all publishers

gabrielmoreira

@gabrielmoreira source repo

21,231 published skills · page 75 of 213

  1. ▌
    Security Benchmark Runner · gabrielmoreira
    Manage security benchmark runner operations. Auto-activating skill for Security Advanced. Triggers on: security benchmark runner, security benchmark runner Part of the Security Advanced skill category. Use when working with security benchmark runner functionality. Trigger with phrases like "security benchmark runner", "security runner", "security".
    17 repo stars
  2. ▌
    Security Policy Generator · gabrielmoreira
    Generate security policy generator operations. Auto-activating skill for Security Advanced. Triggers on: security policy generator, security policy generator Part of the Security Advanced skill category. Use when working with security policy generator functionality. Trigger with phrases like "security policy generator", "security generator", "security".
    17 repo stars
  3. ▌
    Responsive Breakpoint Analyzer · gabrielmoreira
    Analyze responsive breakpoint analyzer operations. Auto-activating skill for Frontend Development. Triggers on: responsive breakpoint analyzer, responsive breakpoint analyzer Part of the Frontend Development skill category. Use when analyzing or auditing responsive breakpoint analyzer. Trigger with phrases like "responsive breakpoint analyzer", "responsive analyzer", "analyze responsive breakpoint r".
    17 repo stars
  4. ▌
    Tensorflow Savedmodel Creator · gabrielmoreira
    Create tensorflow savedmodel creator operations. Auto-activating skill for ML Deployment. Triggers on: tensorflow savedmodel creator, tensorflow savedmodel creator Part of the ML Deployment skill category. Use when working with tensorflow savedmodel creator functionality. Trigger with phrases like "tensorflow savedmodel creator", "tensorflow creator", "tensorflow".
    17 repo stars
  5. ▌
    Benchmark Suite Creator · gabrielmoreira
    Create benchmark suite creator operations. Auto-activating skill for Performance Testing. Triggers on: benchmark suite creator, benchmark suite creator Part of the Performance Testing skill category. Use when working with benchmark suite creator functionality. Trigger with phrases like "benchmark suite creator", "benchmark creator", "benchmark".
    17 repo stars
  6. ▌
    Database Query Profiler · gabrielmoreira
    Profile database query profiler operations. Auto-activating skill for Performance Testing. Triggers on: database query profiler, database query profiler Part of the Performance Testing skill category. Use when working with database query profiler functionality. Trigger with phrases like "database query profiler", "database profiler", "database".
    17 repo stars
  7. ▌
    Visualization Best Practices · gabrielmoreira
    Manage visualization best practices operations. Auto-activating skill for Data Analytics. Triggers on: visualization best practices, visualization best practices Part of the Data Analytics skill category. Use when working with visualization best practices functionality. Trigger with phrases like "visualization best practices", "visualization practices", "visualization".
    17 repo stars
  8. ▌
    Request Interceptor Creator · gabrielmoreira
    Create request interceptor creator operations. Auto-activating skill for API Integration. Triggers on: request interceptor creator, request interceptor creator Part of the API Integration skill category. Use when working with request interceptor creator functionality. Trigger with phrases like "request interceptor creator", "request creator", "request".
    17 repo stars
  9. ▌
    Webhook Signature Validator · gabrielmoreira
    Validate webhook signature validator operations. Auto-activating skill for API Integration. Triggers on: webhook signature validator, webhook signature validator Part of the API Integration skill category. Use when working with webhook signature validator functionality. Trigger with phrases like "webhook signature validator", "webhook validator", "webhook".
    17 repo stars
  10. ▌
    Deprecation Notice Generator · gabrielmoreira
    Generate deprecation notice generator operations. Auto-activating skill for Technical Documentation. Triggers on: deprecation notice generator, deprecation notice generator Part of the Technical Documentation skill category. Use when working with deprecation notice generator functionality. Trigger with phrases like "deprecation notice generator", "deprecation generator", "deprecation".
    17 repo stars
  11. ▌
    Incident Postmortem Template · gabrielmoreira
    Manage incident postmortem template operations. Auto-activating skill for Technical Documentation. Triggers on: incident postmortem template, incident postmortem template Part of the Technical Documentation skill category. Use when working with incident postmortem template functionality. Trigger with phrases like "incident postmortem template", "incident template", "incident".
    17 repo stars
  12. ▌
    Architecture Diagram Creator · gabrielmoreira
    Create architecture diagram creator operations. Auto-activating skill for Visual Content. Triggers on: architecture diagram creator, architecture diagram creator Part of the Visual Content skill category. Use when working with architecture diagram creator functionality. Trigger with phrases like "architecture diagram creator", "architecture creator", "architecture".
    17 repo stars
  13. ▌
    Excel Formula Generator · gabrielmoreira
    Generate excel formula generator operations. Auto-activating skill for Business Automation. Triggers on: excel formula generator, excel formula generator Part of the Business Automation skill category. Use when working with excel formula generator functionality. Trigger with phrases like "excel formula generator", "excel generator", "excel".
    17 repo stars
  14. ▌
    Notification Dispatcher · gabrielmoreira
    Manage notification dispatcher operations. Auto-activating skill for Business Automation. Triggers on: notification dispatcher, notification dispatcher Part of the Business Automation skill category. Use when working with notification dispatcher functionality. Trigger with phrases like "notification dispatcher", "notification dispatcher", "notification".
    17 repo stars
  15. ▌
    Reminder System Creator · gabrielmoreira
    Create reminder system creator operations. Auto-activating skill for Business Automation. Triggers on: reminder system creator, reminder system creator Part of the Business Automation skill category. Use when working with reminder system creator functionality. Trigger with phrases like "reminder system creator", "reminder creator", "reminder".
    17 repo stars
  16. ▌
    Impact Analysis Helper · gabrielmoreira
    Configure with impact analysis helper operations. Auto-activating skill for Enterprise Workflows. Triggers on: impact analysis helper, impact analysis helper Part of the Enterprise Workflows skill category. Use when working with impact analysis helper functionality. Trigger with phrases like "impact analysis helper", "impact helper", "impact".
    17 repo stars
  17. ▌
    Kpi Dashboard Template · gabrielmoreira
    Manage kpi dashboard template operations. Auto-activating skill for Enterprise Workflows. Triggers on: kpi dashboard template, kpi dashboard template Part of the Enterprise Workflows skill category. Use when working with kpi dashboard template functionality. Trigger with phrases like "kpi dashboard template", "kpi template", "kpi".
    17 repo stars
  18. ▌
    Linear Issue Generator · gabrielmoreira
    Generate linear issue generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: linear issue generator, linear issue generator Part of the Enterprise Workflows skill category. Use when working with linear issue generator functionality. Trigger with phrases like "linear issue generator", "linear generator", "linear".
    17 repo stars
  19. ▌
    Sprint Planning Helper · gabrielmoreira
    Configure with sprint planning helper operations. Auto-activating skill for Enterprise Workflows. Triggers on: sprint planning helper, sprint planning helper Part of the Enterprise Workflows skill category. Use when working with sprint planning helper functionality. Trigger with phrases like "sprint planning helper", "sprint helper", "sprint".
    17 repo stars
  20. ▌
    Investigate Inventory Discrepancy · gabrielmoreira bundle
    Investigate inventory discrepancies by tracing receiving, WMS balance, physical count, picking, and adjustment evidence.
    17 repo stars
  21. ▌
    Analyze Labor Productivity · gabrielmoreira bundle
    Analyze labor productivity from labor hours, output, process scope, standards, source records, and operational context.
    17 repo stars
  22. ▌
    Balance Warehouse Workload · gabrielmoreira bundle
    Balance warehouse workload across areas, labor, equipment, priorities, time windows, and service constraints.
    17 repo stars
  23. ▌
    Build Daily Warehouse Plan · gabrielmoreira bundle
    Build daily warehouse operating plans from inbound, outbound, inventory work, labor, constraints, priorities, and handoffs.
    17 repo stars
  24. ▌
    Diagnose Wms Inventory Issue · gabrielmoreira bundle
    Diagnose WMS inventory issues by reconciling balances, transaction history, physical evidence, master data, and source-system conflicts.
    17 repo stars
  25. ▌
    Analyze Freight Accessorials · gabrielmoreira bundle
    Analyze freight accessorials from invoice lines, carrier rules, shipment events, service constraints, and source evidence.
    17 repo stars
  26. ▌
    Analyze Space Utilization · gabrielmoreira bundle
    Analyze warehouse space utilization from facility areas, zones, aisles, support spaces, storage occupancy, and constraints.
    17 repo stars
  27. ▌
    Compare Warehouse Layouts · gabrielmoreira bundle
    Compare warehouse layout alternatives by capacity, travel, flow, congestion, expansion, implementation risk, and review needs.
    17 repo stars
  28. ▌
    Research Us Loading Security · gabrielmoreira
    Prepare United States loading, cargo securement, seal, yard, dock, and shipment security research briefs for logistics operations.
    17 repo stars
  29. ▌
    Research Us Workplace Safety · gabrielmoreira
    Prepare source-backed United States workplace safety research briefs for logistics operations without issuing compliance determinations.
    17 repo stars
  30. ▌
    Dpa Art 28 Oliver Schmidt Prietz · gabrielmoreira bundle
    Review, draft, or redline a Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag / AVV) under Art. 28 GDPR, or prepare a Joint Controller Arrangement under Art. 26 GDPR. Supports bilingual output (DE/EN), both controller- and processor-side perspectives, and two review depths — quick (Art. 28(3)(a)–(h) coverage) and negotiation-grade (clause-by-clause risk scoring).
    17 repo stars
  31. ▌
    Matlab Generate Grader Assessments · gabrielmoreira
    Generate MATLAB Grader assessment item sets. Use when the user asks to create MATLAB Grader assessment items, generate MATLAB assessment materials, build MATLAB homework assessment items, QTI 3 portable assessment items, or mentions "grader assessment items". Produces complete assessment item folders with description, solution, template, tests, Function call blocks, and optional QTI 3 interchange files.
    17 repo stars
  32. ▌
    Simulink Optimizing Embedded Code · gabrielmoreira
    Optimizes Simulink models for Embedded Coder generated code. Use when asked to optimize or improve generated code, or reduce code metrics for a Simulink model. Targets: execution time, memory footprint (RAM, ROM, stack, data copies), code size, MISRA compliance, or any semantically similar generated-code metric. Works iteratively — measures baseline, suggests changes, applies, and re-measures to confirm improvement. Triggers can be prompts similar to: optimize generated code runtime, reduce runtime, shrink code size, improve code efficiency, reduce memory usage, speed up generated code, follow MISRA compliance and so on. CAUTION: Do NOT attempt to optimize Simulink models for generated code efficiency without following this skill — the iterative measurement, gating, and rollback workflow is essential for safe optimization.
    17 repo stars
  33. ▌
    Specifying Mbd Algorithms · gabrielmoreira
    Specify algorithms for Model-Based Design: system specs, architecture specs, implementation plans, test plans. Use when creating specifications for controllers, signal processing, diagnostics, estimators, or other algorithms authored in Simulink, Stateflow, System Composer, or MATLAB Function blocks.
    17 repo stars
  34. ▌
    Azure Monitor Opentelemetry Exporter Py · gabrielmoreira
    Azure Monitor OpenTelemetry Exporter for Python. Use for low-level OpenTelemetry export to Application Insights. Triggers: "azure-monitor-opentelemetry-exporter", "AzureMonitorTraceExporter", "AzureMonitorMetricExporter", "AzureMonitorLogExporter".
    17 repo stars
  35. ▌
    Building Adversary Infrastructure Tracking System · gabrielmoreira bundle
    Build an automated adversary infrastructure tracking system in Python (dnspython, python-whois, shodan, networkx) that pivots across passive DNS, certificate transparency logs, WHOIS records, and IP enrichment to map threat-actor C2 networks and flag newly registered domains matching known patterns. Use when pivoting from known indicators to discover related C2 infrastructure or maintaining a continuously updated map of a threat actor's network.
    17 repo stars
  36. ▌
    Building Threat Intelligence Enrichment In Splunk · gabrielmoreira bundle
    Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time.
    17 repo stars
  37. ▌
    Detecting Anomalies In Industrial Control Systems · gabrielmoreira bundle
    Deploys anomaly detection for OT/ICS environments using machine learning on OT network baselines, physics-based process models, and Modbus/DNP3/OPC UA traffic analysis to flag deviations, rogue devices, and mismatches against historian data. Use for continuous OT monitoring, baselining deterministic SCADA polling, or investigating alerts from Nozomi Guardian/Dragos needing deeper protocol analysis.
    17 repo stars
  38. ▌
    Detecting AWS Credential Exposure With Trufflehog · gabrielmoreira bundle
    Scan source code repositories, CI/CD pipelines, and configuration files for exposed AWS credentials using TruffleHog, git-secrets, and AWS-native detection. Use when integrating secrets scanning into CI/CD, auditing repositories (including git history) for historically committed AWS keys, responding to a GuardDuty alert about credential use from an unexpected location, or verifying credential rotation removed all exposed keys.
    17 repo stars
  39. ▌
    Detecting Azure Storage Account Misconfigurations · gabrielmoreira bundle
    Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions, using the azure-mgmt-storage Python SDK to generate a risk-scored report. Use when assessing an Azure subscription's storage accounts for misconfiguration, building cloud security posture checks, or investigating a suspected data exposure via public blob access.
    17 repo stars
  40. ▌
    Detecting Privilege Escalation In Kubernetes Pods · gabrielmoreira bundle
    Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux capabilities, and syscall patterns. Use when investigating a pod running as root or privileged, hardening workloads against in-pod escalation, or hunting for containers exceeding their intended scope. Keywords: allowPrivilegeEscalation, runAsRoot, capabilities, securityContext, OPA, Falco, audit log. Do not use for escalation through RBAC and service-account permissions - use auditing-kubernetes-rbac-privilege-escalation.
    17 repo stars
  41. ▌
    Detecting T1548 Abuse Elevation Control Mechanism · gabrielmoreira bundle
    Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry changes, integrity-level transitions, and parent-child process relationships via Sysmon and Windows Security events. Use when hunting privilege-escalation activity or validating elevation-abuse detection coverage.
    17 repo stars
  42. ▌
    Implementing Conditional Access Policies Azure Ad · gabrielmoreira bundle
    Configures Microsoft Entra ID (Azure AD) Conditional Access policies for zero trust access control, covering signal-based policy design, device compliance requirements, risk-based authentication, named locations, and session controls aligned to NIST SP 1800-35. Use when deploying or hardening conditional access policies, building zero trust security architecture in Entra ID, or preparing for a security assessment of Azure AD access controls.
    17 repo stars
  43. ▌
    Implementing Google Workspace Phishing Protection · gabrielmoreira bundle
    Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement. Use when hardening Gmail against phishing, spoofing, and malware, or when tuning Workspace email security policies.
    17 repo stars
  44. ▌
    Implementing Hardware Security Key Authentication · gabrielmoreira bundle
    Builds a FIDO2/WebAuthn relying party server with the python-fido2 library, covering registration and authentication ceremonies, YubiKey enrollment, resident key (discoverable credential/passkey) workflows, and user verification policies. Use when implementing phishing-resistant MFA with hardware security keys, building a WebAuthn relying party, enrolling YubiKeys for a workforce, or migrating password-based authentication to passkeys.
    17 repo stars
  45. ▌
    Implementing Identity Verification For Zero Trust · gabrielmoreira bundle
    Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP 800-207 and the CISA Zero Trust Maturity Model Identity Pillar. Use when designing zero trust identity controls, deploying phishing-resistant MFA, or building conditional access policies based on device posture, behavior, and location.
    17 repo stars
  46. ▌
    Implementing Network Traffic Analysis With Arkime · gabrielmoreira bundle
    Queries Arkime (formerly Moloch) full packet capture via its API to search sessions, download PCAPs, detect C2 beaconing through connection interval/jitter stats, spot DNS tunneling via query-length analysis, and flag known-bad TLS certificate issuers, using the bundled scripts/agent.py. Use when investigating suspicious network flows or doing full-packet-capture forensics against an Arkime deployment.
    17 repo stars
  47. ▌
    Performing Bandwidth Throttling Attack Simulation · gabrielmoreira bundle
    Simulate bandwidth throttling and network degradation attacks using tc, iperf3, and Scapy in authorized lab environments to test QoS controls, application resilience, and monitoring detection of traffic manipulation. Use when validating how VoIP, video, or other real-time applications and network monitoring tools respond to degraded bandwidth or slowloris-style throttling attacks.
    17 repo stars
  48. ▌
    Performing Cloud Asset Inventory With Cartography · gabrielmoreira bundle
    Run Cartography to sync AWS, GCP, or Azure resources into a Neo4j graph database, mapping relationships such as IAM permission chains, network paths, and cross-account trust. Use when building a cloud asset inventory, querying the graph to identify attack paths, or generating security reports across multi-cloud infrastructure.
    17 repo stars
  49. ▌
    Performing Container Security Scanning With Trivy · gabrielmoreira bundle
    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed secrets, and licences, generating CycloneDX or SPDX SBOMs. Use when integrating Trivy into CI/CD, deploying the Trivy Kubernetes operator, scanning non-image targets, or triaging results at scale. Keywords: Trivy, trivy k8s, operator, SBOM, CycloneDX, SPDX, misconfig, secret scanning. Do not use for a single Docker image scan - use scanning-docker-images-with-trivy.
    17 repo stars
  50. ▌
    Performing Static Malware Analysis With Pe Studio · gabrielmoreira bundle
    Performs static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, and resources without executing the binary, identifying packing, anti-analysis tricks, and malicious imports. Use for pre-execution triage of a suspicious Windows executable before sandbox detonation.
    17 repo stars
  51. ▌
    Performing Threat Landscape Assessment For Sector · gabrielmoreira bundle
    Conducts a sector-specific threat landscape assessment (financial, healthcare, energy, government, etc.) by profiling targeting threat actors, mapping attack vectors and MITRE ATT&CK TTPs with the attackcti/pandas Python stack, and analyzing exploited CVEs and incident trends from ISAC and vendor reports. Use when producing CTI for risk management or board-level reporting on an industry's threat exposure.
    17 repo stars
  52. ▌
    Testing API For Broken Object Level Authorization · gabrielmoreira bundle
    Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR, OWASP API1:2023) by intercepting API calls, identifying object ID parameters (numeric IDs, UUIDs, slugs), and systematically substituting IDs belonging to other users to check whether the server enforces per-object authorization. Use when asked to test BOLA or IDOR in an API, verify object-level authorization, or assess an API for access control bypass.
    17 repo stars
  53. ▌
    Compose Performance Audit · gabrielmoreira
    Audit and improve Jetpack Compose runtime performance from code review and architecture. Use when asked to diagnose slow rendering, janky scrolling, excessive recompositions, or performance issues in Compose UI.
    17 repo stars
  54. ▌
    Prior Auth Packet Builder · gabrielmoreira
    Build a concise prior authorization packet from local case files and payer policy docs.
    17 repo stars
  55. ▌
    Modular Decomposition · gabrielmoreira
    Runs a sequenced monolith-to-modular pipeline that sizes and inventories components, finds shared domain duplication, addresses flattening and hierarchy issues, analyzes coupling, then groups components into candidate domain-aligned units, with optional embedded DDD strategic analysis for bounded contexts. Use when asking how to split a monolith, size components before extraction, find duplicated domain logic, clean up module hierarchy, measure coupling between modules, or group components into services. Do NOT use for phased extraction roadmaps or prioritization without the prior analysis steps (use decomposition-planning-roadmap after this pipeline), end-to-end legacy migration strategy writeups (use legacy-migration-planner), pure infrastructure capacity sizing, or when you only need DDD without the structural pipeline (install domain-analysis standalone).
    17 repo stars
  56. ▌
    Edgeone Pages Saas · gabrielmoreira bundle
    This skill scaffolds and customizes a production-ready SaaS website on top of the TencentEdgeOne/saas-starter template (Next.js 14 + TypeScript + Tailwind + Supabase + Stripe + AI), and prepares it for deployment to EdgeOne Pages. It should be used when the user wants to start a new SaaS project, AI SaaS, or AI tool site from scratch — e.g. "build a SaaS site on EdgeOne Pages", "scaffold an AI SaaS with saas-starter", "帮我用 saas-starter 搭一个 SaaS", "初始化一个 AI 图片生成 SaaS 部署到 EdgeOne Pages", "create a new AI SaaS project". The skill first asks whether the user has their own product Prompt. If yes, it parses the Prompt to derive brand, features, color palette, and copy; if no, it runs a short built-in questionnaire (product direction / color / payments on-off / AI on-off / i18n). It then uses `npx degit TencentEdgeOne/saas-starter` to bootstrap, applies customizations, generates `.env.local`, and guides local run. Do NOT trigger when the user already has a running project and only wants to add a single function/API
    17 repo stars
  57. ▌
    Foundations Grounding Communication · gabrielmoreira
    Grounding-theory primitives for human-AI and agent handoffs, common ground, acceptance evidence, repair, and ambiguity. Use when coordinating meaning.
    17 repo stars
  58. ▌
    Implementing Cloud Trail Log Analysis · gabrielmoreira
    Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.
    17 repo stars
  59. ▌
    Implementing Secret Scanning With Gitleaks · gabrielmoreira
    This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.
    17 repo stars
  60. ▌
    Implementing Endpoint Dlp Controls · gabrielmoreira
    Implements endpoint Data Loss Prevention (DLP) controls to detect and prevent sensitive data exfiltration through email, USB, cloud storage, and printing. Use when deploying DLP agents, creating content inspection policies, or preventing unauthorized data movement from endpoints. Activates for requests involving DLP, data exfiltration prevention, content inspection, or sensitive data protection on endpoints.
    17 repo stars
  61. ▌
    Performing Macos Privilege Escalation · gabrielmoreira
    Escalating from a low-privileged user (or unprivileged process) to root on macOS during authorized engagements by abusing the user-preserved sudo PATH, Dock/app masquerading, sudo-password phishing, AuthorizationExecuteWithPrivileges helpers, vulnerable privileged XPC/LaunchDaemon helpers, writable LaunchDaemon plists, PackageKit/zsh logic bombs, kernel credential races, and Time Machine snapshot mounts.
    17 repo stars
  62. ▌
    Pentesting Elasticsearch · gabrielmoreira
    Testing Elasticsearch search/analytics clusters (default HTTP port 9200, transport 9300) for disabled authentication and full index dumping, default/weak credentials, write access to indices, and the historical Groovy/MVEL dynamic-scripting remote-code-execution CVEs (CVE-2015-1427, CVE-2014-3120) during authorized engagements.
    17 repo stars
  63. ▌
    Performing Initial Access With Evilginx3 · gabrielmoreira
    Perform authorized initial access using EvilGinx3 adversary-in-the-middle phishing framework to capture session tokens and bypass multi-factor authentication during red team engagements.
    17 repo stars
  64. ▌
    Performing Lateral Movement With Wmiexec · gabrielmoreira
    Perform lateral movement across Windows networks using WMI-based remote execution techniques including Impacket wmiexec.py, CrackMapExec, and native WMI commands for stealthy post-exploitation during red team engagements.
    17 repo stars
  65. ▌
    Building Soc Metrics And Kpi Tracking · gabrielmoreira
    Builds SOC performance metrics and KPI tracking dashboards measuring Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert quality ratios, analyst productivity, and detection coverage using SIEM data. Use when SOC leadership needs operational visibility, continuous improvement tracking, or executive-level reporting on security operations effectiveness.
    17 repo stars
  66. ▌
    Correlating Security Events In Qradar · gabrielmoreira
    Correlates security events in IBM QRadar SIEM using AQL (Ariel Query Language), custom rules, building blocks, and offense management to detect multi-stage attacks across network, endpoint, and application log sources. Use when SOC analysts need to investigate QRadar offenses, build correlation rules, or tune detection logic for reducing false positives.
    17 repo stars
  67. ▌
    Investigating Phishing Email Incident · gabrielmoreira
    Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
    17 repo stars
  68. ▌
    Testing For Regex Dos Redos · gabrielmoreira
    Testing web applications for Regular Expression Denial of Service (ReDoS), where crafted input forces a backtracking regex engine into super-linear (polynomial or exponential) processing time, hanging worker threads and causing denial of service. Also covers blind regex injection for char-by-char secret exfiltration when the attacker controls the pattern. Activates when input is matched against complex validators or when stored regex rules are attacker-influenced.
    17 repo stars
  69. ▌
    Stat Research Orchestrator · gabrielmoreira
    Orchestrate a statistical research pipeline centered on formal problem formulation, method proposal, theoretical analysis, experimental evaluation, comparison, and final result synthesis.
    17 repo stars
  70. ▌
    Lasso Logistics Analysis · gabrielmoreira
    Use when building a binary classification model from an expression matrix or other omics feature matrix with LASSO logistic regression, cross-validation, and coefficient path visualization. NOT for: multiclass classification, survival/Cox models, or ordinary linear regression.
    17 repo stars
  71. ▌
    Sample Group Sankey Plot · gabrielmoreira
    Use when generating Sankey or alluvial plots from sample annotation tables where rows are samples and selected columns are categorical stages such as risk group, response status, subtype, or cohort labels. NOT for: gene network flow analysis, continuous-value trajectories, or graph-structured pathway visualization.
    17 repo stars
  72. ▌
    Evidence Level Ranker · gabrielmoreira
    Ranks papers by evidence family, methodological quality tier, validation depth, and claim discipline; assigns anchor, context-setting, mechanistic support, or caution citation roles; prevents prestige-based or design-label-based ranking errors.
    17 repo stars
  73. ▌
    Topic Evidence Mapper · gabrielmoreira
    Rapidly maps the evidence landscape around a medical topic by organizing major research streams, target populations, endpoints, methods, evidence density, and thin areas. Use this skill BEFORE medical-research-gap-finder — it provides the structured landscape that makes formal gap analysis more rigorous. Do not use for formal gap identification, study design, or protocol planning directly.
    17 repo stars
  74. ▌
    Medical Review Writer Architect · gabrielmoreira
    A multi-stage workflow for writing long-form medical reviews; used when the user needs to build an outline based on PubMed literature, write chapter by chapter, perform supplementary searches, and format citations; input is the review topic and project directory, output is a c...
    17 repo stars
  75. ▌
    Meta Analysis Methods Generator · gabrielmoreira
    Generates the Methods section for a meta-analysis paper, including search strategy, screening, quality assessment, data extraction, and statistical analysis.
    17 repo stars
  76. ▌
    Unstructured Medical Text Miner · gabrielmoreira
    Mine unstructured clinical text from MIMIC-IV to extract diagnostic logic.
    17 repo stars
  77. ▌
    Bio Differential Expression Batch Correction · gabrielmoreira bundle
    Remove batch effects from RNA-seq data using ComBat, ComBat-Seq, limma removeBatchEffect, and SVA for unknown batch variables. Use when correcting batch effects in expression data.
    17 repo stars
  78. ▌
    Academic Research · gabrielmoreira
    Research project scaffolding, thesis/dissertation writing, literature reviews, publication workflows, and the AI assistant-assisted academic workflows
    17 repo stars
  79. ▌
    Model Task Execution · gabrielmoreira
    Execute an approved model task plan through Microsoft Foundry, Hugging Face, or ElevenLabs and record provider evidence. Use after model-router emits a valid plan and the user wants to run it, monitor jobs, cancel work, download outputs, or apply an approved fallback.
    17 repo stars
  80. ▌
    Book Launch Content · gabrielmoreira
    Generate launch-companion content for books — blog posts, author notes, and dogfooding angles that demonstrate the book's thesis through its own production. Use when a manuscript is approaching publication submission (KDP, agent query, prelaunch).
    17 repo stars
  81. ▌
    Docs Decay Velocity · gabrielmoreira
    Documentation decay rates by content type — hardcoded numbers and version pins rot fastest
    17 repo stars
  82. ▌
    Assess Brain · gabrielmoreira
    Assess active Markdown brain files in a local AI agent project or plugin source without changing it. Use before modifying a brain or reviewing declared instructions, skills, prompts, agents, bundled Markdown resources, and research documentation.
    17 repo stars
  83. ▌
    Chart Big Idea · gabrielmoreira
    Distill the one-sentence Big Idea, story arc, audience, and style stance for a chart BEFORE picking a chart type. Starts by questioning intent — whether the artifact should exist at all, and whether the stated purpose is the real one. Reads the surrounding docs / prose / ticket for an existing Big Idea first, then helps the user articulate one via a 3-question elicitation ladder if none is found. Asks whether the user wants a TRADITIONAL (safe) or INNOVATIVE (higher-impact, higher-risk) treatment. Use before invoking the flint-chart skill or the /render-chart prompt whenever the user's ask is 'chart this', 'visualize', 'make a chart', 'show the data', or when framing is unclear.
    17 repo stars
  84. ▌
    Platform Architecture Analyze · gabrielmoreira
    Analyze a Salesforce project against the Salesforce Well-Architected framework (Trusted / Easy / Adaptable). Use when the developer asks to "review the architecture", "run a Well-Architected check", "audit this project", "is this project well-architected?", "assess security/governor-limit/packageability risk across the project", or wants a holistic code-and-metadata health report. Grades the criteria that are observable from code and metadata (sharing/FLS, bulkification, selective SOQL, trigger-handler separation, legacy tech, packageability) with file:line evidence, and emits a human checklist for governance/process pillars it cannot see (security matrix, BCP, roadmaps, AI governance). Distinct from `dx-code-analyzer-run` (single-tool Code Analyzer scan of Apex) — this skill is a multi-pillar architectural review that orchestrates several analysis skills and maps findings to Well-Architected. Read-only: it grades and advises, never edits.
    17 repo stars
  85. ▌
    Platform Environment Validate · gabrielmoreira
    Validate and configure the local Salesforce development environment. Runs a prerequisite scan showing 🔴/🟡/🟢 status for all required tools (Salesforce CLI, Code Analyzer plugin, Node.js, NPM, Git, Salesforce MCP, Source Tracking) and offers to install or update missing/outdated items. TRIGGER when the user runs /salesforce-development:platform-environment-validate, asks to 'check my setup', 'validate tools', 'verify prerequisites', 'am I set up correctly', or reports that a tool is missing or not working. DO NOT TRIGGER for: org authentication issues (use /salesforce-development:login), deployment problems (use platform-metadata-deploy), or general status checks (use /salesforce-development:status).
    17 repo stars
  86. ▌
    Mdtraj Trajectory Analysis · gabrielmoreira
    mdtraj molecular dynamics trajectory analysis (Python). Reads DCD/XTC/TRR/NetCDF/H5/PDB topologies and trajectories; computes RMSD vs time, radius of gyration, per-residue RMSF, residue-residue contact frequency maps, phi/psi torsions for Ramachandran plots (general + Gly/Pro), and 8-state DSSP secondary structure. Modules: trajectory I/O, geometry (distances/angles/dihedrals), structural analysis (RMSD/Rg/RMSF/SASA), contacts, hydrogen bonds, secondary structure (DSSP), NMR observables. For broader atom-selection grammar use mdanalysis-trajectory; for running MD simulations use OpenMM/GROMACS.
    17 repo stars
  87. ▌
    Find Service Providers · gabrielmoreira
    Use whenever the user wants to find, shortlist, vet, enrich, or research US professional-services firms — law, marketing, consulting, accounting, IT services, architecture, engineering, HR, PR, design, and similar B2B service providers. Triggers on requests like "find me a PPC agency in California", "shortlist three boutique IP law firms", "build a longlist of 50 mid-size IT consultancies", or "here are 12 agency domains — pull contact info and confirm which are US-based", even when the need is described indirectly without naming a category. Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog with filters for industry, services, location, size, ratings, and third-party listings. Skip when the user is asking for personal/consumer services for themselves (an individual's own legal, tax, or medical needs), non-US firms, individual freelancers, retail/ecommerce/SaaS-product companies, recruiting-an-employee tasks, or general web research that doesn't need a structured firm directory.
    17 repo stars
  88. ▌
    Attio Rate Limits · gabrielmoreira
    Handle Attio API rate limits with exponential backoff, queue-based throttling, and Retry-After header parsing. Trigger: "attio rate limit", "attio 429", "attio throttling", "attio retry", "attio backoff", "attio too many requests".
    17 repo stars
  89. ▌
    Analyzing Malware Behavior With Cuckoo Sandbox · gabrielmoreira bundle
    Detonate malware samples in Cuckoo Sandbox to observe runtime behavior — process creation, file system and registry changes, network communications, and API calls — and generate behavioral reports for classification and IOC extraction. Use when a sample has passed static triage and needs dynamic/behavioral analysis, when mapping a full infection chain, or when building YARA/behavioral signatures from observed sandbox activity.
    17 repo stars
  90. ▌
    Analyzing Prefetch Files For Execution History · gabrielmoreira bundle
    Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a suspicious binary ran, or correlating execution evidence with other forensic artifacts during an investigation.
    17 repo stars
  91. ▌
    Building Identity Governance Lifecycle Process · gabrielmoreira bundle
    Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests, periodic recertification, and orphaned-account remediation sourced from an HR feed. Use when automating cross-system JML provisioning, remediating former-employee access, or building lifecycle processes for SOX, HIPAA, or GDPR compliance.
    17 repo stars
  92. ▌
    Building Red Team C2 Infrastructure With Havoc · gabrielmoreira bundle
    Deploy and configure the Havoc C2 framework (teamserver, HTTPS/HTTP/SMB listeners, Nginx redirectors, and Demon agents) with malleable traffic profiles and OPSEC-hardened infrastructure for authorized red team operations. Use when standing up or hardening Havoc C2 infrastructure for a written, authorized adversary emulation engagement.
    17 repo stars
  93. ▌
    Conducting Social Engineering Penetration Test · gabrielmoreira bundle
    Design and execute a social engineering penetration test combining OSINT-driven target profiling with phishing, vishing, smishing, and physical pretexting campaigns using tools like GoPhish, the Social Engineer Toolkit (SET), and Evilginx to measure human security resilience. Use when scoping or running an authorized human-attack-surface test and reporting results to identify security awareness training gaps.
    17 repo stars
  94. ▌
    Configuring Certificate Authority With Openssl · gabrielmoreira bundle
    Build a two-tier PKI Certificate Authority hierarchy (offline Root CA plus issuing Intermediate CA) using OpenSSL and the Python cryptography library, covering certificate extensions, CRL distribution points, OCSP responder configuration, and certificate policy management. Use when standing up an internal CA, issuing or revoking X.509 certificates, or designing PKI trust hierarchies for TLS, code-signing, or client-authentication use cases.
    17 repo stars
  95. ▌
    Detecting Container Runtime Threats With Falco · gabrielmoreira bundle
    Deploys and operates Falco with the modern eBPF driver in Kubernetes and Docker, covering driver selection, Helm installation, output channels, and the built-in ruleset that detects container escape, namespace abuse, privileged mounts, and anomalous syscalls. Use when standing Falco up on a cluster, choosing between the eBPF and kernel-module drivers, routing Falco alerts into a SIEM or Falcosidekick, or upgrading an existing deployment. Keywords: Falco, modern_ebpf, kernel module, Helm, Falcosidekick, runtime security, syscall. Do not use for authoring individual escape rules - use detecting-container-escape-with-falco-rules.
    17 repo stars
  96. ▌
    Detecting Qr Code Phishing With Email Security · gabrielmoreira bundle
    Detect and prevent QR code phishing (quishing) attacks that embed malicious URLs inside QR code images to bypass link-based email security, using image-based threat detection, OCR/QR decoding, and mobile-side scanning (Microsoft Defender for O365, Proofpoint TAP, Barracuda Multimodal AI). Use when configuring gateway rules against QR phishing or investigating suspicious emails containing QR codes.
    17 repo stars
  97. ▌
    Exploiting Broken Function Level Authorization · gabrielmoreira bundle
    Tests APIs for Broken Function Level Authorization (OWASP API5:2023) by identifying admin and privileged endpoints, then reaching them with regular-user credentials via HTTP method switching, URL path manipulation, and parameter tampering. Use when testing whether low-privilege users can invoke admin API functions or otherwise escalate privileges via function-level access control gaps.
    17 repo stars
  98. ▌
    Hunting For Lolbins Execution In Endpoint Logs · gabrielmoreira bundle
    Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries used for malicious purposes. Use when reviewing endpoint process telemetry for LOLBins-based defense evasion or building detections for signed-binary proxy execution.
    17 repo stars
  99. ▌
    Implementing API Threat Protection With Apigee · gabrielmoreira bundle
    Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and Advanced API Security for detecting malicious clients. Use when shielding APIs proxied through Apigee against OWASP API Security Top 10 threats and malicious client abuse patterns.
    17 repo stars
  100. ▌
    Implementing AWS Macie For Data Classification · gabrielmoreira bundle
    Enable and configure Amazon Macie via AWS CLI/Terraform to discover, classify, and protect sensitive data (PII, financial data, credentials) in S3 using ML and pattern matching, including discovery jobs, custom data identifiers, allow lists, and EventBridge-based remediation. Use when setting up S3 data classification, cloud DLP, or auditing S3 for unprotected sensitive data.
    17 repo stars