL;DR block, query-phrased H2s, FAQ section, FAQPage + BreadcrumbList + HowTo JSON-LD), then publish through a platform adapter (Ghost Admin API, WordPress REST, or static-site file output). Platform-agnostic core; swap the publish step without rewriting the writing pipeline. Built for indie hackers, founders, and content marketers who want AI to draft posts that are actually citable - not paraphrased docs, not hallucinated benchmarks. Trigger when the user says: 'write a blog post on X', 'draft an article about X', 'publish a post on X to Ghost / WordPress / the static site', or any request to ship editorial content for a long-tail query.
    17 repo stars
  57. ▌
    Algolia CI Integration · gabrielmoreira
    Configure Algolia CI/CD: GitHub Actions for index validation, automated reindexing on deploy, and integration testing against real Algolia indices. Trigger: "algolia CI", "algolia GitHub Actions", "algolia automated tests", "CI algolia", "algolia deploy pipeline".
    17 repo stars
  58. ▌
    Attio Deploy Integration · gabrielmoreira
    Deploy Attio integrations to Vercel, Fly.io, Railway, and Cloud Run with proper secrets, health checks, and webhook endpoint configuration. Trigger: "deploy attio", "attio Vercel", "attio production deploy", "attio Cloud Run", "attio Fly.io", "attio Railway".
    17 repo stars
  59. ▌
    Attio Performance Tuning · gabrielmoreira
    Optimize Attio API performance -- caching, batch queries, pagination strategies, connection pooling, and latency reduction. Trigger: "attio performance", "optimize attio", "attio slow", "attio latency", "attio caching", "attio batch requests".
    17 repo stars
  60. ▌
    Clickup Local Dev Loop · gabrielmoreira
    Set up local development for ClickUp API integrations with testing, mocking, and hot reload. Trigger: "clickup dev setup", "clickup local development", "clickup dev environment", "develop with clickup", "clickup testing setup", "mock clickup API".
    17 repo stars
  61. ▌
    Cohere Incident Runbook · gabrielmoreira
    Execute Cohere incident response procedures with triage, mitigation, and postmortem. Use when responding to Cohere API outages, investigating errors, or running post-incident reviews for Cohere integration failures. Trigger with phrases like "cohere incident", "cohere outage", "cohere down", "cohere on-call", "cohere emergency", "cohere broken".
    17 repo stars
  62. ▌
    Exa Reference Architecture · gabrielmoreira
    Implement Exa reference architecture for search pipelines, RAG, and content discovery. Use when designing new Exa integrations, reviewing project structure, or establishing architecture standards for neural search applications. Trigger with phrases like "exa architecture", "exa project structure", "exa RAG pipeline", "exa reference design", "exa search pipeline".
    17 repo stars
  63. ▌
    Granola Local Dev Loop · gabrielmoreira
    Access Granola meeting data programmatically for developer workflows. Use when reading notes from the local cache, building MCP integrations, extracting action items into code, or syncing meeting outcomes to dev tools. Trigger: "granola dev workflow", "granola MCP", "granola local cache", "granola developer", "granola programmatic".
    17 repo stars
  64. ▌
    Linear Incident Runbook · gabrielmoreira
    Production incident response procedures for Linear integrations. Use when handling production issues, diagnosing outages, or responding to Linear-related incidents. Trigger: "linear incident", "linear outage", "linear production issue", "debug linear production", "linear down", "linear 500".
    17 repo stars
  65. ▌
    Posthog CI Integration · gabrielmoreira
    Configure PostHog CI/CD with GitHub Actions: unit tests with mocked PostHog, integration tests against a dev project, and deployment annotations. Trigger: "posthog CI", "posthog GitHub Actions", "posthog automated tests", "CI posthog", "posthog pipeline".
    17 repo stars
  66. ▌
    Posthog Local Dev Loop · gabrielmoreira
    Configure PostHog local development with mocking, debug mode, and testing. Use when setting up a development environment, mocking PostHog for tests, or establishing a fast iteration cycle with posthog-js or posthog-node. Trigger: "posthog dev setup", "posthog local development", "posthog dev environment", "mock posthog", "test posthog".
    17 repo stars
  67. ▌
    Posthog Prod Checklist · gabrielmoreira
    Production readiness checklist for PostHog integrations: SDK configuration, graceful degradation, health checks, shutdown hooks, and rollback procedures. Trigger: "posthog production", "deploy posthog", "posthog go-live", "posthog launch checklist", "posthog production ready".
    17 repo stars
  68. ▌
    Serpapi CI Integration · gabrielmoreira
    Set up CI/CD for SerpApi integrations with fixture-based testing. Use when automating SerpApi tests without consuming credits, or validating search result parsing in CI. Trigger: "serpapi CI", "serpapi GitHub Actions", "serpapi automated tests".
    17 repo stars
  69. ▌
    Serpapi Local Dev Loop · gabrielmoreira
    Configure SerpApi local development with cached responses and test fixtures. Use when building search integrations, avoiding API calls during development, or setting up reproducible test data from SerpApi. Trigger: "serpapi dev setup", "serpapi local", "test serpapi locally".
    17 repo stars
  70. ▌
    Serpapi Prod Checklist · gabrielmoreira
    Production readiness checklist for SerpApi integrations. Use when deploying search features, validating credit budgets, or preparing SerpApi-powered apps for launch. Trigger: "serpapi production", "deploy serpapi", "serpapi go-live".
    17 repo stars
  71. ▌
    Together Sdk Patterns · gabrielmoreira
    Together AI sdk patterns for inference, fine-tuning, and model deployment. Use when working with Together AI's OpenAI-compatible API. Trigger: "together sdk patterns".
    17 repo stars
  72. ▌
    Webflow CI Integration · gabrielmoreira
    Configure Webflow CI/CD with GitHub Actions — automated CMS validation, integration tests with test tokens, and publish-on-merge workflows. Use when setting up automated testing or CI pipelines for Webflow integrations. Trigger with phrases like "webflow CI", "webflow GitHub Actions", "webflow automated tests", "CI webflow", "webflow pipeline".
    17 repo stars
  73. ▌
    Webflow Local Dev Loop · gabrielmoreira
    Configure a Webflow local development workflow with TypeScript, hot reload, mocked API tests, and webhook tunneling via ngrok. Use when setting up a development environment, configuring test workflows, or establishing a fast iteration cycle with the Webflow Data API. Trigger with phrases like "webflow dev setup", "webflow local development", "webflow dev environment", "develop with webflow".
    17 repo stars
  74. ▌
    Webflow Prod Checklist · gabrielmoreira
    Execute Webflow production deployment checklist — token security, rate limit hardening, health checks, circuit breakers, gradual rollout, and rollback procedures. Use when deploying Webflow integrations to production or preparing for launch. Trigger with phrases like "webflow production", "deploy webflow", "webflow go-live", "webflow launch checklist", "webflow production ready".
    17 repo stars
  75. ▌
    Guidewire Observability And Incident Response · gabrielmoreira bundle
    Operate a Guidewire Cloud API integration in production — define SLIs/SLOs for token availability, bind success rate, FNOL p99 latency; route alerts so the on-call gets paged for real outages and never for transient noise; triage 401 spikes, 409 storms, 429 saturation, scope drift, and Gosu OOM cascades from signal to recovery in 15 minutes or less. Use when designing a dashboard for a new integration, writing the on-call runbook, or running a post-incident review. Trigger with "guidewire observability", "guidewire slo", "guidewire on-call", "guidewire 401 spike", "guidewire 409 storm", "guidewire incident".
    17 repo stars
  76. ▌
    Governance Checklist Generator · gabrielmoreira
    Generate governance checklist generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: governance checklist generator, governance checklist generator Part of the Enterprise Workflows skill category. Use when working with governance checklist generator functionality. Trigger with phrases like "governance checklist generator", "governance generator", "governance".
    17 repo stars
  77. ▌
    Design Logistics Unit Identification · gabrielmoreira bundle
    Design source-backed logistics unit identification concepts across items, cases, cartons, pallets, locations, parties, shipments, and system handoffs.
    17 repo stars
  78. ▌
    Diagnose Throughput Loss · gabrielmoreira bundle
    Diagnose logistics throughput loss from throughput gaps, queues, downtime, labor, equipment, process, and source evidence.
    17 repo stars
  79. ▌
    Research Canadian Commercial Vehicle Safety · gabrielmoreira
    Prepare Canadian commercial-vehicle safety research briefs for motor carrier, driver, vehicle, maintenance, and hours-of-service context.
    17 repo stars
  80. ▌
    Research Us Material Handling Safety · gabrielmoreira
    Prepare United States material-handling safety research briefs for warehouse movement, storage, lifting, traffic, and ergonomic risks.
    17 repo stars
  81. ▌
    Research Us Powered Equipment Safety · gabrielmoreira
    Prepare United States powered industrial truck and powered equipment safety research briefs for logistics operations.
    17 repo stars
  82. ▌
    Deepmd Python Inference · gabrielmoreira
    Run Python inference with DeePMD-kit models using the DeepPot API. Use when the user wants to load a trained/frozen DeePMD model (.pth or .pb) or a built-in pretrained model (e.g., DPA-3.2-5M) in Python, predict energy/force/virial for atomic configurations, evaluate descriptors, or calculate model deviation between multiple models. Also covers using `dp test` CLI for batch evaluation against labeled data.
    17 repo stars
  83. ▌
    Eu AI Act Fria · gabrielmoreira bundle
    Assess whether a Fundamental Rights Impact Assessment (FRIA) is required under Article 27 EU AI Act, and structure or draft that assessment for a specific high-risk AI deployment. Covers deployer scope gating (public bodies and private entities providing public services), affected group mapping, Charter rights analysis, proportionality, safeguards evaluation, residual risk, DPIA/FRIA cross-referencing under the amended Article 27(4), the unconditional notification duty under Article 27(3), and DACH-specific considerations. Use when asked about FRIA obligations, Article 27 scope, fundamental rights and AI, or deployer assessment duties.
    17 repo stars
  84. ▌
    Implementing Container Image Minimal Base With Distroless · gabrielmoreira bundle
    Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using multi-stage build patterns plus debugging and scanning techniques adapted to distroless. Use when hardening container images, cutting attack surface in a container architecture, or answering an assessment finding about bloated base images. Keywords: distroless, multi-stage build, no shell, nonroot tag, debug image, scratch, attack surface. Do not use for scanning an image for known CVEs - use scanning-docker-images-with-trivy.
    17 repo stars
  85. ▌
    Performing Cloud Native Threat Hunting With AWS Detective · gabrielmoreira bundle
    Investigate AWS security incidents using Amazon Detective's behavior graphs, built from CloudTrail, VPC Flow Logs, GuardDuty, and EKS audit logs, to trace entity timelines and profile IAM users, roles, EC2 instances, and IP addresses for lateral movement. Use when triaging GuardDuty findings, investigating a suspected AWS compromise, or reconstructing an attacker's activity timeline across AWS accounts.
    17 repo stars
  86. ▌
    Android Coroutines · gabrielmoreira
    Authoritative rules and patterns for production-quality Kotlin Coroutines onto Android. Covers structured concurrency, lifecycle integration, and reactive streams.
    17 repo stars
  87. ▌
    Android Emulator Skill · gabrielmoreira
    Production-ready scripts for Android app testing, building, and automation. Provides semantic UI navigation, build automation, log monitoring, and emulator lifecycle management. Optimized for AI agents with minimal token output.
    17 repo stars
  88. ▌
    Single Sheet Reading And Analysis · gabrielmoreira
    读取并解析单个Excel工作表数据,支持合并单元格处理、数据清洗、交叉分析及多维度可视化,适用于需要从单表中提取关键指标并进行趋势模拟与图表生成的场景。
    17 repo stars
  89. ▌
    Tlc Generative Engine Optimization · gabrielmoreira bundle
    Generative Engine Optimization (GEO) specialist — the technical, on-page publishing work that makes a given page or site discoverable, understandable, trustworthy, quotable, and fresh for AI answer engines (Google AI Overviews, ChatGPT Search, Bing Copilot, Perplexity). Use when asked to 'optimize this page/site for GEO', 'optimize for AI search / answer engines', 'get my page cited by ChatGPT/Perplexity', 'improve AI visibility/citability', 'write an llms.txt', 'add citation-ready structure or schema for AI answers', 'otimizar para busca com IA', or to audit/create/improve a codebase for generative search. Do NOT use for AI-driven SEO content strategy or programmatic pages at scale (use ai-seo), classic keyword/SERP ranking (use seo), accessibility (use web-accessibility), or multi-area site audits (use web-quality-audit).
    17 repo stars
  90. ▌
    Develop Flexible Bismuth Telluride · gabrielmoreira
    Develop and audit Bi2Te3-family flexible thermoelectric films and devices, including deposition or printing, composition and texture, substrate and interface mechanics, p/n integration, wearable thermal boundaries, bending reliability, metrology, and device benchmarking; use when Bi2Te3, Sb2Te3, flexible thin films, conformal generators, cooling patches, fibers, textiles, or bend-cycle failures are central.
    17 repo stars
  91. ▌
    Exploiting Format String Vulnerabilities · gabrielmoreira
    Methodology for exploiting format string bugs where attacker-controlled data reaches the format argument of printf-family functions, enabling stack/memory disclosure (info leaks for ASLR/PIE/canary defeat) and arbitrary write primitives (%n) to hijack control flow via GOT/.fini_array overwrites.
    17 repo stars
  92. ▌
    Analyzing Office365 Audit Logs For Compromise · gabrielmoreira
    Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
    17 repo stars
  93. ▌
    Auditing Azure Active Directory Configuration · gabrielmoreira
    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.
    17 repo stars
  94. ▌
    Configuring Host Based Intrusion Detection · gabrielmoreira
    Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Use when deploying OSSEC, Wazuh, or AIDE for endpoint monitoring, building file integrity monitoring (FIM) policies, or meeting compliance requirements for change detection. Activates for requests involving HIDS configuration, file integrity monitoring, OSSEC/Wazuh deployment, or host-based detection.
    17 repo stars
  95. ▌
    Exploiting Dbus And Socket Command Injection · gabrielmoreira
    Enumerating the D-Bus system bus and abusing root-exposed methods, policy and Polkit misconfigurations, and unix/abstract socket services for command injection and privilege escalation during authorized engagements, covering busctl/gdbus/dbus-send enumeration and exploitation plus root-owned UNIX socket abuse.
    17 repo stars
  96. ▌
    Analyzing Macro Malware In Office Documents · gabrielmoreira
    Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination.
    17 repo stars
  97. ▌
    Performing S7comm Protocol Security Analysis · gabrielmoreira
    Perform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers.
    17 repo stars
  98. ▌
    Exploiting SQL Injection Vulnerabilities · gabrielmoreira
    Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.
    17 repo stars
  99. ▌
    Detecting Business Email Compromise With AI · gabrielmoreira
    Deploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.
    17 repo stars
  100. ▌
    Building Threat Intelligence Feed Integration · gabrielmoreira
    Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.
    17 repo stars