gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Build Script Path Rot · gabrielmoreiraHardcoded paths in build scripts break when directory structure changes:
- ▌ Copilot Usage Metrics · gabrielmoreiraRetrieve and display GitHub Copilot usage metrics for organizations and enterprises using the GitHub CLI and REST API.
- ▌ Project Risk Analysis · gabrielmoreiraSystematic methodology for identifying, categorizing, and mitigating software project risks before implementation
- ▌ Hr People Operations · gabrielmoreiraTalent acquisition, employee lifecycle, compensation, labor regulations, and organizational development.
- ▌ Create Associate Nsg · gabrielmoreiraCreates a new Network Security Group and associates it with the specified subnets and/or NICs of a Virtual Network.
- ▌ Visual Vocabulary · gabrielmoreiraChart catalog organized by communication goal, CSAR evaluation loop for AI-generated charts, 5-visual rule, override decision framework, and living gallery references
- ▌ Managing Autonomous Development · gabrielmoreiraExecute enables AI assistant to manage sugar's autonomous development workflows. it allows AI assistant to create tasks, view the status of the system, review pending tasks, and start autonomous execution mode. use this skill when the user asks to create a new develo... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
- ▌ Python Tooling · gabrielmoreiraUse when managing Python packages, virtual environments, or linting and formatting Python code
- ▌ Strategic Clarity · gabrielmoreiraGuided workflow for establishing team identity, boundaries, and strategic clarity. Use when starting a new role, inheriting ambiguity, when a team lacks clear identity, or when you need to define "what we own" vs "what we don't". Triggers include "strategic clarity", "team identity", "new role", "inherited ambiguity", "what does my team own", or "define our boundaries".
- ▌ Abridge Sdk Patterns · gabrielmoreiraApply production-ready patterns for Abridge clinical AI integration. Use when building reusable Abridge client wrappers, implementing HIPAA-compliant error handling, or establishing team coding standards for healthcare AI. Trigger: "abridge SDK patterns", "abridge best practices", "abridge code patterns".
- ▌ Algolia Sdk Patterns · gabrielmoreiraApply production-ready algoliasearch v5 patterns: singleton client, typed search, error handling, and batch operations. Use when implementing Algolia integrations, refactoring SDK usage, or establishing team coding standards. Trigger: "algolia SDK patterns", "algolia best practices", "algolia code patterns", "idiomatic algolia".
- ▌ Clickup Sdk Patterns · gabrielmoreiraProduction-ready ClickUp API v2 client patterns with typed wrappers, error handling, caching, and multi-tenant support. Trigger: "clickup client wrapper", "clickup SDK patterns", "clickup best practices", "clickup typescript client", "clickup API wrapper", "production clickup code".
- ▌ Cohere CI Integration · gabrielmoreiraConfigure CI/CD for Cohere integrations with GitHub Actions and automated testing. Use when setting up automated testing for Chat/Embed/Rerank, configuring CI pipelines, or testing Cohere-powered applications. Trigger with phrases like "cohere CI", "cohere GitHub Actions", "cohere automated tests", "CI cohere", "cohere pipeline".
- ▌ Granola Sdk Patterns · gabrielmoreiraZapier automation patterns and Enterprise API integration for Granola. Use when building automated workflows, connecting Granola to 8,000+ apps via Zapier, or querying the Enterprise API for notes and transcripts. Trigger: "granola zapier", "granola automation", "granola API", "granola SDK".
- ▌ Linear CI Integration · gabrielmoreiraIntegrate Linear with GitHub Actions CI/CD pipelines. Use when setting up automated testing, PR-to-issue linking, or creating Linear issues from CI failures. Trigger: "linear CI", "linear GitHub Actions", "linear CI/CD", "linear automated tests", "linear PR integration".
- ▌ Linear Local Dev Loop · gabrielmoreiraSet up local Linear development environment and testing workflow. Use when configuring local dev, testing integrations, or setting up a development workflow with Linear webhooks. Trigger: "linear local development", "linear dev setup", "test linear locally", "linear development environment".
- ▌ Linear Prod Checklist · gabrielmoreiraProduction readiness checklist for Linear integrations. Use when preparing to deploy, reviewing production requirements, or auditing existing Linear deployments. Trigger: "linear production checklist", "deploy linear", "linear production ready", "linear go live", "linear launch".
- ▌ Miro Deploy Integration · gabrielmoreiraDeploy Miro REST API v2 integrations to Vercel, Fly.io, and Cloud Run with proper OAuth token management and webhook configuration. Trigger with phrases like "deploy miro", "miro Vercel", "miro production deploy", "miro Cloud Run", "miro Fly.io".
- ▌ Posthog Sdk Patterns · gabrielmoreiraProduction-ready PostHog SDK patterns: singleton client, typed events, React hooks, Next.js App Router integration, and Python patterns. Trigger: "posthog SDK patterns", "posthog best practices", "posthog React hook", "posthog Next.js", "posthog typescript".
- ▌ Serpapi Sdk Patterns · gabrielmoreiraProduction-ready SerpApi client patterns with caching, typing, and multi-engine support. Use when building search services, implementing result caching, or wrapping SerpApi with typed responses. Trigger: "serpapi patterns", "serpapi best practices", "serpapi client wrapper".
- ▌ Vercel Edge Functions · gabrielmoreiraBuild and deploy Vercel Edge Functions for ultra-low latency at the edge. Use when creating API routes with minimal latency, geolocation-based routing, A/B testing, or authentication at the edge. Trigger with phrases like "vercel edge function", "vercel edge runtime", "deploy edge function", "vercel middleware", "@vercel/edge".
- ▌ Webflow Debug Bundle · gabrielmoreiraCollect Webflow debug evidence for support tickets and troubleshooting. Gathers SDK version, token validation, rate limit status, site connectivity, CMS health, and error logs into a single diagnostic bundle. Trigger with phrases like "webflow debug", "webflow support bundle", "collect webflow logs", "webflow diagnostic", "webflow troubleshoot".
- ▌ Webflow Sdk Patterns · gabrielmoreiraApply production-ready Webflow SDK patterns — singleton client, typed error handling, pagination helpers, and raw response access for the webflow-api package. Use when implementing Webflow integrations, refactoring SDK usage, or establishing team coding standards. Trigger with phrases like "webflow SDK patterns", "webflow best practices", "webflow code patterns", "idiomatic webflow", "webflow typescript".
- ▌ Windsurf Load Scale · gabrielmoreiraScale Windsurf adoption across large organizations with workspace strategies and performance tuning. Use when rolling out Windsurf to 50+ developers, managing large monorepo workspaces, or planning enterprise-scale deployment. Trigger with phrases like "windsurf at scale", "windsurf large team", "windsurf monorepo", "windsurf organization", "windsurf 100 developers".
- ▌ Hardcoded Credential Finder · gabrielmoreiraManage hardcoded credential finder operations. Auto-activating skill for Security Fundamentals. Triggers on: hardcoded credential finder, hardcoded credential finder Part of the Security Fundamentals skill category. Use when working with hardcoded credential finder functionality. Trigger with phrases like "hardcoded credential finder", "hardcoded finder", "hardcoded".
- ▌ Definition Of Done Generator · gabrielmoreiraGenerate definition of done generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: definition of done generator, definition of done generator Part of the Enterprise Workflows skill category. Use when working with definition of done generator functionality. Trigger with phrases like "definition of done generator", "definition generator", "definition".
- ▌ Classify Material Handling Requirements · gabrielmoreira bundleClassify material handling requirements from load, dimensions, volume, distance, throughput, environment, and safety constraints.
- ▌ Analyze Warehouse Kpis · gabrielmoreira bundleAnalyze warehouse KPI data, targets, trends, variance, exceptions, and operational implications with source and unit discipline.
- ▌ Identify Us Logistics Jurisdiction · gabrielmoreiraIdentify federal, state, territorial, modal, product, workplace, and activity jurisdiction for United States logistics research.
- ▌ Research Us Import Export Controls · gabrielmoreiraPrepare CBP-centered United States import and export research briefs for logistics evidence, documentation, release, reporting, and broker review.
- ▌ Manage Safety Analysis · gabrielmoreiraCreate, populate, and manage safety analysis spreadsheets (FMEA, FHA, HARA, custom) and fault trees (FTA) in Safety Analysis Manager. Use when the user asks to perform FMEA, hazard analysis, fault tree analysis, safety analysis, or work with Safety Analysis Manager documents. Requires Simulink Fault Analyzer.
- ▌ Implementing Deception Based Detection With Canarytoken · gabrielmoreira bundleDeploys and monitors Canary Tokens via the Thinkst Canary REST API for deception-based breach detection, programmatically creating web bug, DNS, MS Word document, and AWS API key tokens and generating deception coverage reports from triggered alerts. Use when standing up honeytoken tripwires for early breach detection or building a deception-technology coverage report.
- ▌ Implementing Github Advanced Security For Code Scanning · gabrielmoreira bundleConfigures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across repositories at enterprise scale, including custom CodeQL queries and CI workflow integration. Use when setting up or tuning code scanning, rolling out CodeQL across an organization, or shifting SAST left into pull request workflows.
- ▌ Implementing Network Intrusion Prevention With Suricata · gabrielmoreira bundleDeploys and configures Suricata as an inline network intrusion prevention system, covering IPS mode setup (NFQueue), custom rule writing, Emerging Threats ruleset management, performance tuning, and logging integration. Use when deploying real-time inline traffic inspection to actively block malicious traffic, or when tuning Suricata rules and performance for production IDS/IPS deployment.
- ▌ Implementing Privileged Access Management With Cyberark · gabrielmoreira bundleDeploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure, covering vault architecture, session isolation, credential rotation policies, and integration with NIST 800-53 access control requirements. Use when standing up CyberArk PAM, vaulting privileged credentials, or designing credential rotation policies.
- ▌ Android Retrofit · gabrielmoreiraExpert guidance on setting up and using Retrofit for type-safe HTTP networking in Android. Covers service definitions, coroutines, OkHttp configuration, and Hilt integration.
- ▌ Multi File Excel Parquet Analysis · gabrielmoreira读取多 Sheet Excel 文件并统计规模,支持大文件向 Parquet 格式转换、分类数据统计及可视化报告生成。
- ▌ Performing AI Assisted Vulnerability Discovery · gabrielmoreiraUsing LLMs to accelerate vulnerability research and pentest workflows — generating syntax-valid fuzzing seeds and evolving grammars, fine-tuned mutation dictionaries, parallel agent-based proof-of-vulnerability generation, and evidence-driven passive analysis of real HTTP traffic via the Burp MCP server. Covers concrete prompts, AFL++/ libFuzzer wiring, and Burp+Codex/Gemini/Ollama MCP setup.
- ▌ Performing Return Oriented Programming · gabrielmoreiraMethodology for building Return-Oriented Programming (ROP) chains to bypass NX/DEP by reusing existing code gadgets, covering gadget discovery, calling-convention argument setup, ret2libc, ret2syscall (execve), one_gadget, stack alignment, JOP, and stack pivoting across x86/x64/ARM64 during authorized engagements.
- ▌ Performing Windows Binary Exploitation · gabrielmoreiraMethodology for exploiting classic 32-bit Windows stack buffer overflows in network services during authorized engagements (OSCP-level), covering crash reproduction, EIP offset discovery with pattern_create/pattern_offset, shellcode space and bad-character enumeration, locating a reliable JMP ESP return address with mona.py, and delivering an msfvenom payload to gain remote code execution.
- ▌ Performing Cryptographic Audit Of Application · gabrielmoreiraA cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco
- ▌ Analyzing Linux Audit Logs For Intrusion · gabrielmoreiraUses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized access, privilege escalation, and suspicious system activity. Covers audit rule configuration, log querying, timeline reconstruction, and integration with SIEM platforms. Activates for requests involving auditd analysis, Linux audit log investigation, ausearch queries, aureport summaries, or host-based intrusion detection on Linux.
- ▌ Conducting Post Incident Lessons Learned · gabrielmoreiraFacilitate structured post-incident reviews to identify root causes, document what worked and failed, and produce actionable recommendations to improve future incident response.
- ▌ Exploiting Insecure Data Storage In Mobile · gabrielmoreiraIdentifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements. Activates for requests involving mobile data storage security, local storage exploitation, SharedPreferences analysis, or mobile data leakage assessment.
- ▌ Implementing Mobile Application Management · gabrielmoreiraImplements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security.
- ▌ Intercepting Mobile Traffic With Burpsuite · gabrielmoreiraIntercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure API communications, authentication flaws, data leakage, and server-side vulnerabilities. Use when performing mobile application penetration testing, assessing API security, or evaluating client-server communication patterns. Activates for requests involving mobile traffic interception, Burp Suite mobile proxy, API security testing, or mobile HTTPS analysis.
- ▌ Performing Dynamic Analysis Of Android App · gabrielmoreiraPerforms runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime values, and identify vulnerabilities that static analysis misses. Use when testing Android apps for runtime security flaws, hooking sensitive methods, bypassing client-side protections, or analyzing obfuscated applications. Activates for requests involving Android dynamic analysis, runtime hooking, Frida Android instrumentation, or live app behavior analysis.
- ▌ Conducting Mobile App Penetration Test · gabrielmoreiraConducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment.
- ▌ Executing Phishing Simulation Campaign · gabrielmoreiraExecutes authorized phishing simulation campaigns to assess an organization's susceptibility to email-based social engineering attacks. The tester designs realistic phishing scenarios, builds credential harvesting infrastructure, sends targeted phishing emails, and tracks open rates, click-through rates, and credential submission rates to measure human security awareness. Activates for requests involving phishing simulation, social engineering assessment, email security testing, or security awareness measurement.
- ▌ Performing Internal Network Pentesting · gabrielmoreiraMethodology for internal network penetration testing from a foothold on the LAN, covering host discovery, port scanning, passive/active sniffing, MitM (ARP/DNS/ICMP/DHCPv6), and LLMNR/NBT-NS/mDNS poisoning with Responder plus relay attacks during authorized engagements.
- ▌ Detecting Beaconing Patterns With Zeek · gabrielmoreiraPerforms statistical analysis of Zeek conn.log connection intervals to detect C2 beaconing patterns. Uses the ZAT library to load Zeek logs into Pandas DataFrames, calculates inter-arrival time standard deviation, and flags periodic connections with low jitter. Use when hunting for command-and-control callbacks in network data.
- ▌ Implementing Ticketing System For Incidents · gabrielmoreiraImplements an integrated incident ticketing system connecting SIEM alerts to ServiceNow, Jira, or TheHive for structured incident tracking, SLA management, escalation workflows, and compliance documentation. Use when SOC teams need formalized incident lifecycle management with automated ticket creation, assignment routing, and resolution tracking.
- ▌ Ga4 Bigquery Export · gabrielmoreiraWire GA4 → BigQuery for unsampled, queryable event-level data. Covers the one-time export setup, the events_YYYYMMDD table schema, partitioning + clustering, and the SQL patterns for the reports the Data API can't do well (true cohort retention, custom-event attribution, large date ranges). Trigger with "GA4 BigQuery", "GA4 to BQ", "event-level GA4 data", "unsampled GA4", "GA4 export setup", "GA4 SQL".
- ▌ Miro Data Handling · gabrielmoreiraImplement Miro REST API v2 data handling with PII detection in board content, data export via API, retention policies, and GDPR/CCPA compliance patterns. Trigger with phrases like "miro data", "miro PII", "miro GDPR", "miro data export", "miro privacy", "miro compliance".
- ▌ Miro Observability · gabrielmoreiraSet up observability for Miro REST API v2 integrations with Prometheus metrics, OpenTelemetry traces, structured logging, and Grafana dashboards. Trigger with phrases like "miro monitoring", "miro metrics", "miro observability", "monitor miro", "miro alerts", "miro tracing".
- ▌ Optimizing Database Connection Pooling · gabrielmoreira bundleProcess use when you need to work with connection management. This skill provides connection pooling and management with comprehensive guidance and automation. Trigger with phrases like "manage connections", "configure pooling", or "optimize connection usage".
- ▌ Kubernetes Configmap Handler · gabrielmoreiraConfigure kubernetes configmap handler operations. Auto-activating skill for DevOps Advanced. Triggers on: kubernetes configmap handler, kubernetes configmap handler Part of the DevOps Advanced skill category. Use when configuring systems or services. Trigger with phrases like "kubernetes configmap handler", "kubernetes handler", "kubernetes".
- ▌ SQL Injection Detector · gabrielmoreiraDetect sql injection detector operations. Auto-activating skill for Security Fundamentals. Triggers on: sql injection detector, sql injection detector Part of the Security Fundamentals skill category. Use when working with sql injection detector functionality. Trigger with phrases like "sql injection detector", "sql detector", "sql".
- ▌ Container Security Auditor · gabrielmoreiraAudit container security auditor operations. Auto-activating skill for Security Advanced. Triggers on: container security auditor, container security auditor Part of the Security Advanced skill category. Use when analyzing or auditing container security auditor. Trigger with phrases like "container security auditor", "container auditor", "container".
- ▌ Encryption At REST Checker · gabrielmoreiraValidate encryption at rest checker operations. Auto-activating skill for Security Advanced. Triggers on: encryption at rest checker, encryption at rest checker Part of the Security Advanced skill category. Use when working with encryption at rest checker functionality. Trigger with phrases like "encryption at rest checker", "encryption checker", "encryption".
- ▌ Connection Pool Analyzer · gabrielmoreiraAnalyze connection pool analyzer operations. Auto-activating skill for Performance Testing. Triggers on: connection pool analyzer, connection pool analyzer Part of the Performance Testing skill category. Use when analyzing or auditing connection pool analyzer. Trigger with phrases like "connection pool analyzer", "connection analyzer", "analyze connection pool r".
- ▌ Gatling Scenario Creator · gabrielmoreiraCreate gatling scenario creator operations. Auto-activating skill for Performance Testing. Triggers on: gatling scenario creator, gatling scenario creator Part of the Performance Testing skill category. Use when working with gatling scenario creator functionality. Trigger with phrases like "gatling scenario creator", "gatling creator", "gatling".
- ▌ Jmeter Test Plan Creator · gabrielmoreiraCreate jmeter test plan creator operations. Auto-activating skill for Performance Testing. Triggers on: jmeter test plan creator, jmeter test plan creator Part of the Performance Testing skill category. Use when writing or running tests. Trigger with phrases like "jmeter test plan creator", "jmeter creator", "jmeter".
- ▌ Troubleshooting Guide Creator · gabrielmoreiraCreate troubleshooting guide creator operations. Auto-activating skill for Technical Documentation. Triggers on: troubleshooting guide creator, troubleshooting guide creator Part of the Technical Documentation skill category. Use when working with troubleshooting guide creator functionality. Trigger with phrases like "troubleshooting guide creator", "troubleshooting creator", "troubleshooting".
- ▌ Mermaid Gantt Chart Generator · gabrielmoreiraGenerate mermaid gantt chart generator operations. Auto-activating skill for Visual Content. Triggers on: mermaid gantt chart generator, mermaid gantt chart generator Part of the Visual Content skill category. Use when working with mermaid gantt chart generator functionality. Trigger with phrases like "mermaid gantt chart generator", "mermaid generator", "mermaid".
- ▌ Mermaid State Diagram Creator · gabrielmoreiraCreate mermaid state diagram creator operations. Auto-activating skill for Visual Content. Triggers on: mermaid state diagram creator, mermaid state diagram creator Part of the Visual Content skill category. Use when working with mermaid state diagram creator functionality. Trigger with phrases like "mermaid state diagram creator", "mermaid creator", "mermaid".
- ▌ Email Template Generator · gabrielmoreiraGenerate email template generator operations. Auto-activating skill for Business Automation. Triggers on: email template generator, email template generator Part of the Business Automation skill category. Use when working with email template generator functionality. Trigger with phrases like "email template generator", "email generator", "email".
- ▌ Google Sheets Automation · gabrielmoreiraManage google sheets automation operations. Auto-activating skill for Business Automation. Triggers on: google sheets automation, google sheets automation Part of the Business Automation skill category. Use when working with google sheets automation functionality. Trigger with phrases like "google sheets automation", "google automation", "google".
- ▌ Meeting Scheduler Helper · gabrielmoreiraConfigure with meeting scheduler helper operations. Auto-activating skill for Business Automation. Triggers on: meeting scheduler helper, meeting scheduler helper Part of the Business Automation skill category. Use when working with meeting scheduler helper functionality. Trigger with phrases like "meeting scheduler helper", "meeting helper", "meeting".
- ▌ Risk Assessment Creator · gabrielmoreiraCreate risk assessment creator operations. Auto-activating skill for Enterprise Workflows. Triggers on: risk assessment creator, risk assessment creator Part of the Enterprise Workflows skill category. Use when working with risk assessment creator functionality. Trigger with phrases like "risk assessment creator", "risk creator", "risk".
- ▌ Forecast Warehouse Workload · gabrielmoreira bundleForecast warehouse workload from orders, receipts, SKU mix, seasonality, backlog, service windows, and source evidence.
- ▌ Analyze Logistics Scan Events · gabrielmoreira bundleAnalyze logistics scan events across devices, labels, locations, users, timestamps, process steps, and source systems.
- ▌ Design Logistics Barcode Flow · gabrielmoreira bundleDesign logistics barcode and scan-flow concepts for process steps, identifiers, labels, validation points, exceptions, and system handoffs.
- ▌ Validate Location Master Data · gabrielmoreira bundleValidate logistics location master data for location type, zone, status, capacity, dimensions, restrictions, pickability, and source-system alignment.
- ▌ Select Material Handling Equipment · gabrielmoreira bundleCompare material handling equipment classes from handling requirements, facility constraints, labor, safety, and capital intensity.
- ▌ Calculate Replenishment Demand · gabrielmoreira bundleCalculate replenishment demand from order forecast, pick-face inventory, capacity, service window, and pack constraints.
- ▌ Eu AI Act Report Oliver Schmidt Prietz · gabrielmoreira bundleGenerates a formal, structured AI Act compliance assessment report suitable for legal files, audit trails, and regulatory inquiries. This skill should be used when the user asks to "generate an AI Act report", "create a compliance assessment report", "document the AI Act analysis", "create a Prüfbericht", "export as Word document", or wants to consolidate prior AI Act skill outputs into a formal documented assessment.
- ▌ Managing Simulink Projects · gabrielmoreiraManages MATLAB projects for Simulink workflows: path management, file registration, labels, source control configuration, and project lifecycle. Use when creating projects, adding models/dictionaries/requirements to projects, configuring labels for automation, fixing broken model references, or setting up source control for Simulink artifacts.
- ▌ Simulating Simulink Models · gabrielmoreiraConfigures Simulink simulations non-destructively using SimulationInput objects — parameter overrides without modifying the model, batch sweeps via parsim, custom input signals via Dataset, and simulation data retrieval via logsout. Use when running sim()/parsim() with setVariable, setBlockParameter, setExternalInput, or when performing parameter sweeps and multi-run analysis. Not needed for one-shot simulations without configuration.
- ▌ Analyzing Email Headers For Phishing Investigation · gabrielmoreira bundleParse and analyze email headers (Received chain, Return-Path, Message-ID) to trace the true origin of a phishing email and validate SPF, DKIM, and DMARC results to confirm or rule out sender spoofing. Use when triaging a suspicious or reported email, investigating a phishing incident, or verifying whether a message's sender domain was spoofed.
- ▌ Collecting Volatile Evidence From Compromised Host · gabrielmoreira bundleCollect volatile forensic evidence from a compromised host by following the order of volatility, preserving memory, network connections, running processes, and system state with documented chain of custody before they are lost. Use before isolating, shutting down, or remediating a compromised host, especially when fileless or memory-resident malware is suspected, root cause analysis is needed, or the evidence must hold up in legal proceedings.
- ▌ Detecting Dns Exfiltration With Dns Query Analysis · gabrielmoreira bundleDetect data exfiltration via DNS tunneling (tools like iodine, dnscat2, dns2tcp) by analyzing query entropy, subdomain length, query volume to single domains, TXT/CNAME/NULL record abuse, and oversized response payloads using passive DNS monitoring and statistical/ML methods. Use when hunting for covert DNS-based data exfiltration or building a passive DNS anomaly detection capability.
- ▌ Implementing Conduit Security For Ot Remote Access · gabrielmoreira bundleImplements secure conduit architecture for OT remote access under the IEC 62443 zones-and-conduits model, deploying jump servers, MFA gateways, session recording, and approval-based workflows for vendor and engineer access to ICS. Use when replacing direct VPN access into OT networks, securing third-party vendor access to SCADA equipment, or remediating audit findings on uncontrolled OT remote access.
- ▌ Implementing Fuzz Testing In Cicd With Aflplusplus · gabrielmoreira bundleIntegrates AFL++ coverage-guided fuzzing into CI/CD pipelines, covering harness construction, AFL++/AddressSanitizer/CmpLog instrumentation builds, and persistent-mode fuzzing to discover memory-corruption and input-handling vulnerabilities in C/C++ code. Use when adding automated fuzz testing to a build pipeline or hunting for memory-safety bugs in native/compiled applications.
- ▌ Implementing Kubernetes Network Policy With Calico · gabrielmoreira bundleInstalls Calico as the cluster CNI and writes standard Kubernetes NetworkPolicy under it, covering default-deny baselines, policy ordering and precedence, service-account-based selectors, and verifying that policy is genuinely being enforced. Use when adopting Calico as the enforcement CNI, establishing a default-deny baseline, or debugging why a NetworkPolicy is not taking effect under Calico. Keywords: Calico CNI, NetworkPolicy, default deny, policy order, Felix, service account selector. Do not use for Calico-only CRDs such as GlobalNetworkPolicy or DNS egress - use implementing-container-network-policies-with-calico; for CNI-agnostic policy use implementing-network-policies-for-kubernetes.
- ▌ Implementing Network Access Control With Cisco Ise · gabrielmoreira bundleDeploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X wired and wireless authentication, MAC Authentication Bypass, posture assessment, dynamic VLAN assignment, downloadable ACLs, and TrustSec Security Group Tags. Use when deploying enterprise NAC with ISE and Active Directory integration, enforcing endpoint posture compliance, or segmenting access with TrustSec instead of a generic 802.1X/PacketFence setup.
- ▌ Implementing Opa Gatekeeper For Policy Enforcement · gabrielmoreira bundleDeploys OPA Gatekeeper via Helm as a Kubernetes admission controller and writes ConstraintTemplates with Rego plus instantiated Constraints to validate, mutate, or deny resource requests at admission time. Use when enforcing custom policy-as-code at admission on Kubernetes v1.24+, blocking non-compliant workloads before scheduling, or expressing a rule that built-in controls cannot. Keywords: Gatekeeper, ConstraintTemplate, Constraint, Rego, admission webhook, audit, mutation. Do not use for the standard pod security profiles that Pod Security Admission already covers - use implementing-pod-security-admission-controller.
- ▌ Implementing Policy As Code With Open Policy Agent · gabrielmoreira bundleImplements policy-as-code enforcement with Open Policy Agent (OPA) and Gatekeeper for Kubernetes and CI/CD pipelines, covering writing Rego policies, deploying OPA Gatekeeper as a Kubernetes admission controller, testing policies in development, and integrating policy evaluation into deployment pipelines. Use when writing Rego policies, deploying Gatekeeper admission control, or gating CI/CD pipelines with policy-as-code checks.
- ▌ Implementing Zero Standing Privilege With Cyberark · gabrielmoreira bundleDeploy CyberArk Secure Cloud Access (SCA) to eliminate standing privileges in AWS, Azure, and GCP by provisioning ephemeral, scoped roles on a just-in-time basis governed by the TEA framework (Time, Entitlements, Approvals). Use when designing or implementing zero standing privilege / just-in-time privileged access models with CyberArk, or when replacing persistent cloud admin roles with time-bound, approval-gated sessions.
- ▌ Performing Log Analysis For Forensic Investigation · gabrielmoreira bundleCollect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
- ▌ Performing Malware Hash Enrichment With Virustotal · gabrielmoreira bundleEnrich malware file hashes (MD5, SHA-1, SHA-256) using the VirusTotal API v3 to retrieve multi-engine detection rates, sandbox behavioral analysis, YARA rule matches, related indicators, and community threat intelligence. Use during SOC triage, incident response, or threat intelligence workflows to validate whether a file hash is malicious and gather context for IOC enrichment.
- ▌ Performing Mobile Device Forensics With Cellebrite · gabrielmoreira bundleAcquire and analyze mobile device data using Cellebrite UFED Touch/4PC, UFED Physical Analyzer, and open-source alternatives (ALEAPP, iLEAPP, MEAT, libimobiledevice) to extract communications, call logs, location data, and application artifacts. Use when extracting or recovering deleted evidence from smartphones or tablets during criminal, corporate, or employee-misuse investigations.
- ▌ Android Gradle Logic · gabrielmoreiraExpert guidance on setting up scalable Gradle build logic using Convention Plugins and Version Catalogs.
- ▌ Android Testing · gabrielmoreiraComprehensive testing strategy involving Unit, Integration, Hilt, and Screenshot tests.
- ▌ Range Reading And Large File Analysis · gabrielmoreira读取多 Sheet Excel 文件,根据数据量动态选择处理策略,支持特定区域数据提取、大文件 Parquet 转换、统计分析及可视化图表生成。
- ▌ Turning Engineering Analytics Into Insights · gabrielmoreiraConverts engineering analytics (PR / CI) data into saved PostHog insights, dashboards, and subscriptions, and explains how to query the product data directly with SQL. Covers discovering per-team GitHub warehouse tables via engineering-analytics-sources, replicating curated column semantics in HogQL, reading exposed engineering_analytics_* warehouse views where product logic is involved (CI cost, fingerprinted failure lines, commit attribution), saving queries with insight-create, and scheduling delivery with subscriptions-create. Use when asked to "save this as an insight", "put CI health / merge times on a dashboard", "email me PR throughput weekly", "chart CI cost", "track time to first review", "subscribe to these numbers", "alert on CI success rate", or "what data/tables/views does engineering analytics read". For ad-hoc CI and merge questions use diagnosing-ci-and-merge-bottlenecks; to investigate one specific CI failure use investigating-ci-failures.
- ▌ Sglang Diffusion Benchmark Profile · gabrielmoreira bundleUse when benchmarking denoise latency or profiling a diffusion bottleneck in SGLang.
- ▌ Smart Data Analysis · gabrielmoreira数据分析员工(Data Analyst Agent)的唯一总入口:凡与数据资产、取数、指标、表/视图、 治理职责、知识网络、统计或分析相关的问题,必须先经本 skill 做编排与路由,再进入找表或问数等子流程。 负责 kn 分域、上下文注入(accountId / date)、多候选 KN 时的 LLM 决策、 问数分支的 SQL 生成;与 smart-search-tables / smart-ask-data / ontology-core 的交接。 当用户提出任何数据类自然语言任务、或需在多条业务 KN 间切换时使用; 所有 ontology CLI 执行均委托 ontology-core 完成,本 skill 不直接执行 CLI。
- ▌ Smart Search Tables · gabrielmoreira找表/找数端到端编排:在元数据型知识网络下用 ontology bkn object-type query 检索表/视图实例, 再在职责型知识网络下检索相关部门职责与治理边界,最后汇总为中文结论 (候选表 + 职责要点 + 下一步)。当用户问「表在哪、哪个视图、数据资产归属、谁负责这类数据」时使用。 所有 ontology CLI 执行均委托 ontology-core 完成;本 skill 不直接执行 CLI。
- ▌ AI Coding Agents Observability Evals · gabrielmoreiraDesigns coding-agent observability and evals. Use when measuring traces, replay, checkpoint lineage, quality trajectories, tool grading, regression, or cost.