gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Connection Pooling Config · gabrielmoreiraConfigure connection pooling config operations. Auto-activating skill for API Integration. Triggers on: connection pooling config, connection pooling config Part of the API Integration skill category. Use when configuring systems or services. Trigger with phrases like "connection pooling config", "connection config", "connection".
- ▌ Contributing Guide Creator · gabrielmoreiraCreate contributing guide creator operations. Auto-activating skill for Technical Documentation. Triggers on: contributing guide creator, contributing guide creator Part of the Technical Documentation skill category. Use when working with contributing guide creator functionality. Trigger with phrases like "contributing guide creator", "contributing creator", "contributing".
- ▌ Installation Guide Creator · gabrielmoreiraCreate installation guide creator operations. Auto-activating skill for Technical Documentation. Triggers on: installation guide creator, installation guide creator Part of the Technical Documentation skill category. Use when working with installation guide creator functionality. Trigger with phrases like "installation guide creator", "installation creator", "installation".
- ▌ Quickstart Guide Generator · gabrielmoreiraGenerate quickstart guide generator operations. Auto-activating skill for Technical Documentation. Triggers on: quickstart guide generator, quickstart guide generator Part of the Technical Documentation skill category. Use when working with quickstart guide generator functionality. Trigger with phrases like "quickstart guide generator", "quickstart generator", "quickstart".
- ▌ Database Schema Visualizer · gabrielmoreiraGenerate database schema visualizer operations. Auto-activating skill for Visual Content. Triggers on: database schema visualizer, database schema visualizer Part of the Visual Content skill category. Use when working with database schema visualizer functionality. Trigger with phrases like "database schema visualizer", "database visualizer", "database".
- ▌ Mermaid Er Diagram Creator · gabrielmoreiraCreate mermaid er diagram creator operations. Auto-activating skill for Visual Content. Triggers on: mermaid er diagram creator, mermaid er diagram creator Part of the Visual Content skill category. Use when working with mermaid er diagram creator functionality. Trigger with phrases like "mermaid er diagram creator", "mermaid creator", "mermaid".
- ▌ Plantuml Diagram Generator · gabrielmoreiraGenerate plantuml diagram generator operations. Auto-activating skill for Visual Content. Triggers on: plantuml diagram generator, plantuml diagram generator Part of the Visual Content skill category. Use when working with plantuml diagram generator functionality. Trigger with phrases like "plantuml diagram generator", "plantuml generator", "plantuml".
- ▌ Technical Diagram Analyzer · gabrielmoreiraAnalyze technical diagram analyzer operations. Auto-activating skill for Visual Content. Triggers on: technical diagram analyzer, technical diagram analyzer Part of the Visual Content skill category. Use when analyzing or auditing technical diagram analyzer. Trigger with phrases like "technical diagram analyzer", "technical analyzer", "analyze technical diagram r".
- ▌ Discord Bot Generator · gabrielmoreiraGenerate discord bot generator operations. Auto-activating skill for Business Automation. Triggers on: discord bot generator, discord bot generator Part of the Business Automation skill category. Use when working with discord bot generator functionality. Trigger with phrases like "discord bot generator", "discord generator", "discord".
- ▌ Make Scenario Creator · gabrielmoreiraCreate make scenario creator operations. Auto-activating skill for Business Automation. Triggers on: make scenario creator, make scenario creator Part of the Business Automation skill category. Use when working with make scenario creator functionality. Trigger with phrases like "make scenario creator", "make creator", "make".
- ▌ Github Project Setup · gabrielmoreiraConfigure github project setup operations. Auto-activating skill for Enterprise Workflows. Triggers on: github project setup, github project setup Part of the Enterprise Workflows skill category. Use when working with github project setup functionality. Trigger with phrases like "github project setup", "github setup", "github".
- ▌ User Story Generator · gabrielmoreiraGenerate user story generator operations. Auto-activating skill for Enterprise Workflows. Triggers on: user story generator, user story generator Part of the Enterprise Workflows skill category. Use when working with user story generator functionality. Trigger with phrases like "user story generator", "user generator", "user".
- ▌ Manage Lot Controlled Inventory · gabrielmoreira bundleManage lot-controlled inventory workflows by tracing lot IDs, quantities, statuses, movements, and hold boundaries.
- ▌ Analyze Edi Logistics Flow · gabrielmoreira bundleAnalyze EDI logistics flows across trading parties, documents, identifiers, statuses, acknowledgements, exceptions, and system handoffs.
- ▌ Calculate Pick Productivity · gabrielmoreira bundleCalculate pick productivity from picks, lines, units, labor hours, method, period, and process scope.
- ▌ Diagnose Picking Bottleneck · gabrielmoreira bundleDiagnose picking bottlenecks from productivity, travel, replenishment, congestion, errors, labor, equipment, and order mix.
- ▌ Classify Storage Requirements · gabrielmoreira bundleClassify storage requirements from SKU attributes, load units, velocity, handling, environment, and control needs.
- ▌ Calculate Load Utilization · gabrielmoreira bundleCalculate load utilization from trailer or container dimensions, load dimensions, weight, cube, pallets, and handling constraints.
- ▌ Plan Freight Consolidation · gabrielmoreira bundlePlan freight consolidation from shipments, lanes, timing, cost, service constraints, load utilization, and accessorial risk.
- ▌ Select Transportation Mode · gabrielmoreira bundleSelect a transportation mode from shipment profile, service need, geography, cost, handling, and constraint evidence.
- ▌ Neb · gabrielmoreiraPrepare ASE NEB workflow tasks with backend-agnostic controls. Use when the user needs reaction-path optimization between initial/final states with explicit image construction, spring settings, and convergence controls.
- ▌ Dotnet Testing Filesystem Testing Abstractions · gabrielmoreira bundle使用 System.IO.Abstractions 測試檔案系統操作的專門技能。當需要測試 File、Directory、Path 等操作、模擬檔案系統時使用。涵蓋 IFileSystem、MockFileSystem、檔案讀寫測試、目錄操作測試等。 Make sure to use this skill whenever the user mentions file system testing, IFileSystem, MockFileSystem, System.IO.Abstractions, or testing file/directory operations, even if they don't explicitly ask for filesystem testing guidance. Keywords: file testing, filesystem, 檔案測試, 檔案系統測試, IFileSystem, MockFileSystem, System.IO.Abstractions, File.ReadAllText, File.WriteAllText, Directory.CreateDirectory, Path.Combine, mock file system, 檔案抽象化
- ▌ Serious Incident Reporting · gabrielmoreira bundleAssess, report, and manage serious incidents involving high-risk AI systems under Article 73 EU AI Act. Covers incident qualification, deadline buckets (2/10/15 days), authority notification, deployer duties (Art. 26(5)), cross-regulation mapping (GDPR/NIS2/MDR), corrective measures, and DACH-specific routing. Use when asked to evaluate whether an AI incident is reportable, draft an Article 73 notification, identify the right authority, or build an AI incident response process.
- ▌ Swiss Legal Source Authority Triage Enrique G Zbinden · gabrielmoreira bundleSwiss legal source and authority triage. Use when a user asks a Swiss legal, regulatory, compliance, contract, employment, corporate, litigation, IP, tax, privacy, public-law, fintech, register, or cantonal-law question; when Swiss law may apply; or when an AI legal answer needs source routing across federal, cantonal, communal, regulator, register, contractual, professional, soft-law, multilingual, or open-data layers.
- ▌ Simulink Generate Embedded Code · gabrielmoreiraConfigure Simulink models for Embedded Coder (ERT) or AUTOSAR code generation. Use when the user asks to configure a model for production/ECU deployment, generate embedded C or C++ code, target ARM or x86 hardware, optimize code generation for speed or RAM, apply MISRA C/C++ compliance, or set up ERT, AUTOSAR, or shared-library targets — including running a full build or producing a code generation report. Handles target selection, optimization cascades, hardware mapping, model hierarchy propagation, and constraint introspection via the configure_for_codegen function. Do NOT use for Simulink Coder / GRT / grt.tlc / rapid-prototyping targets, DDS, or ROS — this skill is Embedded Coder and AUTOSAR only.
- ▌ Specifying Plant Models · gabrielmoreiraSpecify plant models for closed-loop simulation: system specs, architecture, build plans, validation plans. Use when creating, updating, or reviewing plant model specifications, planning plant model architecture, or planning plant model validation.
- ▌ Simulink Use C Function Block · gabrielmoreiraUse when integrating legacy code, custom code, or C/C++ code into Simulink via C Function blocks. Configure Simulink C Function blocks programmatically using the SymbolSpec API. TRIGGER when the user: - Asks about calling or wrapping C/C++ code or libraries in Simulink - Wants to create, configure, or use a C Function block - Mentions integrating custom code, legacy code, or external C/C++ into a model - Asks to integrate a C++ class into a Simulink model or test bench - Mentions inputs/outputs/parameters for a C++ algorithm block
- ▌ Building Admin Dashboard Customizations · gabrielmoreiraLoad automatically when planning, researching, or implementing Medusa Admin dashboard UI (widgets, custom pages, forms, tables, data loading, navigation). REQUIRED for all admin UI work in ALL modes (planning, implementation, exploration). Contains design patterns, component usage, and data loading patterns that MCP servers don't provide.
- ▌ Data Science Engineering Foundation · gabrielmoreiraState, resume, reconstruction, job-lifecycle, transition, and flow-state mechanics for the Data Science and Engineering Coach. Loaded by the coach; not a user entry point.
- ▌ Analyzing Sbom For Supply Chain Vulnerabilities · gabrielmoreira bundleParses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports. Activates for requests involving SBOM analysis, software composition analysis, supply chain security assessment, dependency vulnerability scanning, CycloneDX/SPDX parsing, or CVE correlation.
- ▌ Analyzing Slack Space And File System Artifacts · gabrielmoreira bundleExamine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery is insufficient, such as hunting for data hidden in ADS.
- ▌ Building Identity Federation With Saml Azure Ad · gabrielmoreira bundleConfigure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML authentication flow. Use when extending on-premises authentication authority to cloud resources or designing hybrid identity SSO architecture for Entra ID.
- ▌ Coercing Authentication With Coercer Petitpotam · gabrielmoreira bundleTrigger machine account authentication with PetitPotam (MS-EFSR) and Coercer (MS-RPRN, MS-DFSNM, MS-FSRVP, MS-EVEN) via Coercer's scan/coerce/fuzz modes, feeding the coerced NTLM auth into a relay against AD CS Web Enrollment (ESC8), LDAP (RBCD), or SMB. Use in authorized engagements to complete a coercion-relay chain against a Domain Controller, or to validate coercion detections and signing/EPA mitigations.
- ▌ Implementing API Security Testing With 42crunch · gabrielmoreira bundleImplements API security testing on the 42Crunch platform, combining API Audit for static analysis of OpenAPI definitions, API Conformance Scan for dynamic vulnerability testing, and API Protect for runtime threat prevention, integrated into CI/CD pipelines and IDEs. Use when shift-left testing APIs for OWASP API Security Top 10 vulnerabilities or setting up 42Crunch audit and conformance scanning.
- ▌ Implementing Attack Path Analysis With Xm Cyber · gabrielmoreira bundleDeploys XM Cyber's continuous exposure management platform to build attack graphs that chain vulnerabilities, misconfigurations, identity risks, and credential weaknesses toward critical assets, identifying the small fraction of exposures sitting on converging "choke points". Use when mapping attack paths across an environment or prioritizing remediation within a continuous threat exposure management (CTEM) program.
- ▌ Implementing Beyondcorp Zero Trust Access Model · gabrielmoreira bundleImplement Google's BeyondCorp zero trust access model using Cloud IAP, Access Context Manager, Endpoint Verification, Chrome Enterprise Premium, and BeyondCorp Enterprise Connectors to enforce identity- and device-aware access for VPN-less application access. Use for replacing VPN, enforcing device posture checks, or securing remote/hybrid access to GCP-hosted or on-prem apps; not for raw network-level protocols.
- ▌ Implementing Google Workspace Sso Configuration · gabrielmoreira bundleConfigures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication and enable immediate access revocation. Use when setting up or troubleshooting Google Workspace SSO/SAML federation or migrating from native Google passwords to an external IdP.
- ▌ Implementing Identity Governance With Sailpoint · gabrielmoreira bundleDeploys SailPoint IdentityNow or IdentityIQ for identity governance and administration, covering identity lifecycle management, access request workflows, certification campaigns, role mining, separation-of-duties (SOD) policy enforcement, and compliance reporting. Use when standing up or tuning an identity governance program, automating access certifications, or enforcing SOD policies across enterprise IAM.
- ▌ Implementing Soar Playbook With Palo Alto Xsoar · gabrielmoreira bundleBuild automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise, and DDoS response workflows across SOC tools. Use when authoring or wiring up an XSOAR playbook, adding custom XSOAR integration commands or Python automation scripts, or reducing manual SOC response time via orchestration.
- ▌ Implementing Supply Chain Security With In Toto · gabrielmoreira bundleImplements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link metadata, verifying before deployment, enforcing at Kubernetes admission, and integrating with SLSA. Use when attesting CI/CD pipeline steps, proving an image followed the approved build process, or enforcing provenance at admission. Keywords: in-toto, layout, link metadata, step, inspection, SLSA, provenance, admission. Do not use for signing and verifying images with Cosign - use implementing-image-provenance-verification-with-cosign.
- ▌ Implementing Syslog Centralization With Rsyslog · gabrielmoreira bundleConfigure rsyslog for centralized log collection with TLS encryption, custom templates, and log rotation, generating server and client configuration files with GnuTLS stream drivers, x509 certificate authentication, per-host log segregation, and reliable queue settings. Use when building a centralized, encrypted syslog pipeline, hardening rsyslog client/server configs for high-availability log infrastructure, or troubleshooting TLS-based syslog forwarding.
- ▌ Implementing Zero Trust With Hashicorp Boundary · gabrielmoreira bundleInstalls and configures HashiCorp Boundary as a default-deny, identity-aware proxy for infrastructure access, including controller/worker setup, Vault-backed credential brokering, session recording, and OIDC/LDAP auth across an org/project scope hierarchy. Use when replacing VPN or direct network access with just-in-time, credential-less Boundary sessions, or standing up Boundary controllers and workers.
- ▌ Performing Active Directory Bloodhound Analysis · gabrielmoreira bundleUse BloodHound and SharpHound (or AzureHound) to enumerate Active Directory relationships and graph attack paths from a compromised user to Domain Admin. Use when performing AD red-team reconnaissance, mapping privilege-escalation chains from group memberships, ACLs, and trusts, or auditing AD for exploitable misconfigurations.
- ▌ Performing Active Directory Forest Trust Attack · gabrielmoreira bundleEnumerate and audit Active Directory forest trust relationships using Impacket for SID filtering analysis, trust key extraction, cross-forest SID history abuse detection, and inter-realm Kerberos ticket assessment. Use when red-teaming multi-forest AD environments or auditing forest trusts for cross-forest privilege escalation and trust ticket forgery exposure.
- ▌ Performing Automated Malware Analysis With Cape · gabrielmoreira bundleDeploy and operate the CAPEv2 malware sandbox (a Cuckoo derivative) to run samples in a monitored Windows guest VM, capturing behavioral signatures, dropped files, PCAP network traffic, and family-specific configuration extraction (e.g. Emotet, TrickBot, Cobalt Strike) via cape-parsers. Use when a suspicious file or payload needs automated dynamic analysis, anti-evasion debugger tricks, or config/payload extraction.
- ▌ Performing Hardware Security Module Integration · gabrielmoreira bundleIntegrates Hardware Security Modules (HSMs) via the PKCS#11 interface using python-pkcs11, performing key generation, signing, encryption, verification, and token/slot queries against SoftHSM2, AWS CloudHSM, or YubiHSM2. Use when implementing HSM-backed key management or validating HSM configuration for FIPS 140-2/3 compliance.
- ▌ Performing Network Traffic Analysis With Tshark · gabrielmoreira bundleAutomate network traffic analysis using tshark (Wireshark CLI) and pyshark to compute protocol distribution statistics, detect suspicious flows such as port scans and beaconing, extract IOCs (IPs, domains, URLs), and identify DNS tunneling patterns from PCAP files. Use when scripted or repeatable analysis of packet captures is needed rather than interactive inspection.
- ▌ Performing Ssl Certificate Lifecycle Management · gabrielmoreira bundleAutomates the full SSL/TLS certificate lifecycle, including generating Certificate Signing Requests, issuing, deploying, monitoring, renewing, and revoking X.509 certificates, using Python and ACME protocol tools. Use when managing certificate issuance or renewal, preventing certificate-expiry outages, or building automated PKI/ACME workflows.
- ▌ Performing Web Application Vulnerability Triage · gabrielmoreira bundleTriages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and prioritize remediation. Use when reviewing scanner output to reduce alert fatigue and rank vulnerabilities for development teams to fix.
- ▌ Sglang Diffusion Modelopt Quant · gabrielmoreiraUse when quantizing a diffusion DiT with NVIDIA ModelOpt and making the resulting FP8 or NVFP4 checkpoint loadable, verifiable, and benchmarkable in SGLang Diffusion.
- ▌ Syncfusion Maui Toolkit Linear Progressbar · gabrielmoreira bundleImplements Syncfusion .NET MAUI Linear ProgressBar (SfLinearProgressBar) control. Use when working with progress bars, progress indicators, loading indicators, determinate/indeterminate progress, or buffer progress visualization. Covers progress tracking, multi-segment progress, animated progress, and gradient progress bars.
- ▌ Confluence Assistant · gabrielmoreiraExpert in Confluence operations using Atlassian MCP. Use when the user says "search Confluence", "create a Confluence page", "update a page", "find documentation in Confluence", "list spaces", or "add a comment to a page". Do NOT use for Jira issues, general web search, or local file creation.
- ▌ Cloudbase Document Database Web Sdk · gabrielmoreiraUse CloudBase document database Web SDK only for confirmed NoSQL collection work. Query, create, update, and delete document data; if the task mentions PostgreSQL / CloudBase PG / app.rdb(), route to postgresql-development instead.
- ▌ Archive Protocol · gabrielmoreira全局归档协议。只要任务需要写入任何文件(含 PLAN.md、报告、JSON 等归档物),必须按本技能执行 Session→ARCHIVE_ID、TIMESTAMP、双轨路径(根段须为 archives/)、回读校验与状态回执;WebUI 的 archive_grid 必须用 Markdown 中语言标识为 json 的围栏代码块输出。
- ▌ AI Coding Agents Provider Runtime · gabrielmoreiraDesigns provider runtimes for coding agents. Use when modeling model abstraction, streaming semantics, tool-call normalization, retries, or fallback routing.
- ▌ Dev Contribution Quality Analysis · gabrielmoreiraAnalyzes commit and PR history to score contribution quality objectively. Use when building engineering scorecards, calibrating promotions, or measuring AI-assist impact.
- ▌ Foundations Consumer Neuroscience · gabrielmoreiraConsumer-neuroscience primitives for attention, arousal, bonding, narrative, memory, and reward. Use when shaping ethical UX, neuro study design, or DMCC/AI Act gates.
- ▌ Foundations Theory Of Constraints · gabrielmoreiraTheory of Constraints primitives for focusing steps, drum-buffer-rope, throughput accounting, critical chain, and policy constraints. Use when sequencing by bottleneck.
- ▌ Performing GRAPHQL Depth Limit Attack · gabrielmoreiraExecute and test GraphQL depth limit attacks using deeply nested recursive queries to identify denial-of-service vulnerabilities in GraphQL APIs.
- ▌ Testing API Authentication Weaknesses · gabrielmoreiraTests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester evaluates JWT implementation, API key handling, OAuth flows, and session token entropy to identify authentication bypasses. Maps to OWASP API2:2023 Broken Authentication. Activates for requests involving API authentication testing, token validation assessment, credential security testing, or API auth bypass.
- ▌ Performing Linux Post Exploitation · gabrielmoreiraPost-exploitation on Linux during authorized engagements — credential harvesting from process environments, systemd units and dotfiles, PAM-based credential capture and backdoors, GPG keyring relocation for offline decryption, and persistence / stealth tradecraft (process masquerading, BPF passive backdoors) plus the hunts that detect them.
- ▌ Analyzing Heap Spray Exploitation · gabrielmoreiraDetect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
- ▌ Detecting Attacks On Scada Systems · gabrielmoreiraThis skill covers detecting cyber attacks targeting Supervisory Control and Data Acquisition (SCADA) systems including man-in-the-middle attacks on industrial protocols, unauthorized command injection into PLCs, HMI compromise, historian data manipulation, and denial-of-service against control system communications. It leverages OT-specific intrusion detection systems, industrial protocol anomaly detection, and process data analytics to identify attacks that traditional IT security tools miss.
- ▌ Analyzing Dns Logs For Exfiltration · gabrielmoreiraAnalyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.
- ▌ Building Detection Rules With Sigma · gabrielmoreiraBuilds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. Use when creating portable detection logic from threat intelligence, mapping rules to MITRE ATT&CK techniques, or converting community Sigma rules into platform-specific queries using sigmac or pySigma backends.
- ▌ Exploiting Ldap Injection · gabrielmoreiraExploiting LDAP injection where web applications build LDAP search filters from unsanitized user input, letting an attacker manipulate filter logic to bypass authentication, enumerate directory objects, and blind-extract attribute values such as passwords. Activates when login forms, search boxes, or directory lookups feed user input into LDAP filters (uid, cn, mail, etc.).
- ▌ Competition Request Normalization Smuggling · gabrielmoreiraInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for parser differentials, HTTP normalization gaps, ambiguous headers, path decoding drift, transfer-framing mismatches, and request smuggling routes. Use when the user asks to trace proxy and backend parse differences, conflicting path normalization, Host or forwarded-header ambiguity, CL/TE issues, or routing outcomes that differ across hops. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- ▌ Chengfeng Report Bug · gabrielmoreira整理、脱敏并上报 chengfeng-videocut 的 GitHub Bug。用户说上报 Bug、反馈剪口播问题、提交 GitHub Issue、这个问题告诉开发者,或要求继续提交已预览的 Bug 草稿时使用。不要用于功能建议、普通排错、代码提交或未获用户确认的自动上报。
- ▌ Discussion Composer · gabrielmoreiraComposes a Discussion around key findings, mechanisms, clinical relevance, and limitations. Use when writing or improving a Discussion section for any biomedical manuscript — including interpreting results, connecting to prior literature, addressing unexpected findings, framing limitations, and writing the conclusion. Also triggers on "write my discussion", "help me discuss my findings", "how do I compare to prior studies", "write the limitations paragraph", or "draft a discussion for my paper".
- ▌ Paper Sprint Review · gabrielmoreiraScrum-inspired paper review, revision, and R&R workflow. Handles docx/tex/md/PDF in English or Chinese. Auto-detects manuscript stage, estimates sprint count, runs multi-lens review (Contribution/Rigor/Writing/Editor), generates prioritized revision backlog, exports MD/DOCX/PDF/HTML reports. Use when asked to review a paper, revise based on reviewer comments, handle R&R, respond to peer review, plan paper revision sprints, or when user types /ps or /papersprint.
- ▌ Decision Tree Analysis · gabrielmoreiraUse when building a decision tree model in R and generating feature importance ranking outputs. Supports classification and regression, automatic task detection, parameter validation, model evaluation summaries, and exports of feature-importance tables and figures.
- ▌ Deg Screening Analysis · gabrielmoreiraUse when screening differentially expressed genes from a bulk expression matrix between two user-specified groups, producing DEG tables, a volcano plot, and a clustered heatmap. Triggers include DEG analysis, volcano plot, clustered heatmap, limma-based two-group comparison, and case-vs-control screening. NOT for single-cell RNA-seq, multi-group contrasts, count-model workflows such as DESeq2/edgeR, or non-expression omics data.
- ▌ Method Gap Detector · gabrielmoreiraDetects methodological gaps across study design, analysis, validation, bias control, reproducibility, and implementation readiness within a biomedical research area. Use this skill when a user wants to identify what current studies are still methodologically missing, which weaknesses are most consequential, and what upgrade path would produce a stronger next-step study. Always separate design gaps, analysis gaps, validation gaps, and reproducibility gaps. Never treat technical complexity as methodological rigor.
- ▌ Automated Soap Note Generator · gabrielmoreiraGenerate structured SOAP notes from clinical narratives, transcripts, or existing notes; use when the user needs de-identified clinical documentation organized into Subjective, Objective, Assessment, and Plan sections, with clear assumptions and review points.
- ▌ Blockbuster Therapy Predictor · gabrielmoreiraComprehensive analytics tool for forecasting breakthrough therapeutic technologies by integrating multi-dimensional data sources including clinical development pipelines, intellectual property landscapes, and capital mar.
- ▌ Clinical Study Info Extractor · gabrielmoreiraBatch extracts and verifies structured information (PMID, title, abstract, methodology, results, etc.) from clinical research literature using PMIDs. Use when the user wants to extract details from specific PMIDs.
- ▌ Literature Experiment Extract · gabrielmoreiraExtract experimental models, experimental methods, and biomarker information from paper Markdown (typically produced by PDF-to-Markdown tools) when a user provides paper Markdown and needs a structured, evidence-backed summary (1 Markdown + 3 CSVs).
- ▌ Two Sample Mr Research Planner · gabrielmoreiraGenerates complete two-sample Mendelian randomization (MR) research designs from a user-provided research direction. Use when users want to design, plan, or build a study using two-sample MR to test causal relationships. Triggers:"design a two-sample MR study", "build a publishable MR paper", "test whether this biomarker causally affects this disease", "generate Lite/Standard/Advanced MR plans", "screen multiple exposures with MR", "bidirectional MR design", "causal inference using GWAS summary statistics", or "I want to study X and Y using MR". Always outputs four workload configurations (Lite / Standard / Advanced / Publication+) with a recommended primary plan, step-by-step workflow, figure plan, validation strategy, minimal executable version, and publication upgrade path.
- ▌ Tres Upload Tx Header Validation · gabrielmoreiraThe exact column header names required by the TRES Finance bulk transaction CSV upload. Use whenever building, fixing, or validating the header row of a TRES manual transaction or sub-transaction upload CSV — especially after an upload fails with "Missing required column(s): ...". Trigger phrases include: 'fix my CSV headers', 'bulk transaction upload failed', 'missing required columns', 'validate TRES upload CSV', 'transaction CSV template headers'. This skill is ONLY about the header naming convention; it does not cover row values or upload workflow. Do NOT trigger for contacts import CSV (use tres-import-contacts), wallet upload CSV (use tres-wallets-upload), or general CSV parsing unrelated to bulk TX upload headers.
- ▌ Bio Comparative Genomics Genome Distance And Species Delinea · gabrielmoreira bundleCompute genome-to-genome distances (ANI, AAI, dDDH, k-mer Mash) and assign taxonomic classifications using skani (Shaw 2023), FastANI (Jain 2018), pyani / pyANI ANIb / ANIm, OrthoANI (Lee 2016), AAI (amino-acid identity), dDDH via TYGS / GGDC, GTDB-Tk (Chaumeil 2020 standard prokaryote taxonomy), and Mash MinHash (Ondov 2016). Use when delineating prokaryote species (95% ANI threshold; Jain 2018 Nat Commun 9:5114), assigning genomes to GTDB taxonomy with ANI radius, computing genome similarity matrices for clustering, classifying archaea, evaluating MAG (metagenome-assembled genome) species assignment, applying skani for fast metagenomic ANI screening, or reconciling 16S rRNA-based taxonomy with whole-genome ANI.
- ▌ Bio Restriction Fragment Analysis · gabrielmoreira bundleAnalyze restriction digest fragments using Biopython Bio.Restriction. Predict fragment sizes, get fragment sequences, simulate gel electrophoresis patterns, and perform double digests. Use when analyzing restriction digest fragment patterns.
- ▌ Platform Apex Anonymous Run · gabrielmoreiraUse this skill to run anonymous Apex against the connected Salesforce org — from a .apex file or a pasted snippet — capturing the debug log, surfacing compile and runtime errors, and summarizing results. Trigger on phrases like "run this anonymous apex", "execute this script against my org", "run this snippet of Apex", "what does this code return", or "execute scripts/foo.apex". Wraps verification-style scripts in a savepoint and rollback so org state is untouched, and warns before running against production. DO NOT TRIGGER for authoring .cls or .trigger files (use platform-apex-generate), running Apex unit tests (use platform-apex-test-run), or deep debug-log analysis (use platform-apex-logs-debug).
- ▌ Platform Destructive Deploy · gabrielmoreiraExecute the destructiveChanges.xml delete-and-deploy workflow against a Salesforce org. TRIGGER when the user asks to delete/remove a custom object, field, Apex class, flow, or any metadata component FROM an org, or to perform a 'destructive deploy' / removal as part of a release. Validates first and gates production with explicit confirmation. DO NOT TRIGGER for local file deletion (use Bash), or for net-new deploys (use platform-metadata-deploy).
- ▌ Write A Postmortem · gabrielmoreiraWrite a blameless incident postmortem under postmortems/ following the Google SRE shape — evidence-based timeline, trigger vs root cause vs symptom, contributing factors, what went well, and owned+dated+verifiable action items. Read when asked to write a postmortem, do an incident review, run a root cause analysis, write up the outage, retro on the outage, or when the user says we had an incident and wants it documented. Do NOT read to frame a proposal (use frame-a-proposal), write a spec (use write-a-spec), record a decision (use record-a-decision), or review a design (use review-a-design) — a postmortem documents an incident that already happened, it does not propose, specify, decide, or critique future work.
- ▌ Web Analytics · gabrielmoreiraPush-based web analytics intelligence for your entire site portfolio. Fetches data from Umami (primary) and GA4 (fallback), runs specialist analysis agents in parallel, and delivers actionable insights. Three tiers: mini (30s pulse), medium (2min brief), full (5min deep dive). Supports console, email, and Slack delivery. Trigger with "/analytics", "check my analytics", "how's my traffic", "site stats", "traffic report", "analytics brief", "daily brief".
- ▌ Audit Skill · gabrielmoreiraAudit and improve a Claude Code skill using Skill Crossroads. Use when the user says "audit my skill", "grade my skill", "check my skill quality", "why doesn't my skill trigger", or "lint my SKILL.md" — or before publishing any skill, to get an evidence-cited quality score, ranked fix list, and badge. Trigger with "audit my skill".
- ▌ Find MCP Directories · gabrielmoreiraUse whenever the user wants to find, rank, or shortlist directories and registries where they can submit or list an MCP server (Model Context Protocol server) — to get backlinks, referral traffic, and discovery by agent builders. Triggers on "where do I list my MCP server", "best MCP directories", "MCP registries to submit to", "get my MCP server discovered", or "pull submission details for these MCP-directory domains", even when described indirectly (we built an MCP server, where do we publish it). Drives the ServiceGraph API (api.servicegraph.co) — a catalog of 1,000+ product directories enriched with Domain Rating, backlinks, and organic traffic. Defer to find-ai-directories for general AI-tool / AI-agent / agent-skill listings, and to find-product-directories for general SaaS/software launches. Skip building an MCP server or asking how MCP works (DIY), finding a firm to build one (use find-ai-consultancy / find-software-developer), and MCP link-building *services*.
- ▌ Find Recruiting Firm · gabrielmoreiraUse whenever the user wants to find, shortlist, vet, or enrich US recruiting and staffing firms — executive search/retained search, RPO, tech/sales/healthcare recruiting, contingent/contract staffing, and temp staffing. Triggers on "find me an executive search firm for a CFO search", "shortlist three retained-search boutiques in NY focused on tech", "we need RPO support for a 50-engineer hiring push", or "pull contact info for these 8 staffing firm domains", even when described indirectly (need help hiring at scale, executive recruiter for senior roles). Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings. Skip when the user wants to hire someone as their own employee (job-board questions, in-house recruiter hires, "where should I post the role"), individual job-seekers looking for recruiters to represent them, candidate-side career coaching, non-US firms, individual freelance recruiters.
- ▌ Sync Profiles · gabrielmoreiraUse when the user wants to list, create, switch, delete, compare, or inspect config sync profiles.
- ▌ Miro Rate Limits · gabrielmoreiraImplement Miro REST API v2 rate limiting with the credit-based system, exponential backoff, and request queuing. Trigger with phrases like "miro rate limit", "miro throttling", "miro 429", "miro retry", "miro backoff", "miro credits".
- ▌ Detecting Command Injection Patterns · gabrielmoreira bundleScan a source tree for command-injection vulnerable patterns: shell=True calls in Python subprocess, os.system / os.popen with interpolated strings, Node child_process.exec with template literals, Ruby backticks / Kernel#system / Kernel#exec with interpolation, Go exec.Command with shell wrapping, PHP system / passthru / shell_exec / backticks with $-interpolation, Java Runtime.exec with concatenated args. Use when: pre-commit gate on code that calls out to shell utilities, audit of file-processing / archive-handling / image-conversion code, post-bug-report investigation for "we shell out to a tool." Threshold: any shell-invocation API called with a string that contains a variable interpolation, OR shell=True with anything other than a fixed literal. Trigger with: "scan command injection", "shell=True audit", "find exec calls", "check os.system".
- ▌ Music Generation · gabrielmoreiraAI music generation via Replicate — 5 models for background tracks, lyrics, and sound design
- ▌ Video Generation · gabrielmoreiraAI video generation via Replicate — 17 models, editing, and production workflows
- ▌ Generate Report · gabrielmoreiraGenerate an interactive, self-contained HTML dashboard displaying SFI-TI3.2.2 tenant isolation violations for a service, org, or alias -- includes filtering, sorting, severity coding, TSG links, S360 deep links.
- ▌ Nnf Cve Cleanup · gabrielmoreiraCleans up NNF deployments impacted by vulnerable or outdated container images using guided execution.
- ▌ Coherence Audit · gabrielmoreiraDetect coherence violations between Alex_ACT_Edition (brain) and Alex_Skill_Mall (marketplace) — broken references, tag mismatches, deprecated install snippets
- ▌ Source Command Methodology Advisor · gabrielmoreiraAnalyzes your codebase and asks 3 targeted questions to recommend the right AI-assisted development methodology stack
- ▌ Platform Deploy Validate · gabrielmoreiraValidate Salesforce metadata before deploying. TRIGGER when the user asks to validate a deploy, do a dry-run, check before deploying, or targets a Production org for any deploy operation. Routes prod targets to `sf project deploy validate` (returns a 10-day quick-deploy job ID) and sandbox/scratch targets to `sf project deploy start --dry-run`. DO NOT TRIGGER for actual deploys (use platform-metadata-deploy) or destructive changes (use platform-destructive-deploy).
- ▌ Quality · gabrielmoreiraEvaluates whether a GitHub issue is spam, empty, needs more information, or is OK to proceed.
- ▌ Review A Design · gabrielmoreiraReviews whether a design is SOUND — solving the right problem, derived from its stated goals and constraints — and emits ranked, evidence-backed findings, not edits. Read when asked to 'review this design', 'is this design sound', 'pressure-test this proposal', 'do a design review', 'does this solve the right problem', 'poke holes in this spec', 'should we build this', or to critique a proposal / spec / ADR / architecture or product decision. Do NOT read when the user wants to AUTHOR one of these — routing a new proposal is frame-a-proposal, a spec is write-a-spec, a decision record is record-a-decision, a postmortem is write-a-postmortem. Do NOT read for code review of a diff, or to fact-check individual claims (that is a correctness pass, a different job).