all publishers

gabrielmoreira

@gabrielmoreira source repo

21,231 published skills · page 76 of 213

  1. ▌
    Implementing Cloud Security Posture Management · gabrielmoreira bundle
    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for Cloud, and GCP Security Command Center. Use for cross-cloud posture monitoring, CIS/SOC 2/PCI DSS compliance, or drift-detection workflows; not for runtime workload protection or application security testing.
    17 repo stars
  2. ▌
    Implementing Dragos Platform For Ot Monitoring · gabrielmoreira bundle
    Deploys and configures Dragos Platform sensors and detection analytics for OT/ICS network monitoring, using industrial protocol parsers and threat-intel packs to detect groups like VOLTZITE, CHERNOVITE, and KAMACITE. Use when standing up OT-specific network detection and response or an OT SOC, or integrating OT monitoring into an enterprise SIEM; not for IT-only or Claroty/Nozomi environments.
    17 repo stars
  3. ▌
    Implementing Kubernetes Pod Security Standards · gabrielmoreira bundle
    Chooses and applies the correct Kubernetes Pod Security Standard (Privileged, Baseline, Restricted) for a workload: what each profile forbids, how to map existing workloads to a profile, which securityContext fields must change, and how to plan a PodSecurityPolicy-to-PSS migration without breaking running pods. Use when deciding which pod security profile a namespace or workload should run under, auditing which workloads would fail Restricted, planning a PSP migration, or mapping pod security posture to a compliance control. Keywords: Pod Security Standards, PSS, Privileged, Baseline, Restricted, securityContext, runAsNonRoot, drop ALL capabilities, seccomp RuntimeDefault, PSP migration. Do not use for configuring the admission controller that enforces these profiles - use implementing-pod-security-admission-controller.
    17 repo stars
  4. ▌
    Implementing Microsegmentation With Guardicore · gabrielmoreira bundle
    Implements microsegmentation with Akamai Guardicore Segmentation to map application dependencies, visualize east-west traffic flows, and create granular, least-privilege network policies across VMs, containers, bare metal, and cloud. Use when blocking lateral movement in a data center or when PCI DSS/HIPAA compliance requires validated network segmentation.
    17 repo stars
  5. ▌
    Implementing Pod Security Admission Controller · gabrielmoreira bundle
    Configures and operates the Kubernetes Pod Security Admission (PSA) controller that enforces Pod Security Standards: namespace enforce/audit/warn labels, cluster-wide defaults via AdmissionConfiguration, exemptions for usernames, runtime classes and namespaces, version pinning, and troubleshooting pods the controller rejected. Use when wiring PSA up on a cluster, setting cluster-wide default enforcement, exempting system namespaces, debugging why a pod was rejected or why enforcement is not firing, or reading PSA audit and warning output. Keywords: Pod Security Admission, PSA, admission controller, AdmissionConfiguration, pod-security.kubernetes.io labels, enforce audit warn, exemptions, kube-apiserver. Do not use for choosing which security profile a workload needs - use implementing-kubernetes-pod-security-standards.
    17 repo stars
  6. ▌
    Implementing Purdue Model Network Segmentation · gabrielmoreira bundle
    Implement network segmentation based on the Purdue Enterprise Reference Architecture (PERA) model, separating ICS networks into hierarchical security zones from Level 0 physical process through Level 5 enterprise and enforcing strict traffic control through IEC 62443-aligned DMZs between OT and IT domains. Use when designing ICS/SCADA network zones or segmenting OT from IT networks.
    17 repo stars
  7. ▌
    Implementing Vulnerability Sla Breach Alerting · gabrielmoreira bundle
    Build an automated SLA breach alerting system for vulnerability remediation, including a database schema for SLA tracking, breach detection logic, notification dispatch, a scheduled check runner, and a KPI/compliance metrics dashboard. Use when implementing severity-based SLA timelines (critical/high/medium/low), detecting and escalating SLA breaches, or building vulnerability remediation compliance reporting.
    17 repo stars
  8. ▌
    Performing Access Recertification With Saviynt · gabrielmoreira bundle
    Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC 2, and HIPAA. Use when launching or managing certification campaigns for users/entitlements, remediating access review findings, or documenting identity governance evidence for an audit.
    17 repo stars
  9. ▌
    Performing Asset Criticality Scoring For Vulns · gabrielmoreira bundle
    Build a multi-factor asset criticality scoring model—incorporating data sensitivity, business function dependency, regulatory scope, network exposure, and recoverability—to produce a 1-5 criticality tier that weights vulnerability prioritization and remediation SLAs. Use when prioritizing vulnerability remediation by business impact or aligning CMDB asset data with risk-based patching timelines.
    17 repo stars
  10. ▌
    Performing Cloud Forensics With AWS Cloudtrail · gabrielmoreira bundle
    Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and event names to reconstruct an attacker timeline. Use when tracing unauthorized API calls, S3 data exfiltration, IAM privilege escalation, or credential exposure, and building a forensic report of findings and remediation steps.
    17 repo stars
  11. ▌
    Performing Cloud Penetration Testing With Pacu · gabrielmoreira bundle
    Run authorized AWS penetration tests with Pacu, the open-source AWS exploitation framework, to enumerate IAM configuration, scan for privilege escalation paths, and test data access and lateral movement using compromised credentials. Use when conducting authorized red-team assessments of AWS environments, validating IAM policies and SCPs, or determining the blast radius of compromised AWS credentials.
    17 repo stars
  12. ▌
    Performing Cve Prioritization With Kev Catalog · gabrielmoreira bundle
    Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog, enrich it with EPSS scores and CVSS metrics, and build a multi-factor prioritization engine and report that ranks CVE remediation by real-world exploitation evidence and BOD 22-01 deadlines. Use when triaging a vulnerability backlog, deciding patch order across many CVEs, or building an automated KEV+EPSS prioritization workflow.
    17 repo stars
  13. ▌
    Performing Kubernetes Etcd Security Assessment · gabrielmoreira bundle
    Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation. Use when auditing or hardening a control plane, reviewing whether Secrets are encrypted at rest, or protecting etcd backups, since etcd stores Secrets, RBAC policy, and ConfigMaps in plaintext by default. Keywords: etcd, EncryptionConfiguration, encryption at rest, peer TLS, snapshot, backup, control plane. Do not use for broad cluster-wide CIS checks - use performing-kubernetes-cis-benchmark-with-kube-bench.
    17 repo stars
  14. ▌
    Performing Power Grid Cybersecurity Assessment · gabrielmoreira bundle
    Conduct cybersecurity assessments of power grid infrastructure spanning generation, transmission substations, distribution, and EMS control centers, covering NERC CIP compliance verification, IEC 61850 (GOOSE/MMS) substation protocol analysis, and synchrophasor (PMU) network security against threats like Industroyer/CrashOverride. Use for periodic NERC CIP assessments, substation automation or EMS/SCADA security reviews, or regional entity compliance audits; not for non-BES systems or generic OT assessments without power grid specifics.
    17 repo stars
  15. ▌
    Performing Service Account Credential Rotation · gabrielmoreira bundle
    Automates credential rotation for service accounts across Active Directory, cloud platforms, and application databases to eliminate stale secrets and reduce compromise risk. Use when rotating or automating rotation of service account passwords, API keys, or secrets stored in a vault.
    17 repo stars
  16. ▌
    Performing Web Application Scanning With Nikto · gabrielmoreira bundle
    Runs Nikto, an open-source web server and web application scanner, to test over 7,000 potentially dangerous files/programs, check for outdated versions across 1,250+ servers, and identify XSS, SQL injection, misconfigurations, default credentials, and vulnerable CGI scripts. Use when performing web application vulnerability scanning, security assessments, scheduled security testing, or validating web server security controls.
    17 repo stars
  17. ▌
    Performing Yara Rule Development For Detection · gabrielmoreira bundle
    Develops precise YARA and YARA-X rules for malware detection by identifying unique strings, byte sequences, PE header traits, and behavioral indicators in unpacked malware artifacts while minimizing false positives. Use when building detection signatures for threat hunting, classifying malware families, or authoring rules from IOCs such as C2 URLs, mutex names, and encryption constants.
    17 repo stars
  18. ▌
    XML To Compose Migration · gabrielmoreira
    Convert Android XML layouts to Jetpack Compose. Use when asked to migrate Views to Compose, convert XML to Composables, or modernize UI from View system to Compose.
    17 repo stars
  19. ▌
    Word Analysis · gabrielmoreira
    Word (.docx/.doc) 文档全量解析。覆盖:正文/段落文本提取、表格数据提取、高亮/颜色格式读取、多文件汇总对比、嵌入图片转 caption。
    17 repo stars
  20. ▌
    Threejs Screen Space Ambient Occlusion · gabrielmoreira bundle
    Implement a production GTAO path in Three.js. Use for half-resolution horizon sampling, reversed-depth reconstruction, bent-normal encoding, full-resolution bilateral reconstruction, environment-light application, contact grounding, and halo diagnosis.
    17 repo stars
  21. ▌
    Syncfusion Maui Toolkit Navigation Drawer · gabrielmoreira bundle
    Implement the Syncfusion .NET MAUI Navigation Drawer (SfNavigationDrawer) control for creating navigation panes that slide from screen edges. Covers positioning (left, right, top, bottom), content configuration, animations, events, gestures, and customization. Use this skill whenever implementing drawer navigation in MAUI apps.
    17 repo stars
  22. ▌
    Syncfusion Maui Toolkit Segmented Control · gabrielmoreira bundle
    Implements Syncfusion .NET MAUI Segmented Control (SfSegmentedControl). Use when working with segmented controls, segment buttons, tab-like selection, button groups, or filter buttons in MAUI applications. This skill covers installation, item population, selection indicators, appearance customization, layout configuration, disabled segments, and events.
    17 repo stars
  23. ▌
    Syncfusion Maui Toolkit Text Input Layout · gabrielmoreira bundle
    Implements Syncfusion .NET MAUI Text Input Layout (SfTextInputLayout). Use when adding decorative elements like floating labels, icons, assistive labels, or containers to Entry, and Editor controls. Covers text input layout setup, hint labels, helper text, error messages, character counter, and password visibility toggle.
    17 repo stars
  24. ▌
    Not Your Babysitter · gabrielmoreira
    Autonomous senior-operator mode for AI agents that resolve tasks end to end without babysitting and never create new problems. The agent verifies every claim against real evidence (web search dated to the current month and year, the codebase, and available tools, MCPs, and CLIs); it never guesses, never fakes confidence, and never claims something is done without proof. It stays silent and keeps working, interrupting the user only on three stops, namely a destructive or irreversible action, a dead-end with no evidence after exhausting sources, or genuine ambiguity that changes the outcome. Output is short, literal, and human. Use when the user says "not-your-babysitter", "nanny mode", "work autonomously", "stop babysitting", or "no hand-holding", or wants an agent that solves problems on its own, especially hands-on engineering and operational tasks. Do not use when the user explicitly wants a tutorial, a verbose walkthrough, or open-ended brainstorming.
    17 repo stars
  25. ▌
    Vulnerability Triage Brocards · gabrielmoreira
    This skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide if a finding is valid", "review a security finding", "dismiss a vulnerability", "should we fix this CVE", "prioritize a vulnerability report", or needs to determine whether an incoming vulnerability report warrants investigation. Applies 7 brocards (rules of thumb) to systematically accept, dismiss, or request more information on vulnerability reports, or needs to filter raw findings from agentic vulnerability discovery pipelines before human review.
    17 repo stars
  26. ▌
    AI Coding Agents Command Runtime · gabrielmoreira
    Designs slash-command runtimes for coding-agent CLIs. Use when modeling command registries, lazy loading, aliases, forked commands, or remote-safe dispatch.
    17 repo stars
  27. ▌
    AI Coding Agents Settings Policy · gabrielmoreira
    Designs settings and policy layers for coding-agent runtimes. Use when modeling source precedence, managed policy, env controls, or runtime settings validation.
    17 repo stars
  28. ▌
    Foundations Behavioral Economics · gabrielmoreira
    16 behavioral-economics primitives for ethical pricing, choice design, and retention. Use when framing, defaults, habits, dark patterns, AI-agent nudging, or nudge ethics apply.
    17 repo stars
  29. ▌
    Auditing AWS S3 Bucket Permissions · gabrielmoreira
    Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.
    17 repo stars
  30. ▌
    Detecting AWS Cloudtrail Anomalies · gabrielmoreira
    Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized resource access.
    17 repo stars
  31. ▌
    Analyzing PDF Malware With Pdfid · gabrielmoreira
    Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.
    17 repo stars
  32. ▌
    Detecting Mobile Malware Behavior · gabrielmoreira
    Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. Use when analyzing suspicious mobile applications for data exfiltration, command-and-control communication, credential stealing, SMS interception, or other malware indicators. Activates for requests involving mobile malware analysis, app behavior monitoring, trojan detection, or suspicious app investigation.
    17 repo stars
  33. ▌
    Testing Mobile API Authentication · gabrielmoreira
    Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against mobile app backends, testing JWT implementations, evaluating OAuth flows, or assessing session management. Activates for requests involving mobile API auth testing, token security assessment, OAuth mobile flow testing, or API authorization bypass.
    17 repo stars
  34. ▌
    Pentesting Postgresql · gabrielmoreira
    Testing PostgreSQL database services (default port 5432, fallback 5433) for trust-auth and default/weak credentials, role/privilege enumeration, the COPY ... FROM PROGRAM command-execution primitive, large-object and server-file read/write, CREATEROLE privilege escalation, and extension/config-file RCE during authorized engagements.
    17 repo stars
  35. ▌
    Performing User Behavior Analytics · gabrielmoreira
    Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.
    17 repo stars
  36. ▌
    Triaging Security Alerts In Splunk · gabrielmoreira
    Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts face queued alerts from correlation searches, need to prioritize investigation order, or must document triage decisions for handoff to Tier 2/3 analysts.
    17 repo stars
  37. ▌
    Profiling Threat Actor Groups · gabrielmoreira
    Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and attribution indicators from multiple intelligence sources. Use when briefing executives on sector-specific threats, updating threat model assumptions, or prioritizing defensive controls against specific adversaries. Activates for requests involving MITRE ATT&CK Groups, Mandiant APT profiles, CrowdStrike adversary naming, or sector-specific threat briefings.
    17 repo stars
  38. ▌
    Exploiting Orm Injection · gabrielmoreira
    Exploiting ORM injection (ORM Leak) where applications pass attacker-controlled keys/operators directly into ORM query builders (Django, Prisma, Beego, Ransack, Entity Framework/OData), letting attackers smuggle relational filters and comparison operators to leak hidden columns (passwords, reset tokens, TOTP secrets) via boolean, error, or timing oracles, and to bypass field deny-lists. Activates when request data is spread into filter/where clauses.
    17 repo stars
  39. ▌
    Nomogram Construction · gabrielmoreira
    Use when constructing a prognosis nomogram from survival-related clinical predictors, exporting the nomogram bundle and C-index table, and optionally rendering the final nomogram PDF. NOT for: univariate/multivariable Cox feature screening, calibration curves, ROC analysis, decision-curve analysis, or non-survival outcomes.
    17 repo stars
  40. ▌
    Academic Highlight Generator · gabrielmoreira
    Generates submission-ready Elsevier/SCI Highlights from manuscript text or extracted PDF/DOCX/TXT content. Use when a user needs 3-5 concise, evidence-grounded highlight bullets for a research paper, review, meta-analysis, case report, or bioinformatics manuscript.
    17 repo stars
  41. ▌
    Biotech Pitch Deck Narrative · gabrielmoreira
    Use biotech-pitch-deck-narrative for academic writing workflows that need structured investor-facing storytelling, explicit assumptions, and clear output boundaries.
    17 repo stars
  42. ▌
    Discussion Section Architect · gabrielmoreira
    Structures and writes discussion sections for academic papers and research reports. Use when writing a discussion section, interpreting research results, connecting findings to existing literature, addressing study limitations, synthesizing conclusions, or drafting any part of...
    17 repo stars
  43. ▌
    Semantic Consistency Auditor · gabrielmoreira
    Use semantic consistency auditor for academic writing workflows that need structured execution, explicit assumptions, and clear output boundaries.
    17 repo stars
  44. ▌
    Non Tumor Ml Research Planner · gabrielmoreira
    Generates complete non-tumor biomedical machine learning research designs from a user-provided research direction. Always use this skill when users want to plan bioinformatics + ML papers for non-cancer diseases (metabolic, cardiovascular, kidney, inflammatory, autoimmune, infectious, neurological, endocrine, wound healing, chronic multifactor), design diagnostic biomarker studies, combine GEO datasets with feature selection and ML modeling, or generate Lite/Standard/Advanced/Publication+ workload plans. Trigger for:"non-tumor ML study", "bioinformatics paper outside oncology", "key genes and diagnostic model for a disease", "pyroptosis/ferroptosis/senescence/autophagy + disease", "GEO datasets + machine learning", "RF + LASSO diagnostic model", "DEG + feature selection + validation", "immune infiltration + biomarker", "non-cancer biomarker paper". Trigger even for casual phrasings like "I want to study X using machine learning", "help me design a non-tumor bioinformatics paper", or "how do I build a diagnost
    17 repo stars
  45. ▌
    Prompt Registry Helper · gabrielmoreira
    Answer questions about using AI Primitives Hub and authoring bundles. Use this skill whenever the user asks about bundles, collections, hubs, profiles, sources, scopes, marketplace, repository installation, deployment manifests, source scaffolding, collection schemas, validation errors, publishing, or any AI Primitives Hub extension feature — even if they don't name the extension explicitly.
    17 repo stars
  46. ▌
    Wordpress Block Theming · gabrielmoreira
    WordPress Full Site Editing (FSE) theme architecture. Use when generating theme.json, block templates, template parts, patterns, and functions.php for WordPress block themes.
    17 repo stars
  47. ▌
    Issue Reporter · gabrielmoreira
    只在用户明确要求提交 GitHub Issue、GitHub Bug Report 或 GitHub Feature Request 时使用。用户只说“提交问题”“提交反馈”“上报 bug”“这是个 bug”或描述功能建议但未点名 GitHub 时不得触发,必须改用 cherry-studio-feedback 并默认提交飞书。
    17 repo stars
  48. ▌
    Skills Manager · gabrielmoreira
    搜索、安装和协调创建 Claude Code Agent Skills。当用户想要搜索技能、安装工具、创建自定义 Skill,或者说"find a skill"、"搜索技能"、"帮我做个 skill"、"create a skill"时触发。也适用于用户说"有没有做 X 的工具"、"我想扩展 Agent 能力",或当前能力不足需要先查找可复用方案的场景。
    17 repo stars
  49. ▌
    Decision Matrix · gabrielmoreira
    A structured reasoning assistant that helps you make clear, confident decisions using proven frameworks — Pros/Cons, Decision Matrix (Pugh Matrix), Weighted Scoring, Pre-mortem, and Opportunity Cost Analysis.
    17 repo stars
  50. ▌
    AI Wrapper Product · gabrielmoreira
    Expert in building products that wrap AI APIs (OpenAI, Anthropic, etc.) into focused tools people will pay for. Not just 'ChatGPT but different' - products that solve specific problems with AI. Covers prompt engineering for products, cost management, rate limiting, and building defensible AI businesses. Use when: AI wrapper, GPT product, AI tool, wrap AI, AI SaaS.
    17 repo stars
  51. ▌
    Visual Artifact QA · gabrielmoreira
    Visual output that passes static checks can still fail to render:
    17 repo stars
  52. ▌
    Cognitive Load · gabrielmoreira
    Don't overwhelm — chunk, scaffold, summarize first.
    17 repo stars
  53. ▌
    Biome Kusto Query · gabrielmoreira
    Execute read-only KQL queries against Kusto / Azure Data Explorer clusters via the Kusto MCP server. Read-only -- does not create, alter, or drop objects.
    17 repo stars
  54. ▌
    Business Analysis · gabrielmoreira
    Patterns for requirements elicitation, BRDs, process analysis, and stakeholder alignment.
    17 repo stars
  55. ▌
    Release Preflight · gabrielmoreira
    Pre-checks, version consistency, and deployment discipline.
    17 repo stars
  56. ▌
    Work Life Balance · gabrielmoreira
    Detect burnout signals and proactively support sustainable productivity.
    17 repo stars
  57. ▌
    Legal Compliance · gabrielmoreira
    Legal research, contract analysis, regulatory compliance, and case law citation for legal professionals.
    17 repo stars
  58. ▌
    Sales Enablement · gabrielmoreira
    Sales methodology, pipeline management, negotiation frameworks, and customer engagement patterns.
    17 repo stars
  59. ▌
    Image Annotations · gabrielmoreira
    Annotate screenshots, diagrams, and images with callout rectangles, arrows, labels, and color-coded highlights using PIL. Includes rules for animated GIF annotations with timing and pacing.
    17 repo stars
  60. ▌
    Marp Presentation · gabrielmoreira
    End-to-end Marp Markdown presentation workflow — create decks from topics or codebases, build to PDF/PPTX/HTML, review for quality, and customize themes. Use when asked to create slides, export presentations, review decks, or style Marp files.
    17 repo stars
  61. ▌
    Assist Sg Update · gabrielmoreira
    Generate assisted PRs to correct Security Group ownership for first-party apps flagged by S360 tenant-isolation policy (SFI-TI3.2.2)
    17 repo stars
  62. ▌
    Fetch Violations · gabrielmoreira
    Query S360 Kusto for SFI-TI3.2.2 tenant isolation violations, classify by ViolationTitle, flag autofix-eligible items for downstream remediation
    17 repo stars
  63. ▌
    Fleet Management · gabrielmoreira
    Keep heir projects synchronized with Master Alex brain updates — audit drift, upgrade brains, verify deployments
    17 repo stars
  64. ▌
    Flint Chart · gabrielmoreira
    Use when the user wants to visualize data — from 'which chart should I use?' to 'render this'. Helps pick the right chart from the analytical question (comparison / trend / distribution / relationship / proportion / flow / KPI), then authors a ChartAssemblyInput and renders via the flint-chart-mcp server (Vega-Lite / ECharts / Chart.js). Transform data before Flint; style tweaks after Flint.
    17 repo stars
  65. ▌
    Platform Capability Search · gabrielmoreira
    Use this when someone says I don't know where to start or help me get going, asks where am I? in the six-stage journey, requests on-demand org feature detection for Data 360, OmniStudio, or DevOps Center, or asks what could help me do X / which plugin would help with X for a task no installed skill already covers. DO NOT TRIGGER for specific Salesforce tasks already owned by a leaf skill or for generic non-Salesforce help.
    17 repo stars
  66. ▌
    Platform Manifest Generate · gabrielmoreira
    Use this skill to generate a package.xml (and optionally destructiveChanges.xml, destructiveChangesPre.xml, or destructiveChangesPost.xml) from a local source directory, an explicit component list, or org introspection. Trigger when the user says "generate a package.xml from this folder", "create a manifest for these classes", "I need a deploy manifest", "build package.xml for the contacts changes", or "create both package.xml and destructiveChanges.xml for these deletions". Encodes which metadata types accept a wildcard member and which must be enumerated, avoiding the common "Wildcards are not supported for this metadata type" deploy failure. DO NOT TRIGGER for executing a deploy (use platform-metadata-deploy), performing the deletion in destructiveChanges.xml (use platform-destructive-deploy), or retrieving metadata (use platform-metadata-retrieve).
    17 repo stars
  67. ▌
    Record A Decision · gabrielmoreira
    Records an architecture decision as a Nygard/MADR-shaped ADR under decisions/ — capturing the context that forced the choice, the options weighed, the decision itself, and its consequences in both directions, plus the supersedes chain that keeps a decision log honest. Read when asked to record an architecture decision, write an ADR, log the decision we made, document why we chose X over Y, capture this decision for the record, or supersede an old decision with a new one. Do NOT read to frame a proposal or explore an idea not yet decided (frame-a-proposal), to write a spec or implementation plan (write-a-spec), to write an incident postmortem (write-a-postmortem), or to judge whether a design is sound (review-a-design). This skill records a decision already made; it does not make one.
    17 repo stars
  68. ▌
    Smina Molecular Docking · gabrielmoreira
    smina molecular docking CLI. AutoDock Vina fork with customizable scoring functions, native SDF/MOL2/PDB ligand input, autoboxing, local energy minimization, and per-atom score breakdowns. Pipeline: receptor PDBQT prep -> ligand prep (RDKit/OpenBabel) -> dock via autobox or explicit grid -> rescore/minimize with custom scoring -> rank poses by affinity. Choose smina over Vina when you need custom scoring terms (--custom_scoring), local optimization of an existing pose (--local_only), per-atom contributions (--atom_term_data), or SDF/MOL2 ligands without manual PDBQT conversion. For unknown binding sites use diffdock; for the Python-bindings/Vinardo workflow use autodock-vina-docking.
    17 repo stars
  69. ▌
    Brain Save · gabrielmoreira
    Saves a single fact, decision, pattern, or convention into your governed knowledge brain so it can be recalled later — and retires memories that are outdated. Side-effecting: it writes to your durable corpus, so it never auto-fires — invoke it explicitly. Use when you want the brain to remember something specific going forward without a full recompile, or to mark an old memory outdated. Trigger with "/brain-save".
    17 repo stars
  70. ▌
    Find AI Consultancy · gabrielmoreira
    Use whenever the user wants to find, shortlist, vet, or enrich US AI/ML/data consulting firms (consultancies) — AI/ML development, MLOps, generative AI / LLM apps (RAG, chatbots, agents), computer vision, NLP, recommendation systems, data engineering, BI/analytics. Triggers on "find an AI/ML consulting firm to build our recommendation engine", "shortlist three RAG/LLM consultancies for an enterprise chatbot", "compare three AI/ML consulting firms with strong ratings", or "pull contact info for these 8 AI consultancy domains", even when described indirectly (we want to use AI for X, deploy ML to production). Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings. Defer to find-software-developer for general app/backend work where AI is just a feature. Skip in-house ML/data hires, LLM/AI-tool comparisons (ChatGPT vs Claude), "how do I fine-tune X" DIY questions, AI courses for individuals, non-US firms, individual freelancers.
    17 repo stars
  71. ▌
    Find AI Directories · gabrielmoreira
    Use whenever the user wants to find, rank, or shortlist directories and listing sites where they can submit an AI product — an AI tool, AI app, AI agent, or agent skill / plugin — to get backlinks, referral traffic, and discovery. Triggers on "where can I list my AI tool", "directories to submit my AI agent", "agent-skills directories", "best AI tool directories for backlinks", "where do I get my GPT/Claude app discovered", or "pull submission details for these AI-directory domains", even when described indirectly. Drives the ServiceGraph API (api.servicegraph.co) — a catalog of 1,000+ product directories enriched with Domain Rating, backlinks, and organic traffic. Defer to find-mcp-directories for MCP-server listings specifically, and to find-product-directories for general SaaS/software/app launches with no AI angle. Skip finding an AI consultancy/agency to hire (use find-ai-consultancy), comparing AI products ("ChatGPT vs Claude"), building an AI tool (do-the-work), and AI link-building *services*.
    17 repo stars
  72. ▌
    Customerio Advanced Troubleshooting · gabrielmoreira bundle
    Apply Customer.io advanced debugging and incident response. Use when diagnosing complex delivery issues, investigating campaign failures, or running incident playbooks. Trigger: "debug customer.io", "customer.io investigation", "customer.io troubleshoot", "customer.io incident", "customer.io not delivering".
    17 repo stars
  73. ▌
    Implementing Database Audit Logging · gabrielmoreira bundle
    Process use when you need to track database changes for compliance and security monitoring. This skill implements audit logging using triggers, application-level logging, CDC, or native logs. Trigger with phrases like "implement database audit logging", "add audit trails", "track database changes", or "monitor database activity for compliance".
    17 repo stars
  74. ▌
    Managing Environment Configurations · gabrielmoreira bundle
    Implement environment and configuration management with comprehensive guidance and automation. Use when you need to work with environment configuration. Trigger with phrases like "manage environments", "configure environments", or "sync configurations".
    17 repo stars
  75. ▌
    Openevidence Reference Architecture · gabrielmoreira bundle
    Reference Architecture for OpenEvidence. Trigger: "openevidence reference architecture".
    17 repo stars
  76. ▌
    Salesforce Advanced Troubleshooting · gabrielmoreira
    Apply Salesforce advanced debugging with debug logs, SOQL query plans, and EventLogFile analysis. Use when standard troubleshooting fails, investigating SOQL performance issues, or analyzing Apex governor limit violations. Trigger with phrases like "salesforce hard bug", "salesforce debug log", "salesforce governor limit", "salesforce query plan", "salesforce deep debug", "SOQL slow".
    17 repo stars
  77. ▌
    Scanning Input Validation Practices · gabrielmoreira bundle
    Scan for input validation vulnerabilities and injection risks. Use when reviewing user input handling. Trigger with 'scan input validation', 'check injection vulnerabilities', or 'validate sanitization'.
    17 repo stars
  78. ▌
    Supabase Auth Storage Realtime Core · gabrielmoreira bundle
    Implement Supabase Auth (signUp, signIn, OAuth, session management), Storage (upload, download, signed URLs, bucket policies), and Realtime (Postgres changes, broadcast, presence). Use when building user auth flows, file upload features, or live-updating UIs with Supabase. Trigger with phrases like "supabase auth", "supabase storage upload", "supabase realtime subscribe", "supabase oauth", "supabase file upload", "supabase presence", "supabase rls storage".
    17 repo stars
  79. ▌
    Tracking Application Response Times · gabrielmoreira bundle
    Track and optimize application response times across API endpoints, database queries, and service calls. Use when monitoring performance or identifying bottlenecks. Trigger with phrases like "track response times", "monitor API performance", or "analyze latency".
    17 repo stars
  80. ▌
    Alertmanager Rules Config · gabrielmoreira
    Manage alertmanager rules config operations. Auto-activating skill for DevOps Advanced. Triggers on: alertmanager rules config, alertmanager rules config Part of the DevOps Advanced skill category. Use when configuring systems or services. Trigger with phrases like "alertmanager rules config", "alertmanager config", "alertmanager".
    17 repo stars
  81. ▌
    Grafana Dashboard Creator · gabrielmoreira
    Create grafana dashboard creator operations. Auto-activating skill for DevOps Advanced. Triggers on: grafana dashboard creator, grafana dashboard creator Part of the DevOps Advanced skill category. Use when working with grafana dashboard creator functionality. Trigger with phrases like "grafana dashboard creator", "grafana creator", "grafana".
    17 repo stars
  82. ▌
    Istio Service Mesh Config · gabrielmoreira
    Configure istio service mesh config operations. Auto-activating skill for DevOps Advanced. Triggers on: istio service mesh config, istio service mesh config Part of the DevOps Advanced skill category. Use when configuring systems or services. Trigger with phrases like "istio service mesh config", "istio config", "istio".
    17 repo stars
  83. ▌
    Kubernetes Ingress Config · gabrielmoreira
    Configure kubernetes ingress config operations. Auto-activating skill for DevOps Advanced. Triggers on: kubernetes ingress config, kubernetes ingress config Part of the DevOps Advanced skill category. Use when configuring systems or services. Trigger with phrases like "kubernetes ingress config", "kubernetes config", "kubernetes".
    17 repo stars
  84. ▌
    Terraform Provider Config · gabrielmoreira
    Configure terraform provider config operations. Auto-activating skill for DevOps Advanced. Triggers on: terraform provider config, terraform provider config Part of the DevOps Advanced skill category. Use when configuring systems or services. Trigger with phrases like "terraform provider config", "terraform config", "terraform".
    17 repo stars
  85. ▌
    Env Secret Detector · gabrielmoreira
    Detect env secret detector operations. Auto-activating skill for Security Fundamentals. Triggers on: env secret detector, env secret detector Part of the Security Fundamentals skill category. Use when working with env secret detector functionality. Trigger with phrases like "env secret detector", "env detector", "env".
    17 repo stars
  86. ▌
    JWT Token Validator · gabrielmoreira
    Validate jwt token validator operations. Auto-activating skill for Security Fundamentals. Triggers on: jwt token validator, jwt token validator Part of the Security Fundamentals skill category. Use when working with jwt token validator functionality. Trigger with phrases like "jwt token validator", "jwt validator", "jwt".
    17 repo stars
  87. ▌
    Rate Limiter Config · gabrielmoreira
    Configure rate limiter config operations. Auto-activating skill for Security Fundamentals. Triggers on: rate limiter config, rate limiter config Part of the Security Fundamentals skill category. Use when configuring systems or services. Trigger with phrases like "rate limiter config", "rate config", "rate".
    17 repo stars
  88. ▌
    Attack Surface Analyzer · gabrielmoreira
    Analyze attack surface analyzer operations. Auto-activating skill for Security Advanced. Triggers on: attack surface analyzer, attack surface analyzer Part of the Security Advanced skill category. Use when analyzing or auditing attack surface analyzer. Trigger with phrases like "attack surface analyzer", "attack analyzer", "analyze attack surface r".
    17 repo stars
  89. ▌
    Gdpr Compliance Scanner · gabrielmoreira
    Scan gdpr compliance scanner operations. Auto-activating skill for Security Advanced. Triggers on: gdpr compliance scanner, gdpr compliance scanner Part of the Security Advanced skill category. Use when working with gdpr compliance scanner functionality. Trigger with phrases like "gdpr compliance scanner", "gdpr scanner", "gdpr".
    17 repo stars
  90. ▌
    Soc2 Compliance Checker · gabrielmoreira
    Validate soc2 compliance checker operations. Auto-activating skill for Security Advanced. Triggers on: soc2 compliance checker, soc2 compliance checker Part of the Security Advanced skill category. Use when working with soc2 compliance checker functionality. Trigger with phrases like "soc2 compliance checker", "soc2 checker", "soc2".
    17 repo stars
  91. ▌
    Sagemaker Endpoint Deployer · gabrielmoreira
    Deploy sagemaker endpoint deployer operations. Auto-activating skill for ML Deployment. Triggers on: sagemaker endpoint deployer, sagemaker endpoint deployer Part of the ML Deployment skill category. Use when deploying applications or services. Trigger with phrases like "sagemaker endpoint deployer", "sagemaker deployer", "deploy sagemaker endpoint er".
    17 repo stars
  92. ▌
    Torchserve Config Generator · gabrielmoreira
    Generate torchserve config generator operations. Auto-activating skill for ML Deployment. Triggers on: torchserve config generator, torchserve config generator Part of the ML Deployment skill category. Use when configuring systems or services. Trigger with phrases like "torchserve config generator", "torchserve generator", "torchserve".
    17 repo stars
  93. ▌
    Bottleneck Identifier · gabrielmoreira
    Execute bottleneck identifier operations. Auto-activating skill for Performance Testing. Triggers on: bottleneck identifier, bottleneck identifier Part of the Performance Testing skill category. Use when working with bottleneck identifier functionality. Trigger with phrases like "bottleneck identifier", "bottleneck identifier", "bottleneck".
    17 repo stars
  94. ▌
    Flame Graph Generator · gabrielmoreira
    Generate flame graph generator operations. Auto-activating skill for Performance Testing. Triggers on: flame graph generator, flame graph generator Part of the Performance Testing skill category. Use when working with flame graph generator functionality. Trigger with phrases like "flame graph generator", "flame generator", "flame".
    17 repo stars
  95. ▌
    Memory Profiler Setup · gabrielmoreira
    Configure memory profiler setup operations. Auto-activating skill for Performance Testing. Triggers on: memory profiler setup, memory profiler setup Part of the Performance Testing skill category. Use when working with memory profiler setup functionality. Trigger with phrases like "memory profiler setup", "memory setup", "memory".
    17 repo stars
  96. ▌
    Throughput Calculator · gabrielmoreira
    Calculate throughput calculator operations. Auto-activating skill for Performance Testing. Triggers on: throughput calculator, throughput calculator Part of the Performance Testing skill category. Use when working with throughput calculator functionality. Trigger with phrases like "throughput calculator", "throughput calculator", "throughput".
    17 repo stars
  97. ▌
    Regression Analysis Helper · gabrielmoreira
    Configure with regression analysis helper operations. Auto-activating skill for Data Analytics. Triggers on: regression analysis helper, regression analysis helper Part of the Data Analytics skill category. Use when working with regression analysis helper functionality. Trigger with phrases like "regression analysis helper", "regression helper", "regression".
    17 repo stars
  98. ▌
    Hypermedia Link Generator · gabrielmoreira
    Generate hypermedia link generator operations. Auto-activating skill for API Development. Triggers on: hypermedia link generator, hypermedia link generator Part of the API Development skill category. Use when working with hypermedia link generator functionality. Trigger with phrases like "hypermedia link generator", "hypermedia generator", "hypermedia".
    17 repo stars
  99. ▌
    Response Schema Generator · gabrielmoreira
    Generate response schema generator operations. Auto-activating skill for API Development. Triggers on: response schema generator, response schema generator Part of the API Development skill category. Use when working with response schema generator functionality. Trigger with phrases like "response schema generator", "response generator", "response".
    17 repo stars
  100. ▌
    Sorting Parameter Handler · gabrielmoreira
    Manage sorting parameter handler operations. Auto-activating skill for API Development. Triggers on: sorting parameter handler, sorting parameter handler Part of the API Development skill category. Use when working with sorting parameter handler functionality. Trigger with phrases like "sorting parameter handler", "sorting handler", "sorting".
    17 repo stars