gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Exploiting Stack Buffer Overflows · gabrielmoreiraMethodology for discovering and exploiting stack-based buffer overflows in native binaries during authorized engagements, covering crash triage, offset discovery with De Bruijn patterns, control of the saved return address, and escalation paths (ret2win, stack shellcode, ROP) depending on which mitigations are present.
- ▌ Detecting AWS Iam Privilege Escalation · gabrielmoreiraDetect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations
- ▌ Implementing Cloud Workload Protection · gabrielmoreiraImplements cloud workload protection using boto3 and google-cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking on EC2/GCE instances. Scans for cryptomining, reverse shells, and unauthorized binaries. Use when building runtime security controls for cloud compute workloads.
- ▌ Analyzing Security Logs With Splunk · gabrielmoreiraLeverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk investigation, SPL queries, SIEM log analysis, security event correlation, or log-based incident investigation.
- ▌ Collecting Indicators Of Compromise · gabrielmoreiraSystematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.
- ▌ Bypassing Macos Gatekeeper Tcc And Sip · gabrielmoreiraAssessing and bypassing macOS userland and platform security controls during authorized engagements - Gatekeeper/quarantine notarization checks, the TCC (Transparency, Consent & Control) privacy database, System Integrity Protection (SIP/rootless), and the App Sandbox - using codesign, spctl, xattr, sqlite3 against TCC.db, csrutil, sandbox-exec, and AppleEvents/Automation abuse.
- ▌ Analyzing Network Traffic Of Malware · gabrielmoreiraAnalyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding, malware PCAP analysis, or network-based malware detection.
- ▌ Detecting Lateral Movement With Zeek · gabrielmoreiraDetect lateral movement in network traffic using Zeek (formerly Bro) log analysis. Parses conn.log, smb_mapping.log, smb_files.log, dce_rpc.log, kerberos.log, and ntlm.log to identify SMB file transfers, NTLM account spray activity, remote service execution, and anomalous internal connections.
- ▌ Analyzing Malicious Url With Urlscan · gabrielmoreiraURLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat
- ▌ Performing Credential Access With Lazagne · gabrielmoreiraExtract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
- ▌ Analyzing API Gateway Access Logs · gabrielmoreiraParses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating API abuse or building API-specific threat detection rules.
- ▌ Analyzing Windows Event Logs In Splunk · gabrielmoreiraAnalyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or perform forensic timeline analysis of Windows endpoints and domain controllers.
- ▌ Performing Malware Ioc Extraction · gabrielmoreiraMalware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise including file hashes, network indicators (C2 domains, IP addresses, URLs), regist
- ▌ Bypassing Two Factor And Otp · gabrielmoreiraIdentifying and exploiting flaws in two-factor authentication and one-time password verification including response manipulation, code leakage, brute force, race conditions, and delivery-target tampering.
- ▌ Performing Xs Search Attacks · gabrielmoreiraPerforming XS-Search / XS-Leaks attacks that extract cross-origin information through side channels — using inclusion methods (frames, pop-ups, HTML elements, fetch) and leak techniques (event handlers, timing, error events, global limits like connection-pool and event-loop, CORB, postMessage, Performance API) to distinguish two states of a victim page and exfiltrate secrets. Activates when assessing cross-origin information disclosure, search endpoints, or state-dependent responses.
- ▌ Testing Password Reset Flaws · gabrielmoreiraIdentifying and exploiting weaknesses in password reset flows including weak reset tokens, host header poisoning, IDOR on the identification parameter, missing session invalidation, and account enumeration.
- ▌ Generate Prompt Request · gabrielmoreiraThis skill should be used to generate a "prompt request" one-pager that summarizes the current session for a pull request. It produces one consolidated User block folding together every ask and decision from the session, plus one Assistant block summarizing what was built. Use it when the user asks to "generate a prompt request", recap or summarize the session for a PR, or capture what was requested. Also use it automatically when opening a pull request or writing a PR description, so the PR body includes the asks and decisions behind the change. Works on the current session only and outputs inline markdown ready to paste into a PR.
- ▌ Chengfeng Check Updates · gabrielmoreira剪辑环境的唯一管理者:就绪检查(skills 是否最新 → Runtime 是否配套)、Skills 更新激活、Runtime 安装与体检。用户说检查更新、安装剪辑环境、装播放器、检查剪辑环境、剪辑环境就绪了吗、配置转录凭证时使用;业务 Skill(剪口播/字幕/画面/导出)第 0 步也引用本 Skill 的就绪检查。不用于剪辑、字幕、画面、导出本身或项目数据迁移。
- ▌ Statistical Theory Analysis · gabrielmoreiraAnalyze theoretical properties of statistical methods under the formal formulation: identifiability, bias, variance, consistency, asymptotics, coverage, error bounds, robustness, and limitations.
- ▌ Methods Section Writer · gabrielmoreiraTurns your protocol and analysis workflow into publication-ready Methods text. Use when writing or revising the Methods section of a biomedical manuscript, ensuring it complies with reporting guidelines (CONSORT, STROBE, PRISMA, TRIPOD), matches what is in the Results section, and satisfies journal-specific word limits and declarations. Also triggers on "write my methods", "revise my methods section", "how to report my statistics", "what do I need to include in methods for [study type]", or "make my methods CONSORT-compliant".
- ▌ Results Section Writer · gabrielmoreiraWrites the full Results section of a biomedical manuscript from a sufficiently clear result structure, figure inventory, or analysis summary while preserving evidence boundaries and result hierarchy.
- ▌ Table Narrative Writer · gabrielmoreiraConverts biomedical table content into clear manuscript or presentation narrative by prioritizing meaningful patterns, contrasts, and interpretation boundaries rather than restating every number.
- ▌ Target Journal Matcher · gabrielmoreiraMatches your study to appropriate journals based on topic, design, and evidence strength. Use when deciding where to submit a manuscript, comparing journal options by impact factor vs scope fit vs method tolerance, or finding a realistic submission target after a rejection. Also triggers on "where should I submit this paper", "which journal is best for my study", "find journals for my manuscript", "is this a good fit for [journal]", or "I need a journal with IF around X".
- ▌ External Model Validation · gabrielmoreiraUse when validating an existing prognostic risk signature on an external bulk expression cohort with survival outcomes, producing risk scores, Kaplan-Meier curves, risk distribution plots, heatmap, and time-dependent ROC curves. NOT for: model training, feature selection, nomogram construction, calibration analysis, or single-cell data.
- ▌ Study Objective Refiner · gabrielmoreiraRefines broad, vague, or aspirational biomedical research objectives into clear, bounded, measurable, executable, and downstream-ready study objective statements. Always use this skill when a user has a general aim such as “explore a mechanism,” “study prognosis,” “investigate biomarkers,” or “look at treatment response,” but the objective is still too broad, non-operational, or too ambiguous to support protocol framing, design selection, analysis planning, or hypothesis design. Never assume that polished wording alone means the objective is actionable. Focus first on objective type, missing operational elements, scope discipline, and downstream-ready formulation.
- ▌ Cohort Study Quality Assessment Nos · gabrielmoreiraEvaluates the quality of cohort studies using the Newcastle-Ottawa Scale (NOS). Use when the user provides a cohort study article or text and needs a quality assessment report.
- ▌ Cross Disciplinary Bridge Finder · gabrielmoreiraUse when identifying collaboration opportunities across fields, finding experts in complementary disciplines, translating methodologies between scientific domains, or building interdisciplinary research teams. Identifies synergies between scientific disciplines, matches researchers with complementary expertise, and facilitates cross-domain collaborations. Supports interdisciplinary grant applications and innovative research team formation.
- ▌ AI Act Compliance · gabrielmoreiraCheck construction AI systems against the EU AI Act (Regulation 2024/1689): classify risk of estimation, scheduling, CV and agent tools, document transparency, keep human oversight. Use when deploying or auditing AI in construction.
- ▌ Az Cost Optimize · gabrielmoreiraAnalyze Azure resources used in the app (IaC files and/or resources in a target rg) and optimize costs - creating GitHub issues for identified optimizations.
- ▌ Microsoft Fabric · gabrielmoreiraMicrosoft Fabric workspace management, governance, REST API patterns, and medallion architecture implementation
- ▌ Biome Powerbi Query · gabrielmoreiraExecute read-only DAX queries against Power BI semantic models via the Power BI MCP server -- metadata discovery with INFO.VIEW functions and data retrieval with EVALUATE.
- ▌ Data Driven Layouts · gabrielmoreiraTemplate-driven layouts require code changes for structural updates:
- ▌ Career Development · gabrielmoreiraResume crafting, interview preparation, job search strategy, and professional growth planning.
- ▌ Typography Selector · gabrielmoreiraBrowse and select fonts from Google Fonts or curated pairings. Use to find the perfect typography for a design project.
- ▌ Compile Brain · gabrielmoreiraCreate or improve a Markdown instruction, skill, prompt, or agent from an explicitly selected file or user-identified text. Use when a user asks to optimize an existing brain artifact or create one for consistent future execution.
- ▌
- ▌ Version Management · gabrielmoreiraSemver discipline for Alex_ACT_Edition — bump rules, breaking-change classification, fleet rollout sequencing
- ▌ Code Explorer · gabrielmoreiraExplores the repository to locate primary source files, coupled UI components, and test files for bug reports or feature requests.
- ▌ Generate Doc Template · gabrielmoreiraGenerates on-brand document and deck templates — letterhead, slide, and one-pager — as SVG from the active brand profile, with editable title, subtitle, and body zones. Vector output needs no account, key, or network. Use when a user asks for a letterhead, a slide or deck master, or a branded one-pager. Trigger with "make a letterhead", "branded slide", or "/brand-make letterhead".
- ▌ Find Cybersecurity Firm · gabrielmoreiraUse whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec. Triggers on "find me a pen-testing firm for our SOC 2 audit", "shortlist three vCISO services for our healthcare-tech startup", "we need an incident response retainer", or "pull contact info for these 8 security firm domains", even when described indirectly (we got breached, prepare us for the compliance audit, get us SOC 2 ready). Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings. Skip in-house security hires, "how do I patch CVE-X" or "configure firewall Y" DIY questions, security-product reviews (CrowdStrike vs SentinelOne, etc.), generic security knowledge questions, consumer/personal security advice, non-US firms, individual freelancers and bug-bounty hunters.
- ▌ Find Software Developer · gabrielmoreiraUse whenever the user wants to find, shortlist, vet, or enrich US software development firms — custom software, web development, mobile app development, backend/API development, DevOps/cloud, system integration, and hosting. Triggers on "find a software dev shop in Austin", "shortlist three custom-software firms with healthcare experience", "we need a mobile app developer for our iOS launch", or "pull contact info for these 10 dev shop domains", even when described indirectly (build a tool, ship a feature, technical partner). Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings. Defer to find-web-developer for strictly website/landing-page projects. Defer AI/ML, ML pipelines, model building, and data-engineering asks — those are a sibling industry, not software development. Skip in-house engineer hires, code-writing/debugging tasks, cloud-product comparisons, hardware/civil engineering, non-US firms, individual freelancers.
- ▌ Product Brief · gabrielmoreiraStructured product brief and PRD creation assistant. Use when the user needs to write a product brief, PRD, feature spec, or any document that defines what to build and why. Triggers include "product brief", "PRD", "spec", "feature doc", "write a brief", "define this feature", or when scoping work for engineering.
- ▌ Adobe Sdk Patterns · gabrielmoreiraApply production-ready patterns for Adobe Firefly Services SDK, PDF Services SDK, and raw REST API usage in TypeScript and Python. Use when implementing Adobe integrations, refactoring SDK usage, or establishing team coding standards for Adobe APIs. Trigger with phrases like "adobe SDK patterns", "adobe best practices", "adobe code patterns", "idiomatic adobe", "adobe typescript".
- ▌ Attio Sdk Patterns · gabrielmoreiraProduction-ready patterns for the Attio REST API: typed client, retry with backoff, pagination iterators, and multi-tenant factory. Trigger: "attio SDK patterns", "attio best practices", "attio client wrapper", "idiomatic attio", "attio TypeScript patterns".
- ▌ Clari Sdk Patterns · gabrielmoreiraProduction-ready Clari API client patterns in Python and TypeScript. Use when building reusable Clari clients, implementing export pipelines, or wrapping the Clari v4 API for team use. Trigger with phrases like "clari API patterns", "clari client wrapper", "clari Python client", "clari TypeScript client".
- ▌ Miro CI Integration · gabrielmoreiraConfigure CI/CD pipelines for Miro REST API v2 integrations with GitHub Actions, test board isolation, and automated validation. Trigger with phrases like "miro CI", "miro GitHub Actions", "miro automated tests", "CI miro", "miro pipeline".
- ▌ Create Test Run · gabrielmoreiraCreate a Kobiton test run from a test case or suite, then offer to monitor it. When the user gives only partial details (or just a test case id), fill the rest with sensible defaults that match the createTestRun schema, show a summary of what will run, and ask to proceed or customize before creating. After the run is created, offer monitoring in a single prompt — monitor + auto-open live remediation (only when the org's live-remediation flag is ON), monitor only, or don't monitor — and hand off to the monitor-test-run skill if chosen. Use when the user asks to "create / kick off / start / run a test run", "run test case X on N devices", or similar. Wraps the createTestRun MCP tool (and getOrgSettings / listDevices for defaults); delegates the watch to monitor-test-run.
- ▌ Detecting SQL Injection Vulnerabilities · gabrielmoreira bundleDetect and analyze SQL injection vulnerabilities in application code and database queries. Use when you need to scan code for SQL injection risks, review query construction, validate input sanitization, or implement secure query patterns. Trigger with phrases like "detect SQL injection", "scan for SQLi vulnerabilities", "review database queries", or "check SQL security".
- ▌ Kubernetes Deployment Creator · gabrielmoreiraCreate kubernetes deployment creator operations. Auto-activating skill for DevOps Advanced. Triggers on: kubernetes deployment creator, kubernetes deployment creator Part of the DevOps Advanced skill category. Use when deploying applications or services. Trigger with phrases like "kubernetes deployment creator", "kubernetes creator", "deploy kubernetes ment creator".
- ▌ Code Injection Detector · gabrielmoreiraDetect code injection detector operations. Auto-activating skill for Security Fundamentals. Triggers on: code injection detector, code injection detector Part of the Security Fundamentals skill category. Use when working with code injection detector functionality. Trigger with phrases like "code injection detector", "code detector", "code".
- ▌ Password Hash Generator · gabrielmoreiraGenerate password hash generator operations. Auto-activating skill for Security Fundamentals. Triggers on: password hash generator, password hash generator Part of the Security Fundamentals skill category. Use when working with password hash generator functionality. Trigger with phrases like "password hash generator", "password generator", "password".
- ▌ Zapier Integration Helper · gabrielmoreiraAssist with zapier integration helper operations. Auto-activating skill for Business Automation. Triggers on: zapier integration helper, zapier integration helper Part of the Business Automation skill category. Use when working with APIs or building integrations. Trigger with phrases like "zapier integration helper", "zapier helper", "zapier".
- ▌ Change Request Generator · gabrielmoreiraGenerate change request generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: change request generator, change request generator Part of the Enterprise Workflows skill category. Use when working with change request generator functionality. Trigger with phrases like "change request generator", "change generator", "change".
- ▌ Calculate Labor Requirements · gabrielmoreira bundleCalculate warehouse labor requirements from workload, productivity, shifts, breaks, service windows, and capacity assumptions.
- ▌ Identify Logistics Constraints · gabrielmoreira bundleIdentify operational constraints across capacity, labor, equipment, systems, service, product, and safety boundaries.
- ▌ Analyze Logistics Data Quality · gabrielmoreira bundleAnalyze logistics data quality across master data, transactions, scan events, integrations, identifiers, lineage, controls, and operational impact.
- ▌ Analyze Throughput · gabrielmoreira bundleAnalyze logistics throughput from units, orders, lines, time, capacity, process scope, and source records.
- ▌ Research Canadian Logistics Documents · gabrielmoreiraPrepare Canadian logistics documentation research briefs for warehouse, transport, TDG, customs, import, export, carrier, and audit records.
- ▌ Plan Fefo Inventory Rotation · gabrielmoreiraPlan first-expired-first-out food inventory rotation using lot, expiry, status, hold, location, and order evidence while preserving release boundaries.
- ▌ Triage Temperature Excursion · gabrielmoreiraTriage food cold-chain temperature excursions by evidence, affected lots, custody points, hold status, escalation needs, and blocked release decisions.
- ▌ Dotnet Testing Advanced Aspnet Integration Testing · gabrielmoreira bundleASP.NET Core 整合測試的專門技能。當需要測試 Web API 端點、HTTP 請求/回應、中介軟體、依賴注入時使用。涵蓋 WebApplicationFactory、TestServer、HttpClient 測試、記憶體資料庫配置等。 Make sure to use this skill whenever the user mentions ASP.NET Core integration testing, WebApplicationFactory, TestServer, HTTP endpoint testing, or middleware testing, even if they don't explicitly ask for integration testing guidance. Keywords: integration testing, 整合測試, web api testing, WebApplicationFactory, TestServer, HttpClient testing, controller testing, endpoint testing, 端點測試, RESTful API testing, Microsoft.AspNetCore.Mvc.Testing, CreateClient, ConfigureWebHost, AwesomeAssertions.Web, Be200Ok, Be404NotFound, middleware testing, 中介軟體測試, dependency injection testing
- ▌ Dotnet Testing Advanced Webapi Integration Testing · gabrielmoreira bundleASP.NET Core WebApi 整合測試完整指南。當需要對 WebApi 端點進行整合測試或驗證 ProblemDetails 錯誤格式時使用。涵蓋 WebApplicationFactory、IExceptionHandler、Testcontainers 多容器編排、Flurl URL 建構與 AwesomeAssertions HTTP 驗證。 Make sure to use this skill whenever the user mentions WebApi integration testing, ProblemDetails, IExceptionHandler, Flurl, Respawn, or multi-container test orchestration, even if they don't explicitly ask for WebApi testing guidance. Keywords: webapi integration testing, WebApplicationFactory, asp.net core integration test, webapi 整合測試, IExceptionHandler, ProblemDetails, ValidationProblemDetails, AwesomeAssertions, Flurl, Respawn, Be201Created, Be400BadRequest, 多容器測試, Collection Fixture, 全域例外處理
- ▌ Dotnet Testing Autofixture Nsubstitute Integration · gabrielmoreira bundleAutoFixture 與 NSubstitute 整合指南 - 實現自動模擬 (Auto-Mocking)。當需要自動建立 Mock 物件、簡化複雜相依性注入測試時使用。涵蓋 AutoNSubstituteDataAttribute、Frozen 機制、Greedy 建構策略。包含 IMapper (AutoMapper/Mapster) 等特殊相依性的客製化處理。 Make sure to use this skill whenever the user mentions AutoFixture with NSubstitute, auto-mocking, AutoNSubstituteCustomization, Frozen attribute, or AutoNSubstituteDataAttribute, even if they don't explicitly ask for integration guidance. Keywords: autofixture nsubstitute, auto mocking, AutoNSubstituteDataAttribute, 自動模擬, Frozen, AutoNSubstituteCustomization, AutoFixture.AutoNSubstitute, Greedy, fixture.Freeze, Received(), Returns(), IMapper, AutoMapper, Mapster, mapper testing
- ▌ Indian Foreign Investment Approval Assessment Siddhi Kudalka · gabrielmoreira bundleAssess whether Government of India approval is required for foreign investment in an Indian company under Foreign Exchange Management Act, 1999 and the Non-Debt Instruments Rules, 2019. The skill systematically gathers transaction details, evaluates sectoral entry routes and caps, assesses land border country restrictions under applicable laws, and delivers a preliminary compliance note. Produces clear guidance on whether the investment falls within Automatic Route or requires Government approval.
- ▌ Outside Counsel Billing Performance Reviewer · gabrielmoreira bundleReviews outside counsel invoices and related billing data for an in-house legal department, including LEDES or e-billing exports, OCGs, approved rates, discounts, budgets, AFAs, and staffing rules. Starts with internal comparisons before bringing in external data. Produces invoice review findings, MBR/QBR scorecards, dispute logs, and management reports. For demonstration purposes only and not professional advice.
- ▌ Generate Requirement Drafts · gabrielmoreiraGenerates draft requirements from Simulink models. Use when drafting or updating requirement artifacts from a model. Prefers Requirements Toolbox (.slreqx) when available; falls back to structured YAML.
- ▌ Implementing API Abuse Detection With Rate Limiting · gabrielmoreira bundleImplements API abuse detection using token bucket, sliding window, and fixed window rate-limiting algorithms backed by Redis, including adaptive limits that tighten during detected attacks and relax during normal traffic. Use when defending APIs against DDoS, brute force login attempts, credential stuffing, or scraping abuse and you need to design or tune rate-limiting logic.
- ▌ Implementing Cloud Vulnerability Posture Management · gabrielmoreira bundleImplement multi-cloud CSPM to detect cloud-native misconfigurations and vulnerabilities (IAM over-permissions, exposed storage, unencrypted data, missing network controls) using AWS Security Hub, Azure Defender for Cloud, and open-source Prowler and ScoutSuite scans, then aggregate results across clouds. Use when auditing multi-cloud environments for misconfiguration-driven vulnerabilities or building a consolidated cross-cloud posture report.
- ▌ Implementing Container Network Policies With Calico · gabrielmoreira bundleUses Calico's own policy CRDs beyond the upstream Kubernetes API - GlobalNetworkPolicy, HostEndpoint, NetworkSet, policy tiers, and DNS-based egress rules - applied and audited with calicoctl. Use when a policy must span namespaces or protect the host itself, when egress has to be expressed by domain name, or when ordering policies into tiers. Keywords: calicoctl, GlobalNetworkPolicy, HostEndpoint, NetworkSet, tier, DNS egress, order. Do not use for portable upstream NetworkPolicy - use implementing-network-policies-for-kubernetes; for installing Calico and writing standard policy with it use implementing-kubernetes-network-policy-with-calico.
- ▌ Implementing Passwordless Auth With Microsoft Entra · gabrielmoreira bundleImplements passwordless authentication using Microsoft Entra ID with FIDO2 security keys, Windows Hello for Business, Microsoft Authenticator passkeys, and certificate-based authentication to eliminate password-based attacks. Use when deploying passwordless sign-in, configuring FIDO2 passkeys, enforcing phishing-resistant MFA, or setting Microsoft Entra authentication method policies.
- ▌ Implementing Passwordless Authentication With Fido2 · gabrielmoreira bundleDeploy FIDO2/WebAuthn passwordless authentication using security keys and platform authenticators, covering WebAuthn API integration, FIDO2 server configuration, passkey enrollment, biometric authentication, and migration from password-based systems aligned with NIST SP 800-63B AAL3. Use when implementing passkey login, configuring a FIDO2/WebAuthn server, or replacing passwords with phishing-resistant authentication.
- ▌ Implementing Zero Trust Network Access With Zscaler · gabrielmoreira bundleConfigures Zero Trust Network Access using Zscaler Private Access (ZPA) to broker identity-based, context-aware connections between authenticated users and internal applications through the Zscaler Zero Trust Exchange, without placing users on the corporate network. Use when replacing traditional VPN architectures with ZTNA, or when brokering secure per-application access for remote and hybrid users via Zscaler.
- ▌ Performing AWS Account Enumeration With Scout Suite · gabrielmoreira bundleRun the agentless, open-source ScoutSuite tool (via pip install and the `scout` CLI) against an AWS account to enumerate resources across services, identify misconfigurations, and generate an interactive HTML security report. Use when assessing an AWS account's overall security posture with read-only IAM credentials, such as during a cloud security audit or compliance review.
- ▌ Performing Kubernetes Cis Benchmark With Kube Bench · gabrielmoreira bundleTurns kube-bench output into a finished CIS Kubernetes Benchmark audit: interpreting PASS/FAIL/WARN per control, judging which failures are genuine on a managed cluster, writing remediation, and packaging evidence for SOC 2 or PCI DSS. Use when conducting a scheduled compliance audit, triaging kube-bench results, deciding which controls are not applicable on EKS, GKE, or AKS, or producing hardening evidence for an auditor. Keywords: CIS Kubernetes Benchmark, control plane, remediation, compliance evidence, SOC 2, PCI DSS, managed cluster exception. Do not use for installing and running the tool - use benchmarking-kubernetes-with-kube-bench.
- ▌ Performing Ot Vulnerability Assessment With Claroty · gabrielmoreira bundlePerform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe device querying with CVE/ICS-CERT advisory correlation for remediation prioritization. Use for scheduled IEC 62443 or NERC CIP OT vulnerability assessments, initial xDome deployment, or generating CIP-010-4 compliance evidence; not for active PLC scanning or penetration testing.
- ▌ Performing Threat Modeling With Owasp Threat Dragon · gabrielmoreira bundleUses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF threat model reports. Use during secure design review of an application architecture to build a formal threat model and document mitigations for GRC compliance.
- ▌ Tencent Meeting MCP · gabrielmoreira腾讯会议:会议管理与音视频协作助手。预约/创建/修改/取消会议、查询会议详情与会议号转换、查看参会成员/受邀人/等候室成员、查询用户会议列表(即将开始/进行中/已结束)、查询录制列表与下载地址、获取转写全文/段落/搜索、获取AI智能纪要(支持多语言翻译)、录制权限申请(预览+提交两步流程)、时间转换与版本检查、Agent意见箱反馈上报。当用户需要预约或管理腾讯会议、查看参会人员、查询会议录制或转写内容、获取智能纪要时使用;当用户访问录制相关内容(下载地址/转写/智能纪要)出现无权限错误时,自动发起录制权限申请流程;当Agent遇到以下任何情况时必须立即触发submit_feedback:工具缺失(功能不存在)、工具报错(返回错误码)、能力不足(参数/功能限制)、结果不符预期(数据异常)、改进建议(功能优化);如果用户提供的是9位会议号而非meeting_id,优先使用get_meeting_by_code转换后再操作。不要在以下场景触发:日程管理(非腾讯会议日程)、即时通讯/聊天、腾讯文档操作、企业微信审批流程、电话/PSTN拨号、视频剪辑或视频编辑、其他视频会议平台(Zoom/Teams/飞书/钉钉)。
- ▌ Bkn Modeling Advisor · gabrielmoreira指导业务知识网络(BKN)建模,输出符合 BKN 2.0.0 的对象类型、关系类型、操作类型、风险类型与概念分组定义。适用于用户提出本体设计、知识网络建模、实体关系梳理、Action 设计、Schema 评审、从文档提取初稿或扩展现有 BKN 的场景。
- ▌ AI Coding Agents Release Distribution · gabrielmoreiraDesigns release and distribution systems for coding-agent CLIs. Use when modeling packaging, auto-update channels, plugin compatibility, cache migrations, or install footprints.
- ▌ Detecting S3 Data Exfiltration Attempts · gabrielmoreiraDetecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.
- ▌ Detecting Serverless Function Injection · gabrielmoreiraDetects and prevents code injection attacks targeting serverless functions (AWS Lambda, Azure Functions, Google Cloud Functions) through event source poisoning, malicious layer injection, runtime command execution, and IAM privilege escalation via function modification. The analyst combines static analysis of function code, CloudTrail event correlation, runtime behavior monitoring, and IAM policy auditing to identify injection vectors across the expanded serverless attack surface including API Gateway, S3, SQS, DynamoDB Streams, and CloudWatch event triggers. Activates for requests involving Lambda security assessment, serverless injection detection, function event poisoning analysis, or serverless privilege escalation investigation.
- ▌ Performing Sca Dependency Scanning With Snyk · gabrielmoreiraThis skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines. It addresses scanning package manifests and lockfiles, automated fix pull request generation, license compliance checking, continuous monitoring of deployed applications, and integration with GitHub, GitLab, and Jenkins pipelines.
- ▌ Deploying Edr Agent With Crowdstrike · gabrielmoreiraDeploys and configures CrowdStrike Falcon EDR agents across enterprise endpoints to enable real-time threat detection, behavioral analysis, and automated response. Use when onboarding endpoints to EDR coverage, configuring detection policies, or integrating Falcon telemetry with SIEM platforms. Activates for requests involving CrowdStrike deployment, Falcon sensor installation, EDR policy configuration, or endpoint detection and response.
- ▌ Performing IOS App Security Assessment · gabrielmoreiraPerforms comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain extraction for credential analysis, and IPA static analysis for binary-level review. Use when conducting authorized iOS penetration tests, evaluating mobile app security posture against OWASP MASTG, or assessing iOS app data protection and transport security controls. Activates for requests involving iOS app pentesting, Frida-based iOS instrumentation, mobile app SSL pinning bypass, or IPA reverse engineering.
- ▌ Reverse Engineering IOS App With Frida · gabrielmoreiraReverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
- ▌ Detecting Lateral Movement In Network · gabrielmoreiraIdentifies lateral movement techniques in enterprise networks by analyzing authentication logs, network flows, SMB traffic, and RDP sessions using Zeek, Velociraptor, and SIEM correlation rules to detect attackers moving between systems.
- ▌ Detecting Port Scanning With Fail2ban · gabrielmoreiraConfigures Fail2ban with custom filters and actions to detect port scanning activity, SSH brute force attempts, and network reconnaissance, automatically banning offending IP addresses and alerting security teams to suspicious network probing.
- ▌ Pentesting Docker Registry · gabrielmoreiraTesting Docker Registry / Distribution services (default 5000/TCP, HTTP or HTTPS) for unauthenticated catalog access, image and blob/manifest extraction, weak basic-auth, and supply-chain image backdooring (push poisoned WordPress/SSH images) during authorized engagements.
- ▌ Performing Iot Security Assessment · gabrielmoreiraPerforms comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications. The tester uses firmware extraction and analysis, hardware debugging via UART and JTAG, network protocol analysis, and runtime exploitation to identify vulnerabilities across all layers of the IoT stack. Activates for requests involving IoT security testing, embedded device assessment, firmware security analysis, or smart device penetration testing.
- ▌ Conducting Social Engineering Pretext Call · gabrielmoreiraPlan and execute authorized vishing (voice phishing) pretext calls to assess employee susceptibility to social engineering and evaluate security awareness controls.
- ▌ Performing Dns Tunneling Detection · gabrielmoreiraDetects DNS tunneling by computing Shannon entropy of DNS query names, analyzing query length distributions, inspecting TXT record payloads, and identifying high subdomain cardinality. Uses scapy for packet capture analysis and statistical methods to distinguish legitimate DNS from covert channels. Use when hunting for data exfiltration.
- ▌ Building Detection Rule With Splunk Spl · gabrielmoreiraBuild effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments.
- ▌ Investigating Insider Threat Indicators · gabrielmoreiraInvestigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.
- ▌ Detecting Living Off The Land Attacks · gabrielmoreiraDetect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks. Monitors process creation, command-line arguments, and parent-child relationships to identify suspicious LOLBin execution patterns.
- ▌ Analyzing Indicators Of Compromise · gabrielmoreiraAnalyzes indicators of compromise (IOCs) including IP addresses, domains, file hashes, URLs, and email artifacts to determine maliciousness confidence, campaign attribution, and blocking priority. Use when triaging IOCs from phishing emails, security alerts, or external threat feeds; enriching raw IOCs with multi-source intelligence; or making block/monitor/whitelist decisions. Activates for requests involving VirusTotal, AbuseIPDB, MalwareBazaar, MISP, or IOC enrichment pipelines.
- ▌ Bypassing Captcha Protections · gabrielmoreiraIdentifying weaknesses in CAPTCHA implementations and bypassing them via replay, field removal, method/content-type manipulation, missing server-side validation, and weak OCR-solvable challenges to defeat anti-automation controls.
- ▌ Testing Cors Misconfiguration · gabrielmoreiraIdentifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments.
- ▌ Safe Refactoring · gabrielmoreiraExecute behavior-preserving or intentionally scoped refactors safely. Use this for multi-file renames, component/service extraction, state-management changes, API migrations, concurrency refactors, or any request where unrelated user work and subtle contracts must be preserved.
- ▌ Author Response Builder · gabrielmoreiraTurns reviewer comments into structured, professional point-by-point responses linked to manuscript revisions, clarifications, rebuttals, and additional analyses.
- ▌ Roc Diagnostic Performance · gabrielmoreiraUse when evaluating diagnostic biomarker performance from case-control expression data with logistic regression and ROC curves, exporting coefficient and AUC tables together with a ROC PDF. NOT for: survival analysis, time-to-event outcomes, multiclass classification, calibration curves, decision-curve analysis, or nomogram construction.