gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Run Automation Suite · gabrielmoreiraRun local Appium test scripts against Kobiton devices. Guides through app upload, device selection, capability parsing, and local execution. Use when the user asks to run mobile tests, validate an APK or IPA on Kobiton devices, or kick off an Appium suite from a local script directory. Trigger with "run kobiton tests" or "execute appium on kobiton".
- ▌ Statistical Significance Calculator · gabrielmoreiraConfigure and manage - Calculate statistical significance calculator operations. Auto-activating skill for Data Analytics. Triggers on: statistical significance calculator, statistical significance calculator Part of the Data Analytics skill category. Use when working with statistical significance calculator functionality. Trigger with phrases like "statistical significance calculator", "statistical calculator", "statistical".
- ▌ Analyze Logistics Waste · gabrielmoreira bundleAnalyze logistics waste from process maps, movement, waiting, rework, defects, excess inventory, overprocessing, and source evidence.
- ▌ Research Canadian Material Handling Safety · gabrielmoreiraPrepare Canadian material-handling safety research briefs for warehouse movement, storage, lifting, traffic, and ergonomic risks.
- ▌ Research Canadian Powered Equipment Safety · gabrielmoreiraPrepare Canadian powered industrial equipment safety research briefs for forklifts, lift trucks, conveyors, AGVs, AMRs, and ASRS interfaces.
- ▌ Testing Simulink Models · gabrielmoreiraTests Simulink models using either ephemeral Gherkin-based tests (model_test) for quick validation or persistent tests (Simulink Test API) authored from requirements or behavioral specs. Requires Simulink Test.
- ▌ Implementing Data Loss Prevention With Microsoft Purview · gabrielmoreira bundleImplements DLP policies using Microsoft Purview PowerShell cmdlets and the Graph API to protect data across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and Power BI, including sensitivity labels, custom sensitive information types with regex, endpoint DLP rules, and Activity Explorer monitoring. Use when stopping PII/PHI/PCI exfiltration, configuring sensitivity labels, or investigating DLP incidents for policy tuning.
- ▌ Implementing Epss Score For Vulnerability Prioritization · gabrielmoreira bundleQueries FIRST's Exploit Prediction Scoring System (EPSS) API to fetch exploitation-probability and percentile scores for CVEs, then uses those scores to prioritize vulnerability remediation. Use when triaging or ranking a vulnerability backlog by real-world 30-day exploitation likelihood rather than CVSS severity alone.
- ▌ Large Excel Analysis And Formatting · gabrielmoreira用于处理多Sheet大型Excel文件,支持大文件Parquet格式转换提速,并使用openpyxl生成带条件高亮和自定义样式的格式化Excel报告及下载链接。
- ▌ Multi Sheet Reading And Analysis · gabrielmoreira用于读取多工作表Excel文件,动态评估数据量以启用Parquet大文件优化,并执行正则清洗、分类汇总、线性拟合及生成带格式的图表与结果文件。
- ▌ Dynamic Workflows · gabrielmoreiraDesigns and runs task-specific JavaScript harnesses with the `workflow` tool. Use for broad, long-running, highly structured, or adversarial work that benefits from many isolated agents: exhaustive audits, root-cause investigations, research, large triage queues, competing proposals, repeated verification, and independent changes across disjoint files. Covers decomposition patterns, agent and model routing, structured handoffs, failure handling, and the workflow runtime API.
- ▌ Exploiting Arbitrary Write To Execution · gabrielmoreiraMethodology for converting an arbitrary-write (write-what-where) or write-anything-anywhere primitive into code execution during authorized engagements, covering target selection among GOT/PLT entries, .fini_array/.dtors, __malloc_hook/__free_hook, the atexit/__exit_funcs handler list, and __printf_arginfo_table, plus how mitigations (Full RELRO, pointer mangling) change which target is viable and how to confirm hijacked control flow.
- ▌ Exploiting Linux Kernel Vulnerabilities · gabrielmoreiraMethodology for discovering and exploiting Linux kernel memory-corruption vulnerabilities (UAF, OOB read/write, race/TOCTOU, type confusion) during authorized engagements, covering reachability analysis, building stable read/write primitives from a single bug, defeating KASLR/SMEP/SMAP/KPTI, slab/buddy heap grooming, and pivoting to ring-0 code execution or credential overwrite for local privilege escalation.
- ▌ Performing Cloud Native Forensics With Falco · gabrielmoreiraUses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell spawns, file tampering, network anomalies, and privilege escalation. Manages Falco rules via the Falco gRPC API and parses Falco alert output. Use when building container runtime security or investigating k8s cluster compromises.
- ▌ Performing Post Quantum Cryptography Migration · gabrielmoreiraAssesses organizational readiness for post-quantum cryptography migration per NIST FIPS 203/204/205 standards. Performs cryptographic inventory scanning to identify quantum-vulnerable algorithms (RSA, ECDH, ECDSA), evaluates hybrid TLS configurations with X25519MLKEM768, and validates CRYSTALS-Kyber (ML-KEM) and CRYSTALS-Dilithium (ML-DSA) readiness. Implements crypto-agility assessment using oqs-provider for OpenSSL. Use when planning or executing the transition from classical to post-quantum cryptographic algorithms across enterprise infrastructure.
- ▌ Deploying Active Directory Honeytokens · gabrielmoreiraDeploys deception-based honeytokens in Active Directory including fake privileged accounts with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625, 4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for detecting lateral movement, credential theft, and reconnaissance.
- ▌ Implementing Aqua Security For Container Scanning · gabrielmoreiraDeploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
- ▌ Deploying Osquery For Endpoint Monitoring · gabrielmoreiraDeploys and configures osquery for real-time endpoint monitoring using SQL-based queries to inspect running processes, open ports, installed software, and system configuration. Use when building visibility into endpoint state, threat hunting across fleet, or implementing compliance monitoring. Activates for requests involving osquery deployment, endpoint visibility, fleet management, or SQL-based endpoint querying.
- ▌ Performing Service Account Audit · gabrielmoreiraAudit service accounts across enterprise infrastructure to identify orphaned, over-privileged, and non-compliant accounts. This skill covers discovery of service accounts in Active Directory, cloud pl
- ▌ Analyzing Ransomware Encryption Mechanisms · gabrielmoreiraAnalyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware cryptanalysis, encryption analysis, key recovery assessment, or ransomware decryption feasibility.
- ▌ Testing Android Intents For Vulnerabilities · gabrielmoreiraTests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection, unauthorized component access, broadcast sniffing, pending intent hijacking, and content provider data leakage. Use when assessing Android app attack surface through exported components, testing intent-based data flows, or evaluating IPC security. Activates for requests involving Android intent security, IPC testing, exported component analysis, or Drozer assessment.
- ▌ Performing Ot Vulnerability Scanning Safely · gabrielmoreiraPerform vulnerability scanning in OT/ICS environments safely using passive monitoring, native protocol queries, and carefully controlled active scanning with Tenable OT Security to identify vulnerabilities without disrupting industrial processes or crashing legacy controllers.
- ▌ Analyzing Web Server Logs For Intrusion · gabrielmoreiraParse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request frequency and response size outliers.
- ▌ Extracting Memory Artifacts With Rekall · gabrielmoreiraUses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and dlllist to extract forensic artifacts from Windows memory images. Use during incident response memory analysis.
- ▌ Implementing Security Chaos Engineering · gabrielmoreiraImplements security chaos engineering experiments that deliberately disable or degrade security controls to verify detection and response capabilities. Tests WAF bypass, firewall rule removal, log pipeline disruption, and EDR disablement scenarios using boto3 and subprocess. Use when validating SOC detection coverage and resilience.
- ▌ Hunting For Defense Evasion Via Timestomping · gabrielmoreiraDetect NTFS timestamp manipulation (MITRE T1070.006) by comparing $STANDARD_INFORMATION vs $FILE_NAME timestamps in the MFT. Uses analyzeMFT and Python to identify files with anomalous temporal patterns indicating anti-forensic timestomping activity.
- ▌ Performing Reflected File Download · gabrielmoreiraIdentifying and exploiting Reflected File Download (RFD) where an endpoint reflects attacker-controlled input into a downloadable response with an attacker-controlled filename and extension, enabling command execution on the victim's machine when the file is run.
- ▌ Graphical Abstract Generator · gabrielmoreiraConverts a biomedical study storyline into a graphical abstract and, when direct image capability is available, generates the graphical abstract directly; otherwise it falls back to prompts, Mermaid flowcharts, or designer-facing briefs.
- ▌ Title And Abstract Optimizer · gabrielmoreiraOptimizes manuscript titles and abstracts for information density, factual accuracy, and submission fit in biomedical research writing.
- ▌ Gsva Analysis And Visualization · gabrielmoreiraUse this skill to run GSVA or ssGSEA pathway-level differential analysis from a bulk expression matrix and a sample group file, then generate a heatmap from the saved GSVA result object. Trigger keywords: GSVA, ssGSEA, pathway enrichment, KEGG pathway analysis, MSigDB. NOT for: gene-level differential expression, single-cell analysis, methylation analysis, clinical diagnosis.
- ▌ Preprint Surveillance Finder · gabrielmoreiraTracks the latest preprints and emerging research topics related to your topic across bioRxiv, medRxiv, and arXiv. Use when a user wants to discover what is being published right now before it reaches journals, monitor competitor directions, spot new methodology trends, or get an early-warning scan of a research area. Triggers on phrases like "what's new in X", "latest preprints on Y", "emerging topics in Z", "monitor bioRxiv for", or "what are people working on in this field".
- ▌ Translational Study Blueprint · gabrielmoreiraDesigns a translational blueprint for moving a biomedical finding toward diagnosis, prognosis, treatment response prediction, patient stratification, or therapeutic development, with explicit translational milestones, validation thresholds, and feasibility-sensitive route framing.
- ▌ Case Control Study Quality Assessment Nos · gabrielmoreiraClinical Research Bias Assessment - Case-Control Study (NOS) v2.3.0. Use when you need to assess the bias of a case-control study using the Newcastle-Ottawa Scale (NOS) criteria, or when evaluating the quality of a medical paper.
- ▌
- ▌ Cherry Skill Marketplace · gabrielmoreira当用户明确要求搜索、安装、查看、卸载或创建 Skill,或内置 Skill / 工具出现能力缺口、无法完成当前任务时触发。通过 `mcp__skills__search_skills` 搜索并用 `mcp__skills__install_skill` 安装;已安装 Skill 的查看和删除通过产品清单导航到 Skills UI;没有合适结果时调用内置 `skill-creator` 创建并验证自定义 Skill,再继续原任务。普通任务仍先尝试内置能力。
- ▌ Resource Pool Optimizer · gabrielmoreiraOptimize shared resource pools across multiple construction projects. Balance resource allocation, minimize conflicts, and maximize utilization across the portfolio.
- ▌ Microsoft Graph API · gabrielmoreiraComprehensive Microsoft Graph API reference for M365 service integration
- ▌ Msal Authentication · gabrielmoreiraMicrosoft Authentication Library (MSAL) patterns for React/SPA applications with Entra ID
- ▌ Terminal Command Safety · gabrielmoreiraSafe terminal command patterns — backtick escaping, output capture, and hang prevention
- ▌ Universal Audit Pattern · gabrielmoreiraSystematic project audit pattern — version consistency, terminology, fact inventory, cross-references
- ▌ Coaching Techniques · gabrielmoreiraGROW model, active listening, developmental feedback, and team growth approaches
- ▌
- ▌ Deep Work Optimization · gabrielmoreiraFocus blocks, distraction management, and flow state triggers for cognitively demanding work
- ▌ Github Readme Override · gabrielmoreiraGitHub README display rules — which README renders when multiple exist, profile READMEs, org READMEs
- ▌ Draw Io Diagram Generator · gabrielmoreira bundleUse when creating, editing, or generating draw.io diagram files (.drawio, .drawio.svg, .drawio.png). Covers mxGraph XML authoring, shape libraries, style strings, flowcharts, system architecture, sequence diagrams, ER diagrams, UML class diagrams, network topology, layout strategy, the hediet.vscode-drawio VS Code extension, and the full agent workflow from request to a ready-to-open file.
- ▌ Brand Asset Management · gabrielmoreiraBrand hierarchy, visual identity, asset deployment, platform-specific branding guidelines
- ▌ Document Banner Pastel · gabrielmoreiraHand-authored pastel SVG banners for documentation — 1200×240 with content-specific iconography, complementary to algorithmic banner muscles
- ▌ Seek And Analyze Video · gabrielmoreiraSeek and analyze video content using Memories.ai Large Visual Memory Model for persistent video intelligence
- ▌ Node Winget Collision · gabrielmoreiraNode.js installed via winget collides with nvm — path priority, shim conflicts, resolution steps
- ▌ Pat Expiration Silent · gabrielmoreiraPersonal Access Token expiration fails silently — 401 errors with no expiry message, pre-check pattern
- ▌ Linkedin Post Formatter · gabrielmoreiraFormat and draft compelling LinkedIn posts using Unicode bold/italic styling, visual separators, structured sections, and engagement-optimized patterns. USE FOR: draft LinkedIn post, format text for LinkedIn, create social media post, write thought leadership post, convert content to LinkedIn format, LinkedIn carousel text, Unicode bold italic formatting.
- ▌ Distribution Security · gabrielmoreiraDefense-in-depth, PII protection, secrets scanning, and secure packaging for distributed software
- ▌ Subagent Orchestrator · gabrielmoreiraCoordinate quota-aware parallel subagents for large, multi-file Antigravity tasks.
- ▌ Buzz Hn · gabrielmoreiraHacker News post crafter — given a product, feature, or story produces a ready-to-post HN submission (title ≤80 chars, no marketing), honest body text with technical depth, no outbound links, predicted reception analysis, and comment-response templates for likely pushback. Use when asked to "write an HN post", "craft a Show HN", "prepare our Hacker News launch", or "help me post on HN".
- ▌ Blog Figure Svg · gabrielmoreiraStop using stock photos. Generate accessible, lightweight SVG figures for any blog or CMS - flow diagrams, comparison bar charts, taxonomy/Venn diagrams, annotated terminal mocks, and 1600x840 OG feature cards. Hand-authored SVG (no embedded fonts, no external assets, no AI-image latency) with a consistent palette, screen-reader metadata (title + desc + aria-labelledby), and a figcaption-required handoff to the writer. Rasterizes to compressed PNG ready for Ghost, WordPress, Webflow, or any static-site generator. Built for content marketers, indie hackers, and dev-tool blogs that want unique illustrations on every post without paying a designer or burning Midjourney credits. Trigger when the user says: 'add a figure to the post', 'illustrate this comparison', 'draw a flow diagram for X', 'make a feature/OG image', or any request to produce a chart/diagram for editorial use.
- ▌ SEO Blog Writer · gabrielmoreiraTurn a single long-tail query into a publish-ready blog post that ranks in search and gets quoted by AI assistants. Runs the full pipeline: classify the topic, research it against real sources, draft clean HTML, scrub LLM-tell vocabulary and typography, audit for AI-SEO (TL;DR block, query-phrased H2s, FAQ section, FAQPage + BreadcrumbList + HowTo JSON-LD), then publish through a platform adapter (Ghost Admin API, WordPress REST, or static-site file output). Platform-agnostic core; swap the publish step without rewriting the writing pipeline. Built for indie hackers, founders, and content marketers who want AI to draft posts that are actually citable - not paraphrased docs, not hallucinated benchmarks. Trigger when the user says: 'write a blog post on X', 'draft an article about X', 'publish a post on X to Ghost / WordPress / the static site', or any request to ship editorial content for a long-tail query.
- ▌ Algolia CI Integration · gabrielmoreiraConfigure Algolia CI/CD: GitHub Actions for index validation, automated reindexing on deploy, and integration testing against real Algolia indices. Trigger: "algolia CI", "algolia GitHub Actions", "algolia automated tests", "CI algolia", "algolia deploy pipeline".
- ▌ Attio Deploy Integration · gabrielmoreiraDeploy Attio integrations to Vercel, Fly.io, Railway, and Cloud Run with proper secrets, health checks, and webhook endpoint configuration. Trigger: "deploy attio", "attio Vercel", "attio production deploy", "attio Cloud Run", "attio Fly.io", "attio Railway".
- ▌ Attio Performance Tuning · gabrielmoreiraOptimize Attio API performance -- caching, batch queries, pagination strategies, connection pooling, and latency reduction. Trigger: "attio performance", "optimize attio", "attio slow", "attio latency", "attio caching", "attio batch requests".
- ▌ Clickup Local Dev Loop · gabrielmoreiraSet up local development for ClickUp API integrations with testing, mocking, and hot reload. Trigger: "clickup dev setup", "clickup local development", "clickup dev environment", "develop with clickup", "clickup testing setup", "mock clickup API".
- ▌ Cohere Incident Runbook · gabrielmoreiraExecute Cohere incident response procedures with triage, mitigation, and postmortem. Use when responding to Cohere API outages, investigating errors, or running post-incident reviews for Cohere integration failures. Trigger with phrases like "cohere incident", "cohere outage", "cohere down", "cohere on-call", "cohere emergency", "cohere broken".
- ▌ Exa Reference Architecture · gabrielmoreiraImplement Exa reference architecture for search pipelines, RAG, and content discovery. Use when designing new Exa integrations, reviewing project structure, or establishing architecture standards for neural search applications. Trigger with phrases like "exa architecture", "exa project structure", "exa RAG pipeline", "exa reference design", "exa search pipeline".
- ▌ Granola Local Dev Loop · gabrielmoreiraAccess Granola meeting data programmatically for developer workflows. Use when reading notes from the local cache, building MCP integrations, extracting action items into code, or syncing meeting outcomes to dev tools. Trigger: "granola dev workflow", "granola MCP", "granola local cache", "granola developer", "granola programmatic".
- ▌ Linear Incident Runbook · gabrielmoreiraProduction incident response procedures for Linear integrations. Use when handling production issues, diagnosing outages, or responding to Linear-related incidents. Trigger: "linear incident", "linear outage", "linear production issue", "debug linear production", "linear down", "linear 500".
- ▌ Posthog CI Integration · gabrielmoreiraConfigure PostHog CI/CD with GitHub Actions: unit tests with mocked PostHog, integration tests against a dev project, and deployment annotations. Trigger: "posthog CI", "posthog GitHub Actions", "posthog automated tests", "CI posthog", "posthog pipeline".
- ▌ Posthog Local Dev Loop · gabrielmoreiraConfigure PostHog local development with mocking, debug mode, and testing. Use when setting up a development environment, mocking PostHog for tests, or establishing a fast iteration cycle with posthog-js or posthog-node. Trigger: "posthog dev setup", "posthog local development", "posthog dev environment", "mock posthog", "test posthog".
- ▌ Posthog Prod Checklist · gabrielmoreiraProduction readiness checklist for PostHog integrations: SDK configuration, graceful degradation, health checks, shutdown hooks, and rollback procedures. Trigger: "posthog production", "deploy posthog", "posthog go-live", "posthog launch checklist", "posthog production ready".
- ▌ Serpapi CI Integration · gabrielmoreiraSet up CI/CD for SerpApi integrations with fixture-based testing. Use when automating SerpApi tests without consuming credits, or validating search result parsing in CI. Trigger: "serpapi CI", "serpapi GitHub Actions", "serpapi automated tests".
- ▌ Serpapi Local Dev Loop · gabrielmoreiraConfigure SerpApi local development with cached responses and test fixtures. Use when building search integrations, avoiding API calls during development, or setting up reproducible test data from SerpApi. Trigger: "serpapi dev setup", "serpapi local", "test serpapi locally".
- ▌ Serpapi Prod Checklist · gabrielmoreiraProduction readiness checklist for SerpApi integrations. Use when deploying search features, validating credit budgets, or preparing SerpApi-powered apps for launch. Trigger: "serpapi production", "deploy serpapi", "serpapi go-live".
- ▌ Together Sdk Patterns · gabrielmoreiraTogether AI sdk patterns for inference, fine-tuning, and model deployment. Use when working with Together AI's OpenAI-compatible API. Trigger: "together sdk patterns".
- ▌ Webflow CI Integration · gabrielmoreiraConfigure Webflow CI/CD with GitHub Actions — automated CMS validation, integration tests with test tokens, and publish-on-merge workflows. Use when setting up automated testing or CI pipelines for Webflow integrations. Trigger with phrases like "webflow CI", "webflow GitHub Actions", "webflow automated tests", "CI webflow", "webflow pipeline".
- ▌ Webflow Local Dev Loop · gabrielmoreiraConfigure a Webflow local development workflow with TypeScript, hot reload, mocked API tests, and webhook tunneling via ngrok. Use when setting up a development environment, configuring test workflows, or establishing a fast iteration cycle with the Webflow Data API. Trigger with phrases like "webflow dev setup", "webflow local development", "webflow dev environment", "develop with webflow".
- ▌ Webflow Prod Checklist · gabrielmoreiraExecute Webflow production deployment checklist — token security, rate limit hardening, health checks, circuit breakers, gradual rollout, and rollback procedures. Use when deploying Webflow integrations to production or preparing for launch. Trigger with phrases like "webflow production", "deploy webflow", "webflow go-live", "webflow launch checklist", "webflow production ready".
- ▌ Guidewire Observability And Incident Response · gabrielmoreira bundleOperate a Guidewire Cloud API integration in production — define SLIs/SLOs for token availability, bind success rate, FNOL p99 latency; route alerts so the on-call gets paged for real outages and never for transient noise; triage 401 spikes, 409 storms, 429 saturation, scope drift, and Gosu OOM cascades from signal to recovery in 15 minutes or less. Use when designing a dashboard for a new integration, writing the on-call runbook, or running a post-incident review. Trigger with "guidewire observability", "guidewire slo", "guidewire on-call", "guidewire 401 spike", "guidewire 409 storm", "guidewire incident".
- ▌ Governance Checklist Generator · gabrielmoreiraGenerate governance checklist generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: governance checklist generator, governance checklist generator Part of the Enterprise Workflows skill category. Use when working with governance checklist generator functionality. Trigger with phrases like "governance checklist generator", "governance generator", "governance".
- ▌ Design Logistics Unit Identification · gabrielmoreira bundleDesign source-backed logistics unit identification concepts across items, cases, cartons, pallets, locations, parties, shipments, and system handoffs.
- ▌ Diagnose Throughput Loss · gabrielmoreira bundleDiagnose logistics throughput loss from throughput gaps, queues, downtime, labor, equipment, process, and source evidence.
- ▌ Research Canadian Commercial Vehicle Safety · gabrielmoreiraPrepare Canadian commercial-vehicle safety research briefs for motor carrier, driver, vehicle, maintenance, and hours-of-service context.
- ▌ Research Us Material Handling Safety · gabrielmoreiraPrepare United States material-handling safety research briefs for warehouse movement, storage, lifting, traffic, and ergonomic risks.
- ▌ Research Us Powered Equipment Safety · gabrielmoreiraPrepare United States powered industrial truck and powered equipment safety research briefs for logistics operations.
- ▌ Deepmd Python Inference · gabrielmoreiraRun Python inference with DeePMD-kit models using the DeepPot API. Use when the user wants to load a trained/frozen DeePMD model (.pth or .pb) or a built-in pretrained model (e.g., DPA-3.2-5M) in Python, predict energy/force/virial for atomic configurations, evaluate descriptors, or calculate model deviation between multiple models. Also covers using `dp test` CLI for batch evaluation against labeled data.
- ▌ Eu AI Act Fria · gabrielmoreira bundleAssess whether a Fundamental Rights Impact Assessment (FRIA) is required under Article 27 EU AI Act, and structure or draft that assessment for a specific high-risk AI deployment. Covers deployer scope gating (public bodies and private entities providing public services), affected group mapping, Charter rights analysis, proportionality, safeguards evaluation, residual risk, DPIA/FRIA cross-referencing under the amended Article 27(4), the unconditional notification duty under Article 27(3), and DACH-specific considerations. Use when asked about FRIA obligations, Article 27 scope, fundamental rights and AI, or deployer assessment duties.
- ▌ Implementing Container Image Minimal Base With Distroless · gabrielmoreira bundleReduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using multi-stage build patterns plus debugging and scanning techniques adapted to distroless. Use when hardening container images, cutting attack surface in a container architecture, or answering an assessment finding about bloated base images. Keywords: distroless, multi-stage build, no shell, nonroot tag, debug image, scratch, attack surface. Do not use for scanning an image for known CVEs - use scanning-docker-images-with-trivy.
- ▌ Performing Cloud Native Threat Hunting With AWS Detective · gabrielmoreira bundleInvestigate AWS security incidents using Amazon Detective's behavior graphs, built from CloudTrail, VPC Flow Logs, GuardDuty, and EKS audit logs, to trace entity timelines and profile IAM users, roles, EC2 instances, and IP addresses for lateral movement. Use when triaging GuardDuty findings, investigating a suspected AWS compromise, or reconstructing an attacker's activity timeline across AWS accounts.
- ▌ Android Coroutines · gabrielmoreiraAuthoritative rules and patterns for production-quality Kotlin Coroutines onto Android. Covers structured concurrency, lifecycle integration, and reactive streams.
- ▌ Android Emulator Skill · gabrielmoreiraProduction-ready scripts for Android app testing, building, and automation. Provides semantic UI navigation, build automation, log monitoring, and emulator lifecycle management. Optimized for AI agents with minimal token output.
- ▌ Single Sheet Reading And Analysis · gabrielmoreira读取并解析单个Excel工作表数据,支持合并单元格处理、数据清洗、交叉分析及多维度可视化,适用于需要从单表中提取关键指标并进行趋势模拟与图表生成的场景。
- ▌ Tlc Generative Engine Optimization · gabrielmoreira bundleGenerative Engine Optimization (GEO) specialist — the technical, on-page publishing work that makes a given page or site discoverable, understandable, trustworthy, quotable, and fresh for AI answer engines (Google AI Overviews, ChatGPT Search, Bing Copilot, Perplexity). Use when asked to 'optimize this page/site for GEO', 'optimize for AI search / answer engines', 'get my page cited by ChatGPT/Perplexity', 'improve AI visibility/citability', 'write an llms.txt', 'add citation-ready structure or schema for AI answers', 'otimizar para busca com IA', or to audit/create/improve a codebase for generative search. Do NOT use for AI-driven SEO content strategy or programmatic pages at scale (use ai-seo), classic keyword/SERP ranking (use seo), accessibility (use web-accessibility), or multi-area site audits (use web-quality-audit).
- ▌ Develop Flexible Bismuth Telluride · gabrielmoreiraDevelop and audit Bi2Te3-family flexible thermoelectric films and devices, including deposition or printing, composition and texture, substrate and interface mechanics, p/n integration, wearable thermal boundaries, bending reliability, metrology, and device benchmarking; use when Bi2Te3, Sb2Te3, flexible thin films, conformal generators, cooling patches, fibers, textiles, or bend-cycle failures are central.
- ▌ Exploiting Format String Vulnerabilities · gabrielmoreiraMethodology for exploiting format string bugs where attacker-controlled data reaches the format argument of printf-family functions, enabling stack/memory disclosure (info leaks for ASLR/PIE/canary defeat) and arbitrary write primitives (%n) to hijack control flow via GOT/.fini_array overwrites.
- ▌ Analyzing Office365 Audit Logs For Compromise · gabrielmoreiraParse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
- ▌ Auditing Azure Active Directory Configuration · gabrielmoreiraAuditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Microsoft Graph API, and ScoutSuite.
- ▌ Configuring Host Based Intrusion Detection · gabrielmoreiraConfigures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations. Use when deploying OSSEC, Wazuh, or AIDE for endpoint monitoring, building file integrity monitoring (FIM) policies, or meeting compliance requirements for change detection. Activates for requests involving HIDS configuration, file integrity monitoring, OSSEC/Wazuh deployment, or host-based detection.
- ▌ Exploiting Dbus And Socket Command Injection · gabrielmoreiraEnumerating the D-Bus system bus and abusing root-exposed methods, policy and Polkit misconfigurations, and unix/abstract socket services for command injection and privilege escalation during authorized engagements, covering busctl/gdbus/dbus-send enumeration and exploitation plus root-owned UNIX socket abuse.
- ▌ Analyzing Macro Malware In Office Documents · gabrielmoreiraAnalyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download cradles, payload execution, persistence mechanisms, and anti-analysis techniques. Uses olevba, oledump, and VBA deobfuscation to extract the attack chain. Activates for requests involving Office macro analysis, VBA malware investigation, maldoc analysis, or document-based threat examination.
- ▌ Performing S7comm Protocol Security Analysis · gabrielmoreiraPerform security analysis of Siemens S7comm and S7CommPlus protocols used by SIMATIC S7 PLCs to identify vulnerabilities including replay attacks, integrity bypass, unauthorized CPU stop commands, and program download manipulation exploiting weaknesses in S7-300, S7-400, S7-1200, and S7-1500 controllers.
- ▌ Exploiting SQL Injection Vulnerabilities · gabrielmoreiraIdentifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.
- ▌ Detecting Business Email Compromise With AI · gabrielmoreiraDeploy AI and NLP-powered detection systems to identify business email compromise attacks by analyzing writing style, behavioral patterns, and contextual anomalies that evade traditional rule-based filters.
- ▌ Building Threat Intelligence Feed Integration · gabrielmoreiraBuilds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need to operationalize threat intelligence by automating feed ingestion, normalization, scoring, and distribution to detection systems.