gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Security Benchmark Runner · gabrielmoreiraManage security benchmark runner operations. Auto-activating skill for Security Advanced. Triggers on: security benchmark runner, security benchmark runner Part of the Security Advanced skill category. Use when working with security benchmark runner functionality. Trigger with phrases like "security benchmark runner", "security runner", "security".
- ▌ Security Policy Generator · gabrielmoreiraGenerate security policy generator operations. Auto-activating skill for Security Advanced. Triggers on: security policy generator, security policy generator Part of the Security Advanced skill category. Use when working with security policy generator functionality. Trigger with phrases like "security policy generator", "security generator", "security".
- ▌ Responsive Breakpoint Analyzer · gabrielmoreiraAnalyze responsive breakpoint analyzer operations. Auto-activating skill for Frontend Development. Triggers on: responsive breakpoint analyzer, responsive breakpoint analyzer Part of the Frontend Development skill category. Use when analyzing or auditing responsive breakpoint analyzer. Trigger with phrases like "responsive breakpoint analyzer", "responsive analyzer", "analyze responsive breakpoint r".
- ▌ Tensorflow Savedmodel Creator · gabrielmoreiraCreate tensorflow savedmodel creator operations. Auto-activating skill for ML Deployment. Triggers on: tensorflow savedmodel creator, tensorflow savedmodel creator Part of the ML Deployment skill category. Use when working with tensorflow savedmodel creator functionality. Trigger with phrases like "tensorflow savedmodel creator", "tensorflow creator", "tensorflow".
- ▌ Benchmark Suite Creator · gabrielmoreiraCreate benchmark suite creator operations. Auto-activating skill for Performance Testing. Triggers on: benchmark suite creator, benchmark suite creator Part of the Performance Testing skill category. Use when working with benchmark suite creator functionality. Trigger with phrases like "benchmark suite creator", "benchmark creator", "benchmark".
- ▌ Database Query Profiler · gabrielmoreiraProfile database query profiler operations. Auto-activating skill for Performance Testing. Triggers on: database query profiler, database query profiler Part of the Performance Testing skill category. Use when working with database query profiler functionality. Trigger with phrases like "database query profiler", "database profiler", "database".
- ▌ Visualization Best Practices · gabrielmoreiraManage visualization best practices operations. Auto-activating skill for Data Analytics. Triggers on: visualization best practices, visualization best practices Part of the Data Analytics skill category. Use when working with visualization best practices functionality. Trigger with phrases like "visualization best practices", "visualization practices", "visualization".
- ▌ Request Interceptor Creator · gabrielmoreiraCreate request interceptor creator operations. Auto-activating skill for API Integration. Triggers on: request interceptor creator, request interceptor creator Part of the API Integration skill category. Use when working with request interceptor creator functionality. Trigger with phrases like "request interceptor creator", "request creator", "request".
- ▌ Webhook Signature Validator · gabrielmoreiraValidate webhook signature validator operations. Auto-activating skill for API Integration. Triggers on: webhook signature validator, webhook signature validator Part of the API Integration skill category. Use when working with webhook signature validator functionality. Trigger with phrases like "webhook signature validator", "webhook validator", "webhook".
- ▌ Deprecation Notice Generator · gabrielmoreiraGenerate deprecation notice generator operations. Auto-activating skill for Technical Documentation. Triggers on: deprecation notice generator, deprecation notice generator Part of the Technical Documentation skill category. Use when working with deprecation notice generator functionality. Trigger with phrases like "deprecation notice generator", "deprecation generator", "deprecation".
- ▌ Incident Postmortem Template · gabrielmoreiraManage incident postmortem template operations. Auto-activating skill for Technical Documentation. Triggers on: incident postmortem template, incident postmortem template Part of the Technical Documentation skill category. Use when working with incident postmortem template functionality. Trigger with phrases like "incident postmortem template", "incident template", "incident".
- ▌ Architecture Diagram Creator · gabrielmoreiraCreate architecture diagram creator operations. Auto-activating skill for Visual Content. Triggers on: architecture diagram creator, architecture diagram creator Part of the Visual Content skill category. Use when working with architecture diagram creator functionality. Trigger with phrases like "architecture diagram creator", "architecture creator", "architecture".
- ▌ Excel Formula Generator · gabrielmoreiraGenerate excel formula generator operations. Auto-activating skill for Business Automation. Triggers on: excel formula generator, excel formula generator Part of the Business Automation skill category. Use when working with excel formula generator functionality. Trigger with phrases like "excel formula generator", "excel generator", "excel".
- ▌ Notification Dispatcher · gabrielmoreiraManage notification dispatcher operations. Auto-activating skill for Business Automation. Triggers on: notification dispatcher, notification dispatcher Part of the Business Automation skill category. Use when working with notification dispatcher functionality. Trigger with phrases like "notification dispatcher", "notification dispatcher", "notification".
- ▌ Reminder System Creator · gabrielmoreiraCreate reminder system creator operations. Auto-activating skill for Business Automation. Triggers on: reminder system creator, reminder system creator Part of the Business Automation skill category. Use when working with reminder system creator functionality. Trigger with phrases like "reminder system creator", "reminder creator", "reminder".
- ▌ Impact Analysis Helper · gabrielmoreiraConfigure with impact analysis helper operations. Auto-activating skill for Enterprise Workflows. Triggers on: impact analysis helper, impact analysis helper Part of the Enterprise Workflows skill category. Use when working with impact analysis helper functionality. Trigger with phrases like "impact analysis helper", "impact helper", "impact".
- ▌ Kpi Dashboard Template · gabrielmoreiraManage kpi dashboard template operations. Auto-activating skill for Enterprise Workflows. Triggers on: kpi dashboard template, kpi dashboard template Part of the Enterprise Workflows skill category. Use when working with kpi dashboard template functionality. Trigger with phrases like "kpi dashboard template", "kpi template", "kpi".
- ▌ Linear Issue Generator · gabrielmoreiraGenerate linear issue generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: linear issue generator, linear issue generator Part of the Enterprise Workflows skill category. Use when working with linear issue generator functionality. Trigger with phrases like "linear issue generator", "linear generator", "linear".
- ▌ Sprint Planning Helper · gabrielmoreiraConfigure with sprint planning helper operations. Auto-activating skill for Enterprise Workflows. Triggers on: sprint planning helper, sprint planning helper Part of the Enterprise Workflows skill category. Use when working with sprint planning helper functionality. Trigger with phrases like "sprint planning helper", "sprint helper", "sprint".
- ▌ Investigate Inventory Discrepancy · gabrielmoreira bundleInvestigate inventory discrepancies by tracing receiving, WMS balance, physical count, picking, and adjustment evidence.
- ▌ Analyze Labor Productivity · gabrielmoreira bundleAnalyze labor productivity from labor hours, output, process scope, standards, source records, and operational context.
- ▌ Balance Warehouse Workload · gabrielmoreira bundleBalance warehouse workload across areas, labor, equipment, priorities, time windows, and service constraints.
- ▌ Build Daily Warehouse Plan · gabrielmoreira bundleBuild daily warehouse operating plans from inbound, outbound, inventory work, labor, constraints, priorities, and handoffs.
- ▌ Diagnose Wms Inventory Issue · gabrielmoreira bundleDiagnose WMS inventory issues by reconciling balances, transaction history, physical evidence, master data, and source-system conflicts.
- ▌ Analyze Freight Accessorials · gabrielmoreira bundleAnalyze freight accessorials from invoice lines, carrier rules, shipment events, service constraints, and source evidence.
- ▌ Analyze Space Utilization · gabrielmoreira bundleAnalyze warehouse space utilization from facility areas, zones, aisles, support spaces, storage occupancy, and constraints.
- ▌ Compare Warehouse Layouts · gabrielmoreira bundleCompare warehouse layout alternatives by capacity, travel, flow, congestion, expansion, implementation risk, and review needs.
- ▌ Research Us Loading Security · gabrielmoreiraPrepare United States loading, cargo securement, seal, yard, dock, and shipment security research briefs for logistics operations.
- ▌ Research Us Workplace Safety · gabrielmoreiraPrepare source-backed United States workplace safety research briefs for logistics operations without issuing compliance determinations.
- ▌ Dpa Art 28 Oliver Schmidt Prietz · gabrielmoreira bundleReview, draft, or redline a Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag / AVV) under Art. 28 GDPR, or prepare a Joint Controller Arrangement under Art. 26 GDPR. Supports bilingual output (DE/EN), both controller- and processor-side perspectives, and two review depths — quick (Art. 28(3)(a)–(h) coverage) and negotiation-grade (clause-by-clause risk scoring).
- ▌ Matlab Generate Grader Assessments · gabrielmoreiraGenerate MATLAB Grader assessment item sets. Use when the user asks to create MATLAB Grader assessment items, generate MATLAB assessment materials, build MATLAB homework assessment items, QTI 3 portable assessment items, or mentions "grader assessment items". Produces complete assessment item folders with description, solution, template, tests, Function call blocks, and optional QTI 3 interchange files.
- ▌ Simulink Optimizing Embedded Code · gabrielmoreiraOptimizes Simulink models for Embedded Coder generated code. Use when asked to optimize or improve generated code, or reduce code metrics for a Simulink model. Targets: execution time, memory footprint (RAM, ROM, stack, data copies), code size, MISRA compliance, or any semantically similar generated-code metric. Works iteratively — measures baseline, suggests changes, applies, and re-measures to confirm improvement. Triggers can be prompts similar to: optimize generated code runtime, reduce runtime, shrink code size, improve code efficiency, reduce memory usage, speed up generated code, follow MISRA compliance and so on. CAUTION: Do NOT attempt to optimize Simulink models for generated code efficiency without following this skill — the iterative measurement, gating, and rollback workflow is essential for safe optimization.
- ▌ Specifying Mbd Algorithms · gabrielmoreiraSpecify algorithms for Model-Based Design: system specs, architecture specs, implementation plans, test plans. Use when creating specifications for controllers, signal processing, diagnostics, estimators, or other algorithms authored in Simulink, Stateflow, System Composer, or MATLAB Function blocks.
- ▌ Azure Monitor Opentelemetry Exporter Py · gabrielmoreiraAzure Monitor OpenTelemetry Exporter for Python. Use for low-level OpenTelemetry export to Application Insights. Triggers: "azure-monitor-opentelemetry-exporter", "AzureMonitorTraceExporter", "AzureMonitorMetricExporter", "AzureMonitorLogExporter".
- ▌ Building Adversary Infrastructure Tracking System · gabrielmoreira bundleBuild an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP enrichment to map threat-actor C2 networks and flag newly registered domains matching known patterns. Use when pivoting from known indicators to discover related C2 infrastructure or maintaining a continuously updated map of a threat actor's network.
- ▌ Building Threat Intelligence Enrichment In Splunk · gabrielmoreira bundleBuild automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time.
- ▌ Detecting Anomalies In Industrial Control Systems · gabrielmoreira bundleDeploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue devices, and mismatches against historian data. Use for continuous OT monitoring, baselining deterministic SCADA polling, or investigating alerts from Nozomi Guardian/Dragos needing deeper protocol analysis.
- ▌ Detecting AWS Credential Exposure With Trufflehog · gabrielmoreira bundleScan source code repositories, CI/CD pipelines, and configuration files for exposed AWS credentials using TruffleHog, git-secrets, and AWS-native detection. Use when integrating secrets scanning into CI/CD, auditing repositories (including git history) for historically committed AWS keys, responding to a GuardDuty alert about credential use from an unexpected location, or verifying credential rotation removed all exposed keys.
- ▌ Detecting Azure Storage Account Misconfigurations · gabrielmoreira bundleAudit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions, using the azure-mgmt-storage Python SDK to generate a risk-scored report. Use when assessing an Azure subscription's storage accounts for misconfiguration, building cloud security posture checks, or investigating a suspected data exposure via public blob access.
- ▌ Detecting Privilege Escalation In Kubernetes Pods · gabrielmoreira bundleDetects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux capabilities, and syscall patterns. Use when investigating a pod running as root or privileged, hardening workloads against in-pod escalation, or hunting for containers exceeding their intended scope. Keywords: allowPrivilegeEscalation, runAsRoot, capabilities, securityContext, OPA, Falco, audit log. Do not use for escalation through RBAC and service-account permissions - use auditing-kubernetes-rbac-privilege-escalation.
- ▌ Detecting T1548 Abuse Elevation Control Mechanism · gabrielmoreira bundleDetect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry changes, integrity-level transitions, and parent-child process relationships via Sysmon and Windows Security events. Use when hunting privilege-escalation activity or validating elevation-abuse detection coverage.
- ▌ Implementing Conditional Access Policies Azure Ad · gabrielmoreira bundleConfigures Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control, covering signal-based policy design, device compliance requirements, risk-based authentication, named locations, and session controls aligned to NIST SP 1800-35. Use when deploying or hardening conditional access policies, building zero trust security architecture in Entra ID, or preparing for a security assessment of Azure AD access controls.
- ▌ Implementing Google Workspace Phishing Protection · gabrielmoreira bundleConfigures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement. Use when hardening Gmail against phishing, spoofing, and malware, or when tuning Workspace email security policies.
- ▌ Implementing Hardware Security Key Authentication · gabrielmoreira bundleBuilds a FIDO2/WebAuthn relying party server with the python-fido2 library, covering registration and authentication ceremonies, YubiKey enrollment, resident key (discoverable credential/passkey) workflows, and user verification policies. Use when implementing phishing-resistant MFA with hardware security keys, building a WebAuthn relying party, enrolling YubiKeys for a workforce, or migrating password-based authentication to passkeys.
- ▌ Implementing Identity Verification For Zero Trust · gabrielmoreira bundleImplements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP 800-207 and the CISA Zero Trust Maturity Model Identity Pillar. Use when designing zero trust identity controls, deploying phishing-resistant MFA, or building conditional access policies based on device posture, behavior, and location.
- ▌ Implementing Network Traffic Analysis With Arkime · gabrielmoreira bundleQueries Arkime (formerly Moloch) full packet capture via its API to search sessions, download PCAPs, detect C2 beaconing through connection interval/jitter stats, spot DNS tunneling via query-length analysis, and flag known-bad TLS certificate issuers, using the bundled scripts/agent.py. Use when investigating suspicious network flows or doing full-packet-capture forensics against an Arkime deployment.
- ▌ Performing Bandwidth Throttling Attack Simulation · gabrielmoreira bundleSimulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of traffic manipulation. Use when validating how VoIP, video, or other real-time applications and network monitoring tools respond to degraded bandwidth or slowloris-style throttling attacks.
- ▌ Performing Cloud Asset Inventory With Cartography · gabrielmoreira bundleRun Cartography to sync AWS, GCP, or Azure resources into a Neo4j graph database, mapping relationships such as IAM permission chains, network paths, and cross-account trust. Use when building a cloud asset inventory, querying the graph to identify attack paths, or generating security reports across multi-cloud infrastructure.
- ▌ Performing Container Security Scanning With Trivy · gabrielmoreira bundleRuns Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed secrets, and licences, generating CycloneDX or SPDX SBOMs. Use when integrating Trivy into CI/CD, deploying the Trivy Kubernetes operator, scanning non-image targets, or triaging results at scale. Keywords: Trivy, trivy k8s, operator, SBOM, CycloneDX, SPDX, misconfig, secret scanning. Do not use for a single Docker image scan - use scanning-docker-images-with-trivy.
- ▌ Performing Static Malware Analysis With Pe Studio · gabrielmoreira bundlePerforms static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, and resources without executing the binary, identifying packing, anti-analysis tricks, and malicious imports. Use for pre-execution triage of a suspicious Windows executable before sandbox detonation.
- ▌ Performing Threat Landscape Assessment For Sector · gabrielmoreira bundleConducts a sector-specific threat landscape assessment (financial, healthcare, energy, government, etc.) by profiling targeting threat actors, mapping attack vectors and MITRE ATT&CK TTPs with the attackcti/pandas Python stack, and analyzing exploited CVEs and incident trends from ISAC and vendor reports. Use when producing CTI for risk management or board-level reporting on an industry's threat exposure.
- ▌ Testing API For Broken Object Level Authorization · gabrielmoreira bundleTests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR, OWASP API1:2023) by intercepting API calls, identifying object ID parameters (numeric IDs, UUIDs, slugs), and systematically substituting IDs belonging to other users to check whether the server enforces per-object authorization. Use when asked to test BOLA or IDOR in an API, verify object-level authorization, or assess an API for access control bypass.
- ▌ Compose Performance Audit · gabrielmoreiraAudit and improve Jetpack Compose runtime performance from code review and architecture. Use when asked to diagnose slow rendering, janky scrolling, excessive recompositions, or performance issues in Compose UI.
- ▌ Prior Auth Packet Builder · gabrielmoreiraBuild a concise prior authorization packet from local case files and payer policy docs.
- ▌ Modular Decomposition · gabrielmoreiraRuns a sequenced monolith-to-modular pipeline that sizes and inventories components, finds shared domain duplication, addresses flattening and hierarchy issues, analyzes coupling, then groups components into candidate domain-aligned units, with optional embedded DDD strategic analysis for bounded contexts. Use when asking how to split a monolith, size components before extraction, find duplicated domain logic, clean up module hierarchy, measure coupling between modules, or group components into services. Do NOT use for phased extraction roadmaps or prioritization without the prior analysis steps (use decomposition-planning-roadmap after this pipeline), end-to-end legacy migration strategy writeups (use legacy-migration-planner), pure infrastructure capacity sizing, or when you only need DDD without the structural pipeline (install domain-analysis standalone).
- ▌ Edgeone Pages Saas · gabrielmoreira bundleThis skill scaffolds and customizes a production-ready SaaS website on top of the TencentEdgeOne/saas-starter template (Next.js 14 + TypeScript + Tailwind + Supabase + Stripe + AI), and prepares it for deployment to EdgeOne Pages. It should be used when the user wants to start a new SaaS project, AI SaaS, or AI tool site from scratch — e.g. "build a SaaS site on EdgeOne Pages", "scaffold an AI SaaS with saas-starter", "帮我用 saas-starter 搭一个 SaaS", "初始化一个 AI 图片生成 SaaS 部署到 EdgeOne Pages", "create a new AI SaaS project". The skill first asks whether the user has their own product Prompt. If yes, it parses the Prompt to derive brand, features, color palette, and copy; if no, it runs a short built-in questionnaire (product direction / color / payments on-off / AI on-off / i18n). It then uses `npx degit TencentEdgeOne/saas-starter` to bootstrap, applies customizations, generates `.env.local`, and guides local run. Do NOT trigger when the user already has a running project and only wants to add a single function/API
- ▌ Foundations Grounding Communication · gabrielmoreiraGrounding-theory primitives for human-AI and agent handoffs, common ground, acceptance evidence, repair, and ambiguity. Use when coordinating meaning.
- ▌ Implementing Cloud Trail Log Analysis · gabrielmoreiraImplementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.
- ▌ Implementing Secret Scanning With Gitleaks · gabrielmoreiraThis skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.
- ▌ Implementing Endpoint Dlp Controls · gabrielmoreiraImplements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing. Use when deploying DLP agents, creating content inspection policies, or preventing unauthorized data movement from endpoints. Activates for requests involving DLP, data exfiltration prevention, content inspection, or sensitive data protection on endpoints.
- ▌ Performing Macos Privilege Escalation · gabrielmoreiraEscalating from a low-privileged user (or unprivileged process) to root on macOS during authorized engagements by abusing the user-preserved sudo PATH, Dock/app masquerading, sudo-password phishing, AuthorizationExecuteWithPrivileges helpers, vulnerable privileged XPC/LaunchDaemon helpers, writable LaunchDaemon plists, PackageKit/zsh logic bombs, kernel credential races, and Time Machine snapshot mounts.
- ▌ Pentesting Elasticsearch · gabrielmoreiraTesting Elasticsearch search/analytics clusters (default HTTP port 9200, transport 9300) for disabled authentication and full index dumping, default/weak credentials, write access to indices, and the historical Groovy/MVEL dynamic-scripting remote-code-execution CVEs (CVE-2015-1427, CVE-2014-3120) during authorized engagements.
- ▌ Performing Initial Access With Evilginx3 · gabrielmoreiraPerform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.
- ▌ Performing Lateral Movement With Wmiexec · gabrielmoreiraPerform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.
- ▌ Building Soc Metrics And Kpi Tracking · gabrielmoreiraBuilds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.
- ▌ Correlating Security Events In Qradar · gabrielmoreiraCorrelates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.
- ▌ Investigating Phishing Email Incident · gabrielmoreiraInvestigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
- ▌ Testing For Regex Dos Redos · gabrielmoreiraTesting web applications for Regular Expression Denial of Service (ReDoS), where crafted input forces a backtracking regex engine into super-linear (polynomial or exponential) processing time, hanging worker threads and causing denial of service. Also covers blind regex injection for char-by-char secret exfiltration when the attacker controls the pattern. Activates when input is matched against complex validators or when stored regex rules are attacker-influenced.
- ▌ Stat Research Orchestrator · gabrielmoreiraOrchestrate a statistical research pipeline centered on formal problem formulation, method proposal, theoretical analysis, experimental evaluation, comparison, and final result synthesis.
- ▌ Lasso Logistics Analysis · gabrielmoreiraUse when building a binary classification model from an expression matrix or other omics feature matrix with LASSO logistic regression, cross-validation, and coefficient path visualization. NOT for: multiclass classification, survival/Cox models, or ordinary linear regression.
- ▌ Sample Group Sankey Plot · gabrielmoreiraUse when generating Sankey or alluvial plots from sample annotation tables where rows are samples and selected columns are categorical stages such as risk group, response status, subtype, or cohort labels. NOT for: gene network flow analysis, continuous-value trajectories, or graph-structured pathway visualization.
- ▌ Evidence Level Ranker · gabrielmoreiraRanks papers by evidence family, methodological quality tier, validation depth, and claim discipline; assigns anchor, context-setting, mechanistic support, or caution citation roles; prevents prestige-based or design-label-based ranking errors.
- ▌ Topic Evidence Mapper · gabrielmoreiraRapidly maps the evidence landscape around a medical topic by organizing major research streams, target populations, endpoints, methods, evidence density, and thin areas. Use this skill BEFORE medical-research-gap-finder — it provides the structured landscape that makes formal gap analysis more rigorous. Do not use for formal gap identification, study design, or protocol planning directly.
- ▌ Medical Review Writer Architect · gabrielmoreiraA multi-stage workflow for writing long-form medical reviews; used when the user needs to build an outline based on PubMed literature, write chapter by chapter, perform supplementary searches, and format citations; input is the review topic and project directory, output is a c...
- ▌ Meta Analysis Methods Generator · gabrielmoreiraGenerates the Methods section for a meta-analysis paper, including search strategy, screening, quality assessment, data extraction, and statistical analysis.
- ▌ Unstructured Medical Text Miner · gabrielmoreiraMine unstructured clinical text from MIMIC-IV to extract diagnostic logic.
- ▌ Bio Differential Expression Batch Correction · gabrielmoreira bundleRemove batch effects from RNA-seq data using ComBat, ComBat-Seq, limma removeBatchEffect, and SVA for unknown batch variables. Use when correcting batch effects in expression data.
- ▌ Academic Research · gabrielmoreiraResearch project scaffolding, thesis/dissertation writing, literature reviews, publication workflows, and the AI assistant-assisted academic workflows
- ▌ Model Task Execution · gabrielmoreiraExecute an approved model task plan through Microsoft Foundry, Hugging Face, or ElevenLabs and record provider evidence. Use after model-router emits a valid plan and the user wants to run it, monitor jobs, cancel work, download outputs, or apply an approved fallback.
- ▌ Book Launch Content · gabrielmoreiraGenerate launch-companion content for books — blog posts, author notes, and dogfooding angles that demonstrate the book's thesis through its own production. Use when a manuscript is approaching publication submission (KDP, agent query, prelaunch).
- ▌ Docs Decay Velocity · gabrielmoreiraDocumentation decay rates by content type — hardcoded numbers and version pins rot fastest
- ▌ Assess Brain · gabrielmoreiraAssess active Markdown brain files in a local AI agent project or plugin source without changing it. Use before modifying a brain or reviewing declared instructions, skills, prompts, agents, bundled Markdown resources, and research documentation.
- ▌ Chart Big Idea · gabrielmoreiraDistill the one-sentence Big Idea, story arc, audience, and style stance for a chart BEFORE picking a chart type. Starts by questioning intent — whether the artifact should exist at all, and whether the stated purpose is the real one. Reads the surrounding docs / prose / ticket for an existing Big Idea first, then helps the user articulate one via a 3-question elicitation ladder if none is found. Asks whether the user wants a TRADITIONAL (safe) or INNOVATIVE (higher-impact, higher-risk) treatment. Use before invoking the flint-chart skill or the /render-chart prompt whenever the user's ask is 'chart this', 'visualize', 'make a chart', 'show the data', or when framing is unclear.
- ▌ Platform Architecture Analyze · gabrielmoreiraAnalyze a Salesforce project against the Salesforce Well-Architected framework (Trusted / Easy / Adaptable). Use when the developer asks to "review the architecture", "run a Well-Architected check", "audit this project", "is this project well-architected?", "assess security/governor-limit/packageability risk across the project", or wants a holistic code-and-metadata health report. Grades the criteria that are observable from code and metadata (sharing/FLS, bulkification, selective SOQL, trigger-handler separation, legacy tech, packageability) with file:line evidence, and emits a human checklist for governance/process pillars it cannot see (security matrix, BCP, roadmaps, AI governance). Distinct from `dx-code-analyzer-run` (single-tool Code Analyzer scan of Apex) — this skill is a multi-pillar architectural review that orchestrates several analysis skills and maps findings to Well-Architected. Read-only: it grades and advises, never edits.
- ▌ Platform Environment Validate · gabrielmoreiraValidate and configure the local Salesforce development environment. Runs a prerequisite scan showing 🔴/🟡/🟢 status for all required tools (Salesforce CLI, Code Analyzer plugin, Node.js, NPM, Git, Salesforce MCP, Source Tracking) and offers to install or update missing/outdated items. TRIGGER when the user runs /salesforce-development:platform-environment-validate, asks to 'check my setup', 'validate tools', 'verify prerequisites', 'am I set up correctly', or reports that a tool is missing or not working. DO NOT TRIGGER for: org authentication issues (use /salesforce-development:login), deployment problems (use platform-metadata-deploy), or general status checks (use /salesforce-development:status).
- ▌ Mdtraj Trajectory Analysis · gabrielmoreiramdtraj molecular dynamics trajectory analysis (Python). Reads DCD/XTC/TRR/NetCDF/H5/PDB topologies and trajectories; computes RMSD vs time, radius of gyration, per-residue RMSF, residue-residue contact frequency maps, phi/psi torsions for Ramachandran plots (general + Gly/Pro), and 8-state DSSP secondary structure. Modules: trajectory I/O, geometry (distances/angles/dihedrals), structural analysis (RMSD/Rg/RMSF/SASA), contacts, hydrogen bonds, secondary structure (DSSP), NMR observables. For broader atom-selection grammar use mdanalysis-trajectory; for running MD simulations use OpenMM/GROMACS.
- ▌ Find Service Providers · gabrielmoreiraUse whenever the user wants to find, shortlist, vet, enrich, or research US professional-services firms — law, marketing, consulting, accounting, IT services, architecture, engineering, HR, PR, design, and similar B2B service providers. Triggers on requests like "find me a PPC agency in California", "shortlist three boutique IP law firms", "build a longlist of 50 mid-size IT consultancies", or "here are 12 agency domains — pull contact info and confirm which are US-based", even when the need is described indirectly without naming a category. Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog with filters for industry, services, location, size, ratings, and third-party listings. Skip when the user is asking for personal/consumer services for themselves (an individual's own legal, tax, or medical needs), non-US firms, individual freelancers, retail/ecommerce/SaaS-product companies, recruiting-an-employee tasks, or general web research that doesn't need a structured firm directory.
- ▌ Attio Rate Limits · gabrielmoreiraHandle Attio API rate limits with exponential backoff, queue-based throttling, and Retry-After header parsing. Trigger: "attio rate limit", "attio 429", "attio throttling", "attio retry", "attio backoff", "attio too many requests".
- ▌ Analyzing Malware Behavior With Cuckoo Sandbox · gabrielmoreira bundleDetonate malware samples in Cuckoo Sandbox to observe runtime behavior — process creation, file system and registry changes, network communications, and API calls — and generate behavioral reports for classification and IOC extraction. Use when a sample has passed static triage and needs dynamic/behavioral analysis, when mapping a full infection chain, or when building YARA/behavioral signatures from observed sandbox activity.
- ▌ Analyzing Prefetch Files For Execution History · gabrielmoreira bundleParse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a suspicious binary ran, or correlating execution evidence with other forensic artifacts during an investigation.
- ▌ Building Identity Governance Lifecycle Process · gabrielmoreira bundleDesign identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests, periodic recertification, and orphaned-account remediation sourced from an HR feed. Use when automating cross-system JML provisioning, remediating former-employee access, or building lifecycle processes for SOX, HIPAA, or GDPR compliance.
- ▌ Building Red Team C2 Infrastructure With Havoc · gabrielmoreira bundleDeploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB listeners, Nginx redirectors, and Demon agents) with malleable traffic profiles and OPSEC-hardened infrastructure for authorized red team operations. Use when standing up or hardening Havoc C2 infrastructure for a written, authorized adversary emulation engagement.
- ▌ Conducting Social Engineering Penetration Test · gabrielmoreira bundleDesign and execute a social engineering penetration test combining OSINT-driven target profiling with phishing, vishing, smishing, and physical pretexting campaigns using tools like GoPhish, the Social Engineer Toolkit (SET), and Evilginx to measure human security resilience. Use when scoping or running an authorized human-attack-surface test and reporting results to identify security awareness training gaps.
- ▌ Configuring Certificate Authority With Openssl · gabrielmoreira bundleBuild a two-tier PKI Certificate Authority hierarchy (offline Root CA plus issuing Intermediate CA) using OpenSSL and the Python cryptography library, covering certificate extensions, CRL distribution points, OCSP responder configuration, and certificate policy management. Use when standing up an internal CA, issuing or revoking X.509 certificates, or designing PKI trust hierarchies for TLS, code-signing, or client-authentication use cases.
- ▌ Detecting Container Runtime Threats With Falco · gabrielmoreira bundleDeploys and operates Falco with the modern eBPF driver in Kubernetes and Docker, covering driver selection, Helm installation, output channels, and the built-in ruleset that detects container escape, namespace abuse, privileged mounts, and anomalous syscalls. Use when standing Falco up on a cluster, choosing between the eBPF and kernel-module drivers, routing Falco alerts into a SIEM or Falcosidekick, or upgrading an existing deployment. Keywords: Falco, modern_ebpf, kernel module, Helm, Falcosidekick, runtime security, syscall. Do not use for authoring individual escape rules - use detecting-container-escape-with-falco-rules.
- ▌ Detecting Qr Code Phishing With Email Security · gabrielmoreira bundleDetect and prevent QR code phishing (quishing) attacks that embed malicious URLs inside QR code images to bypass link-based email security, using image-based threat detection, OCR/QR decoding, and mobile-side scanning (Microsoft Defender for O365, Proofpoint TAP, Barracuda Multimodal AI). Use when configuring gateway rules against QR phishing or investigating suspicious emails containing QR codes.
- ▌ Exploiting Broken Function Level Authorization · gabrielmoreira bundleTests APIs for Broken Function Level Authorization (OWASP API5:2023) by identifying admin and privileged endpoints, then reaching them with regular-user credentials via HTTP method switching, URL path manipulation, and parameter tampering. Use when testing whether low-privilege users can invoke admin API functions or otherwise escalate privileges via function-level access control gaps.
- ▌ Hunting For Lolbins Execution In Endpoint Logs · gabrielmoreira bundleHunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes. Use when reviewing endpoint process telemetry for LOLBins-based defense evasion or building detections for signed-binary proxy execution.
- ▌ Implementing API Threat Protection With Apigee · gabrielmoreira bundleImplements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and Advanced API Security for detecting malicious clients. Use when shielding APIs proxied through Apigee against OWASP API Security Top 10 threats and malicious client abuse patterns.
- ▌ Implementing AWS Macie For Data Classification · gabrielmoreira bundleEnable and configure Amazon Macie via AWS CLI/Terraform to discover, classify, and protect sensitive data (PII, financial data, credentials) in S3 using ML and pattern matching, including discovery jobs, custom data identifiers, allow lists, and EventBridge-based remediation. Use when setting up S3 data classification, cloud DLP, or auditing S3 for unprotected sensitive data.