all publishers

gabrielmoreira

@gabrielmoreira source repo

21,231 published skills · page 74 of 213

  1. ▌
    Response Time Analyzer · gabrielmoreira
    Analyze response time analyzer operations. Auto-activating skill for Performance Testing. Triggers on: response time analyzer, response time analyzer Part of the Performance Testing skill category. Use when analyzing or auditing response time analyzer. Trigger with phrases like "response time analyzer", "response analyzer", "analyze response time r".
    17 repo stars
  2. ▌
    Cloudformation Template Creator · gabrielmoreira
    Create cloudformation template creator operations. Auto-activating skill for AWS Skills. Triggers on: cloudformation template creator, cloudformation template creator Part of the AWS Skills skill category. Use when working with cloudformation template creator functionality. Trigger with phrases like "cloudformation template creator", "cloudformation creator", "cloudformation".
    17 repo stars
  3. ▌
    Conditional Request Helper · gabrielmoreira
    Configure with conditional request helper operations. Auto-activating skill for API Development. Triggers on: conditional request helper, conditional request helper Part of the API Development skill category. Use when working with conditional request helper functionality. Trigger with phrases like "conditional request helper", "conditional helper", "conditional".
    17 repo stars
  4. ▌
    GRAPHQL Subscription Setup · gabrielmoreira
    Configure graphql subscription setup operations. Auto-activating skill for API Development. Triggers on: graphql subscription setup, graphql subscription setup Part of the API Development skill category. Use when working with graphql subscription setup functionality. Trigger with phrases like "graphql subscription setup", "graphql setup", "graphql".
    17 repo stars
  5. ▌
    Versioning Strategy Helper · gabrielmoreira
    Configure with versioning strategy helper operations. Auto-activating skill for API Development. Triggers on: versioning strategy helper, versioning strategy helper Part of the API Development skill category. Use when working with versioning strategy helper functionality. Trigger with phrases like "versioning strategy helper", "versioning helper", "versioning".
    17 repo stars
  6. ▌
    Integration Test Generator · gabrielmoreira
    Generate integration test generator operations. Auto-activating skill for API Integration. Triggers on: integration test generator, integration test generator Part of the API Integration skill category. Use when writing or running tests. Trigger with phrases like "integration test generator", "integration generator", "integration".
    17 repo stars
  7. ▌
    Webhook Receiver Generator · gabrielmoreira
    Generate webhook receiver generator operations. Auto-activating skill for API Integration. Triggers on: webhook receiver generator, webhook receiver generator Part of the API Integration skill category. Use when working with webhook receiver generator functionality. Trigger with phrases like "webhook receiver generator", "webhook generator", "webhook".
    17 repo stars
  8. ▌
    Code Documentation Analyzer · gabrielmoreira
    Analyze code documentation analyzer operations. Auto-activating skill for Technical Documentation. Triggers on: code documentation analyzer, code documentation analyzer Part of the Technical Documentation skill category. Use when analyzing or auditing code documentation analyzer. Trigger with phrases like "code documentation analyzer", "code analyzer", "analyze code documentation r".
    17 repo stars
  9. ▌
    Sdk Documentation Generator · gabrielmoreira
    Generate sdk documentation generator operations. Auto-activating skill for Technical Documentation. Triggers on: sdk documentation generator, sdk documentation generator Part of the Technical Documentation skill category. Use when working with sdk documentation generator functionality. Trigger with phrases like "sdk documentation generator", "sdk generator", "sdk".
    17 repo stars
  10. ▌
    Infographic Outline Creator · gabrielmoreira
    Create infographic outline creator operations. Auto-activating skill for Visual Content. Triggers on: infographic outline creator, infographic outline creator Part of the Visual Content skill category. Use when working with infographic outline creator functionality. Trigger with phrases like "infographic outline creator", "infographic creator", "infographic".
    17 repo stars
  11. ▌
    Mermaid Flowchart Generator · gabrielmoreira
    Generate mermaid flowchart generator operations. Auto-activating skill for Visual Content. Triggers on: mermaid flowchart generator, mermaid flowchart generator Part of the Visual Content skill category. Use when working with mermaid flowchart generator functionality. Trigger with phrases like "mermaid flowchart generator", "mermaid generator", "mermaid".
    17 repo stars
  12. ▌
    Presentation Slide Outliner · gabrielmoreira
    Manage presentation slide outliner operations. Auto-activating skill for Visual Content. Triggers on: presentation slide outliner, presentation slide outliner Part of the Visual Content skill category. Use when working with presentation slide outliner functionality. Trigger with phrases like "presentation slide outliner", "presentation outliner", "presentation".
    17 repo stars
  13. ▌
    Calendar Event Creator · gabrielmoreira
    Create calendar event creator operations. Auto-activating skill for Business Automation. Triggers on: calendar event creator, calendar event creator Part of the Business Automation skill category. Use when working with calendar event creator functionality. Trigger with phrases like "calendar event creator", "calendar creator", "calendar".
    17 repo stars
  14. ▌
    N8n Workflow Generator · gabrielmoreira
    Generate n8n workflow generator operations. Auto-activating skill for Business Automation. Triggers on: n8n workflow generator, n8n workflow generator Part of the Business Automation skill category. Use when working with n8n workflow generator functionality. Trigger with phrases like "n8n workflow generator", "n8n generator", "n8n".
    17 repo stars
  15. ▌
    Jira Ticket Generator · gabrielmoreira
    Generate jira ticket generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: jira ticket generator, jira ticket generator Part of the Enterprise Workflows skill category. Use when working with jira ticket generator functionality. Trigger with phrases like "jira ticket generator", "jira generator", "jira".
    17 repo stars
  16. ▌
    Jira Workflow Creator · gabrielmoreira
    Create jira workflow creator operations. Auto-activating skill for Enterprise Workflows. Triggers on: jira workflow creator, jira workflow creator Part of the Enterprise Workflows skill category. Use when working with jira workflow creator functionality. Trigger with phrases like "jira workflow creator", "jira creator", "jira".
    17 repo stars
  17. ▌
    Select Inventory Rotation Policy · gabrielmoreira bundle
    Select inventory rotation policy from SKU attributes, age, expiration, lot control, demand, and operational constraints.
    17 repo stars
  18. ▌
    Analyze Logistics Operation · gabrielmoreira bundle
    Assess a logistics operation's facilities, flows, constraints, systems, and service commitments before deeper planning.
    17 repo stars
  19. ▌
    Calculate Equipment Requirements · gabrielmoreira bundle
    Calculate equipment requirements from volume, travel distance, cycle time, uptime, shifts, throughput, and service windows.
    17 repo stars
  20. ▌
    Analyze Carrier Performance · gabrielmoreira bundle
    Analyze carrier performance from on-time service, tender acceptance, claims, cost, billing, transit, and exception evidence.
    17 repo stars
  21. ▌
    Analyze Transportation Kpis · gabrielmoreira bundle
    Analyze transportation KPIs from shipment metrics, service, cost, carrier data, accessorials, claims, and lane evidence.
    17 repo stars
  22. ▌
    Plan Warehouse Expansion · gabrielmoreira bundle
    Plan warehouse expansion from capacity forecast, current constraints, growth options, phasing, risk, and review boundaries.
    17 repo stars
  23. ▌
    Research Canadian Loading Security · gabrielmoreira
    Prepare Canadian loading, cargo securement, seal, yard, dock, and shipment security research briefs for logistics operations.
    17 repo stars
  24. ▌
    Research Canadian Workplace Safety · gabrielmoreira
    Prepare source-backed Canadian workplace safety research briefs for logistics operations without issuing compliance determinations.
    17 repo stars
  25. ▌
    Dpgen Simplify · gabrielmoreira
    Prepare, explain, validate, and run DP-GEN simplify workflows for reducing repeated or redundant DeepMD datasets. Use when the user wants to generate or modify `param.json` and `machine.json`, run `dpgen simplify param.json machine.json`, organize repeated simplify experiments, or inspect simplify outputs.
    17 repo stars
  26. ▌
    Dotnet Testing Advanced Testcontainers Database · gabrielmoreira bundle
    使用 Testcontainers 進行容器化資料庫測試的專門技能。當需要測試真實資料庫行為、使用 SQL Server/PostgreSQL/MySQL 容器、測試 EF Core/Dapper 時使用。涵蓋容器啟動、資料庫遷移、測試隔離、容器共享等。 Make sure to use this skill whenever the user mentions Testcontainers database, SQL Server container, PostgreSQL container, EF Core integration test, Dapper testing, or Collection Fixture, even if they don't explicitly ask for container-based database testing. Keywords: testcontainers, 容器測試, container testing, database testing, 資料庫測試, MsSqlContainer, PostgreSqlContainer, MySqlContainer, EF Core testing, Dapper testing, Testcontainers.MsSql, Testcontainers.PostgreSql, GetConnectionString, IAsyncLifetime, CollectionFixture
    17 repo stars
  27. ▌
    Eu AI Act High Risk Implementation Readiness · gabrielmoreira bundle
    Assess and operationalize implementation readiness for high-risk AI systems under the EU AI Act Annex III, including provider and deployer obligations, conformity assessment, post-market monitoring, and EU database registration. Use when users say things like “we classified this as high-risk, what now?”, “build an EU AI Act readiness plan”, “assess our Annex III compliance gaps”, “what do providers/deployers of high-risk AI need to implement?”, “prepare for conformity assessment”, or “create a high-risk AI implementation roadmap.”
    17 repo stars
  28. ▌
    Building Simulink Models · gabrielmoreira
    Builds and edits Simulink, System Composer, Stateflow, and Simscape models. Use when modifying model structure, parameters, ports, connections, or Stateflow chart internals.
    17 repo stars
  29. ▌
    Configuring Block Policy · gabrielmoreira
    Guide users through creating and managing .satk/block-policy.json for controlling which blocks the agent can use, which are excluded, and which block parameters the agent should not modify. Use when setting up block usage policy for a project.
    17 repo stars
  30. ▌
    26 Thought Leadership Content Global · gabrielmoreira
    Use when a PERSONAL brand needs long-form WRITTEN content that builds authority rather than sells — LinkedIn posts, X threads, Substack and Medium essays, using PAS-Insight for founders, Story-Lesson-CTA for coaches, and Hook-List-Reveal for creators, with six hook formulas and a 1-to-5 repurpose. Trigger on 'LinkedIn post', 'thought leadership', 'write a Twitter thread', 'newsletter essay', 'Substack post', 'I want to be known for this topic'. Also use when the user has an opinion and wants it turned into a post. Not for — company brand captions, see `37-social-caption-global`; paid ad copy, see `05-ad-copy-global`; short video scripts, see `04-script-video-global`.
    17 repo stars
  31. ▌
    Analyzing Threat Actor Ttps With Mitre Navigator · gabrielmoreira bundle
    Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT group's techniques, building Navigator coverage heatmaps, or assessing technique coverage gaps against a specific threat actor.
    17 repo stars
  32. ▌
    Building Attack Pattern Library From Cti Reports · gabrielmoreira bundle
    Parse cyber threat intelligence reports (Mandiant, CrowdStrike, Talos, Microsoft) with stix2, mitreattack-python, and spaCy to extract adversary behaviors, map them to MITRE ATT&CK technique IDs, and build a searchable STIX 2.1 attack-pattern library with detection templates. Use when cataloging attack patterns from CTI reports for threat-informed detection engineering, or generating Sigma/YARA templates from documented behaviors.
    17 repo stars
  33. ▌
    Building C2 Infrastructure With Sliver Framework · gabrielmoreira bundle
    Deploy and harden a Sliver C2 team server (BishopFox's Go-based adversary emulation framework) with multi-protocol listeners (mTLS, HTTP/S, DNS, WireGuard), redirectors, domain fronting, and multi-operator support for authorized red-team operations. Use when standing up resilient C2 for a red-team engagement or generating beacon/session implants that must survive blue-team detection.
    17 repo stars
  34. ▌
    Building Malware Incident Communication Template · gabrielmoreira bundle
    Build structured communication templates for malware incidents (ransomware, wiper, trojan, worm), covering internal stakeholder notifications, executive briefings, technical advisories for IT teams, customer notifications, and regulatory disclosures, with severity-based escalation procedures. Use when drafting or standardizing incident communications and notification workflows for a malware outbreak.
    17 repo stars
  35. ▌
    Building Ransomware Playbook With Cisa Framework · gabrielmoreira bundle
    Builds a structured ransomware incident response playbook aligned with the CISA StopRansomware Guide and NIST Cybersecurity Framework, covering preparation, detection, containment, eradication, recovery, and post-incident phases with actionable checklists. Use when creating or updating a ransomware playbook, running a CISA-aligned readiness assessment, or validating response steps during a tabletop exercise.
    17 repo stars
  36. ▌
    Building Vulnerability Dashboard With Defectdojo · gabrielmoreira bundle
    Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD, Jira ticketing, and Slack notifications via its REST API. Use when consolidating scanner output into one dashboard or automating vulnerability ticketing and executive reporting.
    17 repo stars
  37. ▌
    Building Vulnerability Exception Tracking System · gabrielmoreira bundle
    Build a vulnerability exception and risk acceptance tracking system covering approval workflows, compensating controls documentation, and automatic expiration for vulnerabilities that miss SLA remediation timelines. Use when standing up a governance process for risk acceptance and exception approvals to support PCI DSS, SOC 2, or NIST CSF compliance.
    17 repo stars
  38. ▌
    Configuring Identity Aware Proxy With Google Iap · gabrielmoreira bundle
    Configures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce per-request identity verification on Compute Engine, App Engine, Cloud Run, and GKE, including IAM bindings, Access Context Manager access levels, session/reauth settings, and service-account programmatic access. Use when replacing VPN access with identity-based access to GCP backends or configuring context-aware, zero-trust policies for Google Cloud services.
    17 repo stars
  39. ▌
    Configuring Multi Factor Authentication With Duo · gabrielmoreira bundle
    Deploys Cisco Duo multi-factor authentication across enterprise applications, VPN, RDP, and SSH access points, covering Duo Authentication Proxy setup, adaptive authentication policies, device trust assessment, and phishing-resistant WebAuthn/FIDO2 deployment aligned with NIST 800-63B AAL2/AAL3. Use when adding or hardening MFA for remote access, VPN, or privileged logins with Duo.
    17 repo stars
  40. ▌
    Detecting Golden Ticket Attacks In Kerberos Logs · gabrielmoreira bundle
    Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures. Use when hunting for Kerberos ticket forgery or krbtgt-based persistence (MITRE T1558.001) in AD environments.
    17 repo stars
  41. ▌
    Exploiting Zerologon Vulnerability Cve 2020 1472 · gabrielmoreira bundle
    Exploits the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol using Impacket to reset a domain controller's machine account password to empty, then runs DCSync via secretsdump.py to dump domain credentials. Use when red-teaming or validating unpatched Active Directory domain controllers for Zerologon, including restoring the machine account password afterward.
    17 repo stars
  42. ▌
    Implementing End To End Encryption For Messaging · gabrielmoreira bundle
    Implements a simplified Signal Protocol-style end-to-end encryption scheme for messaging, covering key exchange, forward secrecy, and the core cryptographic components so no server or intermediary can decrypt messages. Use when designing or building E2EE messaging, or evaluating forward-secrecy and key-management tradeoffs for a messaging system.
    17 repo stars
  43. ▌
    Implementing File Integrity Monitoring With Aide · gabrielmoreira bundle
    Configures AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring on Linux, covering baseline database creation, scheduled integrity checks via cron, change detection, and alerting on unauthorized modifications. Use when setting up host-based file integrity monitoring, detecting unauthorized file changes, or meeting compliance requirements for FIM on Linux systems.
    17 repo stars
  44. ▌
    Implementing GCP Organization Policy Constraints · gabrielmoreira bundle
    Implements GCP Organization Policy constraints via gcloud and Terraform, such as restricting external IPs, resource locations, default service accounts, and service account keys, plus dry-run testing of policy impact before enforcement. Use when enforcing security guardrails across an org's resource hierarchy, or hardening GCP config at the org, folder, or project level.
    17 repo stars
  45. ▌
    Implementing Mimecast Targeted Attack Protection · gabrielmoreira bundle
    Deploys and configures Mimecast Targeted Threat Protection (TTP) modules -- URL Protect (click-time URL rewriting/analysis), Attachment Protect (sandbox detonation), Impersonation Protect (BEC/whaling detection), and Internal Email Protect -- for Microsoft 365 or Google Workspace. Use when defending against phishing, spearphishing, or business email compromise, or configuring TTP policies in the Mimecast Administration Console.
    17 repo stars
  46. ▌
    Performing Cloud Incident Containment Procedures · gabrielmoreira bundle
    Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups and network ACLs, and preserve forensic evidence via snapshots. Use when responding to a cloud security incident that requires stopping lateral movement while keeping evidence intact for later investigation.
    17 repo stars
  47. ▌
    Performing Entitlement Review With Sailpoint Iiq · gabrielmoreira bundle
    Runs entitlement review and access certification campaigns in SailPoint IdentityIQ, covering manager certifications, targeted entitlement reviews, role-based access validation, segregation-of-duties violation remediation, and automated revocation workflows. Use when performing periodic user access recertification, auditing SailPoint IIQ access governance, or investigating SOD violations.
    17 repo stars
  48. ▌
    Performing Threat Intelligence Sharing With Misp · gabrielmoreira bundle
    Uses PyMISP (the official MISP REST API library) to create events with structured IOCs (IPs, domains, hashes, URLs), enrich them with MITRE ATT&CK tags and galaxy clusters, manage sharing groups and distribution levels, search existing intelligence, and export in STIX 2.1 format. Use when creating, enriching, or sharing threat intelligence events on a MISP instance, or integrating IOC feeds with other platforms.
    17 repo stars
  49. ▌
    Post Exploiting Microsoft Graph With Graphrunner · gabrielmoreira bundle
    Runs GraphRunner, a PowerShell post-exploitation toolset built on the Microsoft Graph API, to perform tenant recon, establish persistence (OAuth app injection, inbox rules), escalate privilege via group manipulation, and pillage mailboxes, SharePoint, and Teams data from a foothold Graph token. Use during authorized red-team engagements against Microsoft 365/Entra ID tenants once you hold a Graph token.
    17 repo stars
  50. ▌
    Gradle Build Performance · gabrielmoreira
    Debug and optimize Android/Gradle build performance. Use when builds are slow, investigating CI/CD performance, analyzing build scans, or identifying compilation bottlenecks.
    17 repo stars
  51. ▌
    AI Coding Agents Execution Sandbox · gabrielmoreira
    Designs execution sandboxes for coding agents. Use when modeling process isolation, filesystem policy, network controls, workspace mounts, or destructive-command boundaries.
    17 repo stars
  52. ▌
    Software Android Runtime Debugging · gabrielmoreira
    Build/install/launch proof, ANR/jank/memory triage, and stale-build debugging for native Android apps. Use when runtime truth, performance, or crash root cause is in doubt.
    17 repo stars
  53. ▌
    Performing API Inventory And Discovery · gabrielmoreira
    Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. The tester uses passive traffic analysis, active scanning, DNS enumeration, JavaScript analysis, and cloud resource inventory to build a comprehensive API catalog. Maps to OWASP API9:2023 Improper Inventory Management. Activates for requests involving API discovery, shadow API detection, API inventory audit, or attack surface mapping.
    17 repo stars
  54. ▌
    Conducting Cloud Penetration Testing · gabrielmoreira
    This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF to cloud metadata services, and reporting findings aligned to MITRE ATT&CK Cloud matrix.
    17 repo stars
  55. ▌
    Exploiting Deeplink Vulnerabilities · gabrielmoreira
    Tests and exploits deep link (URL scheme and App Link) vulnerabilities in Android and iOS mobile applications to identify unauthorized access, data injection, intent hijacking, and redirect manipulation. Use when assessing mobile app attack surface through custom URI schemes, Android App Links, iOS Universal Links, or intent-based navigation. Activates for requests involving deep link security testing, URL scheme exploitation, mobile intent abuse, or link hijacking.
    17 repo stars
  56. ▌
    Performing Packet Injection Attack · gabrielmoreira
    Crafts and injects custom network packets using Scapy, hping3, and Nemesis during authorized security assessments to test firewall rules, IDS detection, protocol handling, and network stack resilience against malformed and spoofed traffic.
    17 repo stars
  57. ▌
    Conducting API Security Testing · gabrielmoreira
    Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.
    17 repo stars
  58. ▌
    Performing Exploit Verification · gabrielmoreira
    Systematic methodology for safely confirming and documenting exploited vulnerabilities with reproducible proof, ensuring zero false positives before reporting.
    17 repo stars
  59. ▌
    Building Incident Response Dashboard · gabrielmoreira
    Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.
    17 repo stars
  60. ▌
    Building Soc Playbook For Ransomware · gabrielmoreira
    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formalized response procedures for ransomware incidents aligned to NIST SP 800-61 and MITRE ATT&CK ransomware techniques.
    17 repo stars
  61. ▌
    Implementing Alert Fatigue Reduction · gabrielmoreira
    Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness and prevent critical alert dismissal. Use when SOC teams face overwhelming alert volumes, high false positive rates, or declining analyst performance.
    17 repo stars
  62. ▌
    Performing Ioc Enrichment Automation · gabrielmoreira
    Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition recommendations. Use when SOC analysts need rapid multi-source enrichment of IPs, domains, URLs, and file hashes during alert triage or incident investigation.
    17 repo stars
  63. ▌
    Hunting For Spearphishing Indicators · gabrielmoreira
    Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.
    17 repo stars
  64. ▌
    Managing Intelligence Lifecycle · gabrielmoreira
    Manages the end-to-end cyber threat intelligence lifecycle from planning and direction through collection, processing, analysis, dissemination, and feedback to ensure intelligence products meet stakeholder requirements and continuously improve. Use when establishing or maturing a CTI program, defining intelligence requirements with business stakeholders, or building feedback loops between intelligence consumers and producers. Activates for requests involving CTI program maturity, intelligence requirements, PIRs, or intelligence lifecycle management.
    17 repo stars
  65. ▌
    Mapping Mitre Attack Techniques · gabrielmoreira
    Maps observed adversary behaviors, security alerts, and detection rules to MITRE ATT&CK techniques and sub-techniques to quantify detection coverage and guide control prioritization. Use when building an ATT&CK-based coverage heatmap, tagging SIEM alerts with technique IDs, aligning security controls to adversary playbooks, or reporting threat exposure to executives. Activates for requests involving ATT&CK Navigator, Sigma rules, MITRE D3FEND, or coverage gap analysis.
    17 repo stars
  66. ▌
    Abusing Hop By Hop Headers · gabrielmoreira
    Testing proxies, load balancers, and CDNs for improper handling of HTTP hop-by-hop headers, where an attacker uses the Connection header to designate arbitrary headers as hop-by-hop so an intermediary strips them before they reach the backend. Enables IP-based access-control bypass (X-Forwarded-For), header-stripping attacks on auth and caching, and cache poisoning. Activates when a target sits behind one or more HTTP/1.1 proxies.
    17 repo stars
  67. ▌
    Exploiting Xpath Injection · gabrielmoreira
    Exploiting XPath injection where applications build XPath/XQuery expressions from unsanitized user input to query XML documents, allowing authentication bypass and blind extraction of the entire XML document (users, passwords, schema) plus out-of-band exfiltration. Activates when login or search features query XML data stores via XPath.
    17 repo stars
  68. ▌
    Testing For Crlf Injection · gabrielmoreira
    Testing web applications for CRLF (Carriage Return / Line Feed) injection where unsanitized %0d%0a sequences in user input let an attacker inject HTTP headers, split responses, poison caches, plant cookies, or pivot to XSS and request smuggling. Activates when user input is reflected into response headers, Location redirects, log files, or outbound requests made by the application.
    17 repo stars
  69. ▌
    Testing JWT Token Security · gabrielmoreira
    Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
    17 repo stars
  70. ▌
    Statistical Method Design · gabrielmoreira
    Design statistical methods, baselines, diagnostics, variants, and ablations that directly address a formal problem formulation.
    17 repo stars
  71. ▌
    Figure Legend Writer · gabrielmoreira
    Writes complete, publication-grade figure legends that can stand on their own. Use when writing or revising figure legends for any scientific figure — bar charts, line graphs, scatter plots, box plots, heatmaps, survival curves, flow cytometry plots, western blots, microscopy images, or schematic diagrams. Also triggers on "write a figure legend for", "help me describe this figure", "my figure needs a legend", "write Figure 1 legend", or "what should a figure legend include".
    17 repo stars
  72. ▌
    Batch Effect Correction · gabrielmoreira
    Use when correcting batch effects in merged bulk expression matrices with sample-level batch metadata while preserving biological group structure and generating before-and-after QC plots. NOT for: single-cell integration, raw FASTQ processing, differential expression without batch labels, or datasets without biological groups.
    17 repo stars
  73. ▌
    Decision Curve Analysis · gabrielmoreira
    Use when evaluating the clinical utility of a binary prediction model from a single clinical CSV file by fitting a logistic decision-curve model, plotting decision and clinical-impact curves, and exporting summary outputs. NOT for: survival calibration, ROC-only discrimination analysis, nomogram construction, or time-to-event outcomes.
    17 repo stars
  74. ▌
    Immune Pathway Analysis · gabrielmoreira
    Run immune pathway GSVA or ssGSEA analysis from a bulk expression matrix, a sample group file, and a local immune Reactome gene-set table, then export differential pathway results and a heatmap for two-group comparison.
    17 repo stars
  75. ▌
    Model Calibration Curve · gabrielmoreira
    Use when assessing how well a survival model's predicted probabilities agree with observed outcomes by fitting a Cox model and generating bootstrap calibration curves at one or more prediction horizons from a clinical CSV file. NOT for: nomogram construction, univariate Cox screening, ROC analysis, or decision-curve analysis.
    17 repo stars
  76. ▌
    Digital Twin Discharge Drafter · gabrielmoreira
    Use when drafting patient discharge summaries, creating personalized discharge instructions, simulating post-discharge outcomes, reducing hospital readmissions, or optimizing care transitions. Generates AI-enhanced discharge documentation with digital twin predictions for improved patient safety.
    17 repo stars
  77. ▌
    Code Refactor For Reproducibility · gabrielmoreira
    Use when refactoring research code for publication, adding documentation to existing analysis scripts, creating reproducible computational workflows, or preparing code for sharing with collaborators. Transforms research code into publication-ready, reproducible workflows. Adds documentation, implements error handling, creates environment specifications, and ensures computational reproducibility for scientific publications.
    17 repo stars
  78. ▌
    Setup AI Operations · gabrielmoreira
    Configure optional Microsoft Foundry, Hugging Face, and ElevenLabs provider access for AI Operations. Use after installing the plugin, when a provider is unavailable, when auditing authentication, or when previewing and provisioning the exact ElevenLabs private runtime.
    17 repo stars
  79. ▌
    Tech Debt Discovery · gabrielmoreira
    Systematic technical debt inventory and prioritization. Use when asked to "find tech debt", "show me the TODOs", "how healthy is this codebase", "what should we fix first", "find code smells", "audit code quality", or "identify hotspots". Scans code markers, analyzes git history, checks dependencies, and produces a prioritized debt report.
    17 repo stars
  80. ▌
    Project Deployment · gabrielmoreira
    Universal deployment patterns for any project type.
    17 repo stars
  81. ▌
    Gamma Presentation · gabrielmoreira
    Author markdown files optimized for Gamma import — card structure, layout hints, image directives, speaker notes, and chat-agent refinement workflow
    17 repo stars
  82. ▌
    Penpot Uiux Design · gabrielmoreira
    Comprehensive guide for creating professional UI/UX designs in Penpot using MCP tools. Use this skill when: (1) Creating new UI/UX designs for web, mobile, or desktop applications, (2) Building design systems with components and tokens, (3) Designing dashboards, forms, navigation, or landing pages, (4) Applying accessibility standards and best practices, (5) Following platform guidelines (iOS, Android, Material Design), (6) Reviewing or improving existing Penpot designs for usability. Triggers: "design a UI", "create interface", "build layout", "design dashboard", "create form", "design landing page", "make it accessible", "design system", "component library".
    17 repo stars
  83. ▌
    Supervisor Banners · gabrielmoreira
    Dark-slate SVG banner family — 1200×320 hero + 1200×60 section dividers — for governance, curation, and audit-style documentation
    17 repo stars
  84. ▌
    Linkedin Automation · gabrielmoreira
    Automate LinkedIn tasks via Rube MCP (Composio): create posts, manage profile, company info, comments, and image uploads. Always search tools first for current schemas.
    17 repo stars
  85. ▌
    Office Productivity · gabrielmoreira
    Office productivity workflow covering document creation, spreadsheet automation, presentation generation, and integration with LibreOffice and Microsoft Office formats.
    17 repo stars
  86. ▌
    Violation Triager · gabrielmoreira
    Orchestrate end-to-end SFI-TI3.2.2 workflow — fetch violations, classify, dispatch to remediation skills, generate report
    17 repo stars
  87. ▌
    Render Verify · gabrielmoreira
    Verify a rendered visual artifact actually says what it was supposed to say — open it, read its console errors, walk a failure catalog, and check it against the claim it was meant to carry. Works on charts, generated HTML reports, SVG, dashboards, diagrams, and any other output meant to be looked at. Use after render_chart / create_chart_view, after editing a post-Flint Vega-Lite spec, and before committing any generated HTML/SVG/PNG. Satisfied by the host's built-in browser tools or by the optional playwright MCP server.
    17 repo stars
  88. ▌
    Find Engineering Firm · gabrielmoreira
    Use whenever the user wants to find, shortlist, vet, or enrich US engineering firms — civil, structural, MEP, mechanical, electrical, geotechnical, transportation, environmental, and manufacturing. **For real-world engineering (buildings, infrastructure, manufacturing) — NOT software engineering.** Triggers on "find civil engineering firms in Florida for transportation", "shortlist three structural engineering firms with high-rise experience", "MEP consultancy for a hospital project", or "pull contact info for these 12 engineering firm domains", even when described indirectly (PE-stamped drawings, building-permit review). Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings. Defer software-dev / "engineering team" / SaaS-architecture asks to find-software-developer. Skip in-house engineering-manager hires, DIY questions, software-product comparisons (Revit, AutoCAD), non-US firms, individual freelancers.
    17 repo stars
  89. ▌
    Find Marketing Agency · gabrielmoreira
    Use whenever the user wants to find, shortlist, vet, or enrich US marketing agencies — including branding, content marketing, PPC/paid media, social media, email marketing, performance/demand-gen, video production, and full-service digital agencies. Triggers on requests like "shortlist three B2B branding agencies in California", "find a PPC shop with ecommerce experience", "we need a content marketing partner for a SaaS launch", or "pull contact info for these 12 agency domains", even when the need is described indirectly. Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings, and third-party listings. Skip SEO-only asks (use find-seo-agency), web/software-development asks (use find-web-developer or find-software-developer), recruiting an in-house marketing hire, "write me a marketing plan" do-the-work asks, non-US firms, individual freelancers, marketing-software-product recommendations, and consumer/personal-brand asks.
    17 repo stars
  90. ▌
    Ga4 Common Reports · gabrielmoreira
    Copy-paste recipes for the 6-7 reports every site owner actually wants: DAU/MAU/WAU, retention cohort, top pages by source, channel attribution, conversion funnel, geo breakdown, device split. Each recipe is a fully-formed Data API request. Trigger with "GA4 DAU", "GA4 retention", "GA4 top pages", "GA4 funnel", "GA4 channel report", "common GA4 reports".
    17 repo stars
  91. ▌
    Miro Sdk Patterns · gabrielmoreira
    Apply production-ready patterns for @mirohq/miro-api client usage. Use when implementing Miro integrations, refactoring SDK usage, or establishing coding standards for Miro REST API v2. Trigger with phrases like "miro SDK patterns", "miro best practices", "miro code patterns", "miro client wrapper", "miro typescript".
    17 repo stars
  92. ▌
    Assisting With Soc2 Audit Preparation · gabrielmoreira bundle
    Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification. Use when you need to prepare for SOC 2 audits, assess Trust Service Criteria compliance, document security controls, or generate readiness reports. Trigger with phrases like "SOC 2 audit preparation", "SOC 2 readiness assessment", "collect SOC 2 evidence", or "Trust Service Criteria compliance".
    17 repo stars
  93. ▌
    Snowflake Governance Coverage Auditor · gabrielmoreira bundle
    Audit trusted Snowflake classification, tags, masking, row access, projection, join, aggregation, and privacy-policy evidence without reading customer data. Use when governance enforcement may be missing or ambiguous. Trigger with "Snowflake governance coverage", "policy precedence", "tag policy gaps", "classification failure", or "POLICY_CONTEXT verification".
    17 repo stars
  94. ▌
    Snowflake Strong Auth Migration Pilot · gabrielmoreira bundle
    Pilot a Snowflake authentication modernization without lockouts or credential exposure. Inventory PERSON, SERVICE, and LEGACY_SERVICE users; map named workloads to WIF, key pair, OAuth, or bounded PAT; and audit managed MCP/OAuth session controls. Use when replacing Snowflake passwords, reviewing service identities, planning workload identity federation, or scoping MCP OAuth. Trigger with phrases like "Snowflake auth migration", "service user password", "Snowflake WIF", "key pair rotation", or "MCP OAuth role scope".
    17 repo stars
  95. ▌
    Environment Variables Handler · gabrielmoreira
    Manage environment variables handler operations. Auto-activating skill for DevOps Basics. Triggers on: environment variables handler, environment variables handler Part of the DevOps Basics skill category. Use when working with environment variables handler functionality. Trigger with phrases like "environment variables handler", "environment handler", "environment".
    17 repo stars
  96. ▌
    Elasticsearch Index Manager · gabrielmoreira
    Manage elasticsearch index manager operations. Auto-activating skill for DevOps Advanced. Triggers on: elasticsearch index manager, elasticsearch index manager Part of the DevOps Advanced skill category. Use when working with elasticsearch index manager functionality. Trigger with phrases like "elasticsearch index manager", "elasticsearch manager", "elasticsearch".
    17 repo stars
  97. ▌
    Prometheus Config Generator · gabrielmoreira
    Generate prometheus config generator operations. Auto-activating skill for DevOps Advanced. Triggers on: prometheus config generator, prometheus config generator Part of the DevOps Advanced skill category. Use when configuring systems or services. Trigger with phrases like "prometheus config generator", "prometheus generator", "prometheus".
    17 repo stars
  98. ▌
    Cors Policy Validator · gabrielmoreira
    Validate cors policy validator operations. Auto-activating skill for Security Fundamentals. Triggers on: cors policy validator, cors policy validator Part of the Security Fundamentals skill category. Use when working with cors policy validator functionality. Trigger with phrases like "cors policy validator", "cors validator", "cors".
    17 repo stars
  99. ▌
    Path Traversal Finder · gabrielmoreira
    Manage path traversal finder operations. Auto-activating skill for Security Fundamentals. Triggers on: path traversal finder, path traversal finder Part of the Security Fundamentals skill category. Use when working with path traversal finder functionality. Trigger with phrases like "path traversal finder", "path finder", "path".
    17 repo stars
  100. ▌
    Incident Response Planner · gabrielmoreira
    Configure incident response planner operations. Auto-activating skill for Security Advanced. Triggers on: incident response planner, incident response planner Part of the Security Advanced skill category. Use when working with incident response planner functionality. Trigger with phrases like "incident response planner", "incident planner", "incident".
    17 repo stars