gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Configuring Zscaler Private Access For Ztna · gabrielmoreira bundleConfigures Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring identity- and device-posture-based access policies, and integrating with IdPs. Use when replacing VPN concentrators with ZTNA or providing remote users secure access to internal applications without network-level connectivity.
- ▌ Deobfuscating Powershell Obfuscated Malware · gabrielmoreira bundleSystematically deobfuscates multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure. Use during incident response or malware analysis when a PowerShell script is obfuscated with encoding, string manipulation, or invocation tricks and you need to recover the underlying commands, dropped payloads, or C2 endpoints.
- ▌ Detecting AI Model Prompt Injection Attacks · gabrielmoreira bundleDetects prompt injection using regex signature matching, heuristic scoring for structural anomalies, and DeBERTa-based transformer classification, flagging direct injections (system-prompt overrides, role-play escapes) and indirect injections (encoded payloads, obfuscation) per OWASP LLM Top 10 (LLM01:2025). Use for input validation layers in chatbots/agents/RAG pipelines, or for retrospectively classifying injection attempts in logs or incident investigations.
- ▌ Detecting AWS Guardduty Findings Automation · gabrielmoreira bundleBuild automated AWS GuardDuty finding response pipelines using EventBridge and Lambda to trigger real-time incident response, automatically quarantine compromised resources, and route security notifications. Use when designing automated remediation playbooks for GuardDuty findings across VPC Flow Logs, CloudTrail, DNS, EKS, or S3 data events, or when reducing mean time to respond to cloud threats.
- ▌ Detecting Container Escape With Falco Rules · gabrielmoreira bundleWrites and tunes Falco rule syntax for container escape detection - conditions, macros, lists, priorities, and output fields - covering host filesystem mounts, sensitive host path access, kernel module loading, and privileged capability abuse, including how to drive down false positives. Use when authoring or tuning a specific Falco rule for breakout behaviour, or triaging a noisy escape-related Falco alert. Keywords: Falco rule, macro, list, condition, priority, falco_rules.local.yaml, tuning, false positive. Do not use for deploying and operating Falco itself - use detecting-container-runtime-threats-with-falco; for tool-agnostic escape signals use detecting-container-escape-attempts.
- ▌ Detecting Dcsync Attack In Active Directory · gabrielmoreira bundleDetect DCSync attacks (MITRE T1003.006) where adversaries abuse Active Directory replication privileges to extract password hashes, by auditing Event ID 4662 for the DS-Replication-Get-Changes GUIDs and flagging non-domain-controller accounts issuing DsGetNCChanges RPC calls. Use when hunting for credential theft via Mimikatz lsadump::dcsync or Impacket secretsdump, investigating lateral movement with domain admin credentials, or auditing AD replication permissions.
- ▌ Detecting Deepfake Audio In Vishing Attacks · gabrielmoreira bundleDetect AI-generated deepfake audio used in voice phishing (vishing) by extracting spectral features (MFCC, spectral centroid, spectral contrast, zero-crossing rate) and classifying samples with machine learning models, supporting batch audio analysis, confidence scoring, and forensic reporting. Use for deepfake voice detection, vishing investigations, AI-generated speech analysis, voice cloning detection, or audio authenticity verification.
- ▌ Detecting Ntlm Relay With Event Correlation · gabrielmoreira bundleDetect NTLM relay attacks (T1557.001) by correlating Windows Event 4624 LogonType 3 for IP-to-hostname mismatches, identifying Responder/LLMNR poisoning artifacts, auditing SMB/LDAP signing, and flagging NTLMv2-to-NTLMv1 downgrades. Use for hunting credential relay in NTLM-enabled AD, investigating auth-source anomalies, building SIEM correlation rules, or responding to PetitPotam/DFSCoerce/PrinterBug alerts.
- ▌ Detecting T1003 Credential Dumping With Edr · gabrielmoreira bundleDetect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security event logs. Use when hunting for Mimikatz-style credential theft, triaging an EDR alert on LSASS access, or scoping an incident after suspected credential dumping.
- ▌ Generating Forensic Timelines With Hayabusa · gabrielmoreira bundleRun Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and per-host/per-Event-ID metrics. Use during DFIR triage to turn raw event logs into a fast, SIEM-free incident timeline, or to export results into Timesketch or Timeline Explorer for collaborative analysis.
- ▌ Hunting For Living Off The Cloud Techniques · gabrielmoreira bundleHunts for adversary abuse of legitimate cloud services (Azure, AWS, GCP, and SaaS platforms) for command-and-control, data staging, and exfiltration, i.e. "living off the cloud" tradecraft that blends in with normal cloud API and service activity. Use when threat hunting for cloud-native C2 channels, abnormal use of storage/SaaS services for data staging, or exfiltration hidden in legitimate cloud traffic.
- ▌ Hunting For Registry Persistence Mechanisms · gabrielmoreira bundleHunts for registry-based persistence mechanisms (MITRE T1547) in Windows environments, including Run/RunOnce keys, Winlogon Shell/Userinit modifications, Image File Execution Options (IFEO) debugger injection, and COM hijacking via CLSID overrides. Use when auditing the registry for persistence artifacts or building detections for registry-based malware autostart techniques.
- ▌ Implementing Anti Phishing Training Program · gabrielmoreira bundleGuides designing, deploying, and measuring an anti-phishing security awareness program - baseline phishing simulations, interactive training modules, just-in-time learning, and metric tracking - using platforms like KnowBe4, Proofpoint Security Awareness, or Cofense. Use when building or maturing a phishing awareness program, establishing training controls for compliance, or measuring phishing susceptibility and reporting rates over time.
- ▌ Implementing API Schema Validation Security · gabrielmoreira bundleImplements API schema validation using OpenAPI Specification and JSON Schema documents, enforced both at the API gateway (runtime) and during development (shift-left), to lock down request/response contracts and reject unknown properties. Use when preventing injection attacks (SQLi, XSS, XXE), blocking mass assignment, or stopping data leakage through unvalidated API responses.
- ▌ Implementing Cisa Zero Trust Maturity Model · gabrielmoreira bundleAssess, gap-analyze, and progressively implement the CISA Zero Trust Maturity Model v2.0 across five pillars (Identity, Devices, Networks, Applications & Workloads, Data) and three cross-cutting capabilities (Visibility/Analytics, Automation/Orchestration, Governance), from Traditional through Optimal maturity. Use for a federal/enterprise ZTMM assessment, phased roadmap, or mapping controls to NIST SP 800-207 and EO 14028.
- ▌ Implementing Runtime Security With Tetragon · gabrielmoreira bundleImplements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking dangerous calls at the kernel level. Use when deploying Tetragon to detect or block syscalls such as ptrace, mount, and unshare, enforcing kernel-level policy, or adding low-overhead runtime detection to a cluster. Keywords: Tetragon, Cilium, eBPF, TracingPolicy, kprobe, enforcement, process lineage. Do not use for Falco-based detection - use detecting-container-runtime-threats-with-falco.
- ▌ Implementing Siem Correlation Rules For Apt · gabrielmoreira bundleWrite multi-event correlation rules in Splunk SPL and Sigma format that detect APT lateral movement by chaining Windows authentication events (4624, 4648), process execution (4688, Sysmon Event 1), and network connections (Sysmon Event 3) across hosts within sliding time windows. Use when building SIEM correlation searches to surface multi-stage attack sequences that single-event detections miss, such as pass-the-hash or lateral movement chains.
- ▌ Integrating Dast With Owasp Zap In Pipeline · gabrielmoreira bundleIntegrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation, scan policy tuning, and DAST quality gates. Use when testing running web apps or REST/GraphQL APIs for XSS, SQLi, CSRF, and auth/authz flaws, or when SAST alone is insufficient and runtime DAST is required for compliance or release gating.
- ▌ Parsing Artifacts With Eric Zimmerman Tools · gabrielmoreira bundleParse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis. Use during DFIR/incident-response investigations, after triage collection (e.g. with KAPE), to establish program execution, file/folder access, and persistence evidence from acquired forensic images.
- ▌ Performing Authenticated Vulnerability Scan · gabrielmoreira bundlePlan and run authenticated (credentialed) vulnerability scans with scanners such as Nessus, Qualys, OpenVAS, or Rapid7 InsightVM, using SSH, SMB, WinRM, or SNMPv3 credentials to inspect installed software, patches, and configurations on Linux, Windows, and network devices. Use when a scan must catch vulnerabilities unauthenticated scanning misses, or when choosing and managing credential types for a credentialed scan.
- ▌ Performing Dmarc Policy Enforcement Rollout · gabrielmoreira bundleExecute a phased DMARC rollout by inventorying sending sources, configuring SPF/DKIM alignment, and progressing DNS policy from p=none monitoring through p=quarantine to p=reject enforcement, ensuring all legitimate email sources authenticate before unauthorized senders are blocked. Use when deploying or advancing an organization's DMARC anti-spoofing posture, or when meeting bulk-sender authentication requirements from Google and Yahoo.
- ▌ Performing Docker Bench Security Assessment · gabrielmoreira bundleRuns Docker Bench for Security, the open-source CIS Docker Benchmark audit script, across host configuration, daemon settings, images, and runtime configuration, then interprets pass/fail/warn output and remediates the common failures. Use when auditing Docker hosts for CIS compliance, scheduling recurring container assessments, or validating runtime hardening controls after a change. Keywords: docker-bench-security, CIS Docker Benchmark, audit script, pass fail warn, host configuration, remediation. Do not use for applying the daemon hardening itself - use hardening-docker-daemon-configuration.
- ▌ Performing False Positive Reduction In Siem · gabrielmoreira bundleReduces SIEM false positives through systematic rule tuning, threshold adjustment, correlation logic refinement, allowlisting, and threat intelligence enrichment. Use when SOC analysts are overwhelmed by alert noise, when tuning noisy detection rules, or during a quarterly SIEM rule review to cut alert fatigue.
- ▌ Performing Ics Asset Discovery With Claroty · gabrielmoreira bundlePerforms ICS/OT asset discovery with Claroty xDome, combining passive monitoring and Claroty Edge active queries to inventory PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels. Use when gaining visibility into an undocumented OT environment, preparing an IEC 62443 asset inventory, or onboarding Claroty xDome; not for IT-only discovery.
- ▌ Performing Network Forensics With Wireshark · gabrielmoreira bundleCapture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control communications. Use when analyzing captured traffic from a security incident, reconstructing data exfiltration, or finding network indicators of compromise during malware analysis.
- ▌ Performing Oil Gas Cybersecurity Assessment · gabrielmoreira bundleConduct cybersecurity assessments of upstream, midstream, and downstream oil and gas operations, covering pipeline SCADA, refinery DCS, safety instrumented systems, and remote wellhead RTUs, and evaluate compliance with API 1164, TSA Pipeline Security Directives, and IEC 62443. Use when assessing a refinery, pipeline, or production facility or preparing for TSA/API compliance audits; not for IT-only or purely physical-security assessments.
- ▌ Performing Phishing Simulation With Gophish · gabrielmoreira bundleDeploy and run authorized phishing awareness campaigns with GoPhish, covering admin panel setup, SMTP sending profiles, email template and landing page creation, target user groups, and campaign reporting to measure click and credential-submission rates. Use when planning or executing a phishing simulation for employee security-awareness testing or measuring susceptibility to social engineering.
- ▌ Performing Privileged Account Access Review · gabrielmoreira bundleConducts systematic reviews of privileged accounts to validate access rights, identify excessive or stale permissions, and enforce least privilege across PAM infrastructure. Use when auditing privileged access for compliance, periodic access recertification, or investigating whether privileged entitlements are still justified.
- ▌ Performing Ssl Tls Inspection Configuration · gabrielmoreira bundleConfigure SSL/TLS break-and-inspect on next-generation firewalls and forward proxies to decrypt, inspect, and re-encrypt HTTPS traffic for malware and exfiltration detection, including deploying trusted CA certificates, managing exemptions for certificate-pinned apps, and privacy compliance. Use when setting up or auditing TLS inspection on network security devices to close the encrypted-traffic blind spot.
- ▌ Securing Historian Server In Ot Environment · gabrielmoreira bundleAudits and hardens process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments: Purdue-level network placement, interface access control, secure DMZ replication via data diodes or PI-to-PI connectors, SQL injection prevention, and process data integrity. Use when auditing or hardening a historian server, or designing secure OT-to-IT data replication through a DMZ.
- ▌ Triaging Security Incident With Ir Playbook · gabrielmoreira bundleClassifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the appropriate response procedures. Use when a new SOC alert needs triage, multiple concurrent incidents require prioritization, or automated triage rules need validation or tuning.
- ▌ Android Data Layer · gabrielmoreiraGuidance on implementing the Data Layer using Repository pattern, Room (Local), and Retrofit (Remote) with offline-first synchronization.
- ▌ Signals Scout Customer Analytics Billing And Usage · gabrielmoreiraSignals scout for per-account product-mix shifts. Watches each staked account's usage and forecasted MRR per product for one product dropping or spiking against its own baseline while the account total holds.
- ▌ Parallel Investigation · gabrielmoreiraCoordinates parallel investigation threads to simultaneously explore multiple hypotheses or root causes across different system areas. Use when debugging production incidents, slow API performance, multi-system integration failures, or complex bugs where the root cause is unclear and multiple plausible theories exist; when serial troubleshooting is too slow; or when multiple investigators can divide root-cause analysis work. Provides structured phases for problem decomposition, thread assignment, sync points with Continue/Pivot/Converge decisions, and final report synthesis.
- ▌ Copilot Session Management · gabrielmoreiraManage and diagnose GitHub Copilot CLI sessions, plugins, marketplaces, and MCP configuration. Use when sessions cannot resume, plugin installation fails, or local Copilot state needs repair.
- ▌ Syncfusion Maui Toolkit Numeric Updown · gabrielmoreira bundleImplement the Syncfusion .NET MAUI NumericUpDown control for numeric input with validation, formatting, and increment/decrement buttons. Use this skill when building forms requiring numeric entry with up-down buttons, currency formatting, percentage values, decimal precision, custom formats, input validation, or placeholder text.
- ▌ Syncfusion Maui Toolkit Pyramid Charts · gabrielmoreira bundleImplements Syncfusion .NET MAUI Pyramid Chart (SfPyramidChart) for visually representing hierarchical, proportional, and parts-to-whole data using pyramid-shaped segments. Use this for pyramid charts, hierarchical data visualization, proportional data display, or segment-based charts. This skill covers installation, data binding, legends, tooltips, data labels, appearance customization, and gradients.
- ▌ Spec Driven Eval · gabrielmoreira bundleScores how completely an implementation fulfills a PRD/spec, case by case, and produces a single comparable final grade. Invoke only when explicitly named (e.g. run spec-driven-eval); do not auto-trigger. Use when benchmarking spec-driven implementations, grading acceptance criteria, evaluating whether a feature was 100% implemented, comparing multiple implementations of the same PRD, or auditing implementation and test coverage (unit and e2e) against product requirements. Do NOT use for planning or building features (use tlc-spec-driven), writing PRDs, or general code review unrelated to a spec.
- ▌ Algorand Vulnerability Scanner · gabrielmoreiraScans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
- ▌ Fullstack Dev · gabrielmoreiraFull-stack backend architecture and frontend-backend integration guide. TRIGGER when: building a full-stack app, creating REST API with frontend, scaffolding backend service, building todo app, building CRUD app, building real-time app, building chat app, Express + React, Next.js API, Node.js backend, Python backend, Go backend, designing service layers, implementing error handling, managing config/auth, setting up API clients, implementing auth flows, handling file uploads, adding real-time features (SSE/WebSocket), hardening for production. DO NOT TRIGGER when: pure frontend UI work, pure CSS/styling, database schema only.
- ▌ Detecting Cryptomining In Cloud · gabrielmoreiraThis skill teaches security teams how to detect and respond to unauthorized cryptocurrency mining operations in cloud environments. It covers identifying cryptomining indicators through compute usage anomalies, network traffic patterns to mining pools, GuardDuty CryptoCurrency findings, and runtime process monitoring on EC2, ECS, EKS, and Azure Automation workloads.
- ▌ Pentesting Couchdb · gabrielmoreiraTesting Apache CouchDB document databases (default HTTP port 5984, HTTPS 6984) for unauthenticated/admin-party access, database dumping over the REST API, default/weak credentials, the CVE-2017-12635 privilege-escalation admin-creation bug and CVE-2017-12636/CVE-2018-8007 remote-code-execution paths, plus Erlang EPMD cookie abuse during authorized engagements.
- ▌ Pentesting Mongodb · gabrielmoreiraTesting MongoDB document databases (default ports 27017 and 27018) for no-auth/unauthenticated access, weak credentials, database and collection dumping, predictable ObjectID enumeration, config-based auth bypass, and the MongoBleed unauthenticated memory-disclosure CVE during authorized engagements.
- ▌ Pentesting Netbios · gabrielmoreiraTesting NetBIOS over TCP/IP services during authorized engagements. Covers the NetBIOS Name Service (137/udp, 137/tcp), Datagram Service (138/udp), and Session Service (139/tcp). Focuses on name and MAC enumeration with nmblookup, nbtscan and nmap nbstat, identifying workgroups/domains, and pivoting to SMB over NetBIOS (139) for share and user enumeration.
- ▌ Performing Purple Team Exercise · gabrielmoreiraPerforms purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.
- ▌ Analyzing Cyber Kill Chain · gabrielmoreiraAnalyzes intrusion activity against the Lockheed Martin Cyber Kill Chain framework to identify which phases an adversary has completed, where defenses succeeded or failed, and what controls would have interrupted the attack at earlier phases. Use when conducting post-incident analysis, building prevention-focused security controls, or mapping detection gaps to kill chain phases. Activates for requests involving kill chain analysis, intrusion kill chain, attack phase mapping, or Lockheed Martin kill chain framework.
- ▌ Monitoring Darkweb Sources · gabrielmoreiraMonitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.
- ▌ Chengfeng Export · gabrielmoreira把剪好的口播烧成一个成片文件:账本切片段、推近、字幕、HTML 画面层,一次全部烧进 mp4。用户说导出、出成片、烧字幕、渲染、导出视频、生成最终文件时使用。不要用于生成删词候选、写字幕、做画面动画。
- ▌ Chengfeng Visual · gabrielmoreira给剪好的口播配画面:在录屏上盖 HTML 层(圈重点标注 / 小黑整屏动画 / 推近),层绑字幕屏、由播放器逐帧驱动、直接在预览里看。用户说做分镜、配画面、加动画、圈重点、B-roll、做 storyboard 时使用。不要用于删词剪辑、字幕、物理剪切或成片渲染。
- ▌ Arxiv Preflight · gabrielmoreiraRun a submission-readiness preflight on a manuscript before arXiv upload. Use when the user is preparing an arXiv submission, asks to check a paper before uploading, mentions hallucinated or fake references, leftover LLM meta-comments / prompts in text, placeholder data (TODO, TBD, XX%), AI-use disclosure, scholarly integrity, research integrity, or arXiv moderation risk — even if they don't say "preflight". Also trigger on phrases like "check my paper before arXiv", "verify my references", "scan for AI artifacts", "scan for LLM residue", "is my submission ready", or "review .tex/.bib before submit".
- ▌ Time Dependent Roc · gabrielmoreiraUse when performing time-dependent ROC curve analysis for survival data with follow-up time, event status, and a numeric marker. Supports CSV/TXT/TSV/Excel input, `risk_score` as the default marker unless `--marker_col` is provided, parameter validation, standardized output directories, AUC table export, ROC point export, and PDF figure generation.
- ▌ Umap Tsne Analysis · gabrielmoreiraUse when performing sample-level dimensionality reduction and visualization on abundance or OTU-style matrices with a companion group file, generating UMAP and/or t-SNE coordinates and plots for group separation assessment. NOT for: differential expression testing, single-cell workflows requiring dedicated embeddings pipelines, or analyses without a sample grouping file.
- ▌ Academic Abstract Refiner · gabrielmoreiraRefines long medical academic texts into SCI-style unstructured Chinese and English abstracts; use when you need to condense drafts/reports/summaries into bilingual abstracts and generate Summary_Report.md.
- ▌ Irb Application Assistant · gabrielmoreiraAssists researchers with Institutional Review Board (IRB) application tasks, including drafting informed consent documents, reviewing research protocols for compliance, generating application forms, and preparing submission checklists. Use when the user mentions IRB, Instituti...
- ▌ Meta Manuscript Generator · gabrielmoreiraGenerates a first draft of a clinical meta-analysis paper. Input the research report (including Methods and Results sections), language, and title to automatically generate a complete paper draft including Abstract, Introduction, Discussion, and other sections, with automatic ...
- ▌ Meta Results Risk Of Bias · gabrielmoreiraGenerates the "Risk of Bias" results section for a meta-analysis based on assessment tables and statistics. Use when the user wants to draft the risk of bias analysis text from provided data tables.
- ▌ Literature Extensive Read · gabrielmoreiraRapidly skim and summarize academic papers (default:PDF-to-Markdown full text with `## Page XX` pagination and image references) and output a structured extensive-reading summary in Markdown when you need to quickly understand research questions, methods, key results, conclusions, and decide whether intensive reading is worthwhile.
- ▌ Reference Retrieval Skill · gabrielmoreiraBased on user input, directly find relevant literature or automatically construct PubMed Boolean search queries to retrieve and filter references suitable for citation. Applicable for quickly finding high-quality evidence on specific topics and completing reference lists.
- ▌ Research Hotspot Analysis · gabrielmoreiraAnalyze research hotspots for a disease or topic and recommend representative literature. Use when users need to identify trending directions, topic clusters, or generate hotspot review reports. Input is a disease name or research topic; output is a structured hotspot analysis report and representative literature list.
- ▌ Research Paper Downloader · gabrielmoreiraDownload academic papers from open-access sources when the user provides a DOI/arXiv ID or requests a keyword-based paper search, and return the saved PDF path.
- ▌ Semantic Scholar Database · gabrielmoreiraAccess the Semantic Scholar Graph API to search papers and retrieve paper/author/citation data when you need literature discovery or citation graph exploration.
- ▌ Bio Ortholog Inference · gabrielmoreira bundlePull pre-computed ortholog calls from public databases (OrthoDB, Ensembl Compara, OMA browser, eggNOG, PANTHER, KEGG Orthology, HomoloGene) via their REST APIs. Use when orthologs are already curated upstream, when the question is "what is the X ortholog of Y" rather than "how to infer orthology de novo", when batch-mapping gene IDs across species, or when comparing the resources for consensus calls. Encodes confidence-level semantics, 1:1 vs 1:many vs many:many, HomoloGene deprecation, and when to defect to de novo computation.
- ▌ Threejs Animation · gabrielmoreiraThree.js animation - keyframe animation, skeletal animation, morph targets, animation mixing. Use when animating objects, playing GLTF animations, creating procedural motion, or blending animations.
- ▌ Agent Supply Chain · gabrielmoreiraGenerate and verify integrity manifests for AI agent plugins and tools -- detect tampering, enforce version pinning, and establish supply chain provenance (the SLSA/Sigstore gap for agent ecosystems).
- ▌ Providing Performance Optimization Advice · gabrielmoreiraProduce a prioritized performance-optimization roadmap across frontend, backend, and infrastructure. Use as an explicit/manual helper after bottlenecks are known or suspected, not as the owner of regression detection, profiling capture, or test execution.
- ▌ AI Behavior Trees Utility AI · gabrielmoreira bundleBuild a production behavior-tree runtime (Blackboard, action/condition leaves, sequence/selector/parallel composites, decorators) and a Utility AI system (response curves — linear, exponential, sigmoid, quadratic — considerations, and action evaluators), plus hybrid BT-drives-Utility agents. Use when implementing a reusable behavior-tree or utility-based decision system, or tuning enemy/NPC decisions beyond a simple FSM, or when the user mentions behavior tree, blackboard, decorator, selector, sequence, tick status, utility AI, response/scoring curve, or consideration. For choosing between FSM/BT/steering or for pathfinding, use game-ai; for Unreal's BehaviorTree/Blackboard assets, use unreal-behavior-trees.
- ▌ Unassisted Evidence Checkpoint · gabrielmoreiraAfter scaffolded practice, run an unassisted check with no AI help. Use to distinguish supported performance from what the learner can currently do independently.
- ▌
- ▌ Report Knowledge Curator · gabrielmoreiraInternal specialist skill for Produce BugFull and BugCard outputs and maintain reusable knowledge.. Use when `rdc-debugger` dispatches report-knowledge-curator work.
- ▌ Rdkit Chemdraw Cdxml · gabrielmoreira bundleRead, write, and edit ChemDraw CDX/CDXML files with RDKit's rdkit.Chem.rdChemDraw plus direct XML editing, always paired with a rendered PNG. Parse molecules and reactions from .cdxml/.cdx, write structures with good 2D depiction, and hand-build or modify the parts RDKit cannot write: reaction arrows, plus signs, schemes/steps, and text/labels. Use for reaction schemes, synthesis routes, mechanisms, retrosynthesis, or SI figures. Critical: RDKit writes structures only — round-tripping a reaction through a Mol silently drops arrows and text; this skill shows the XML layer that preserves them. For pure molecular analysis (descriptors, fingerprints, SMARTS) use rdkit-cheminformatics; for multi-format 3D conversion use openbabel.
- ▌ Cortex Integrate · gabrielmoreiraDesign and implement an AI feature integration — model selection, architecture pattern, system prompt, data flow, error handling, cost estimate. Use when asked to "add AI to this", "LLM integration", "add Claude/GPT", or "AI-powered feature".
- ▌ Lumen Instrument · gabrielmoreiraInstrumentation plan — design event taxonomy, property schema, and tracking plan for analytics tools. Use when asked to "what should we track", "instrumentation plan", "set up analytics events", "analytics event schema", "tracking plan", or "instrument this feature".
- ▌ Surge Activation · gabrielmoreiraUse when asked to improve activation, map the growth funnel, identify growth levers, design a referral program, build a retention playbook, develop a PLG strategy, or find where to invest in growth. Examples: "how do we grow faster", "improve our activation rate", "design a referral program", "build a retention playbook", "what are our best growth levers", "map our growth funnel".
- ▌ Surge Experiment · gabrielmoreiraGrowth experiment design — structure a growth hypothesis, define metric, baseline, expected lift, and kill condition for a single experiment. Use when asked to "design a growth experiment", "test this growth idea", "experiment framework", "how do we test if this works", or "growth hypothesis".
- ▌ Vigil Instrument · gabrielmoreiraInstrument a service with OpenTelemetry — RED metrics, structured logs, distributed tracing, and health checks. Outputs actual code and config, not a plan. Use when asked to "add monitoring", "instrument this", "add logging", "set up tracing", or "observability".
- ▌ Pr To Spec · gabrielmoreiraAnalyze code changes and detect intent drift using the pr-to-spec CLI — converts a branch, staged edits, or recent commits into a structured, agent-consumable spec. Use when declaring intent before a change, checking a finished change for drift against that intent, or generating a spec for agent review. Trigger with "/pr-to-spec", "pr-to-spec scan", "pr-to-spec check", or "pr-to-spec intent".
- ▌ Sync Pull · gabrielmoreiraUse when the user wants to restore, download, or pull their Claude Code config from GitHub onto this machine.
- ▌ Sync Push · gabrielmoreiraUse when the user wants to back up, save, or push their current Claude Code config to GitHub.
- ▌ Confirming Pentest Authorization · gabrielmoreira bundleVerify that a penetration test has explicit, written, signed authorization before any scanning begins. Reads a Rules-of- Engagement (ROE) attestation file, validates required fields (authorizer, in-scope targets, time window, emergency contact, signature), checks the signer against an allowlist, and emits a CRITICAL finding if anything is missing. Designed as the first skill the orchestrator routes to. Use when: starting a new engagement, after a scope change, or before any cluster 1-4 scan skill runs. Threshold: any missing or unsigned ROE field; any time-window expiry; any in-scope target outside the authorized list. Trigger with: "confirm authorization", "verify ROE", "check pentest authz", "pre-flight authorization".
- ▌ Detecting SQL Injection Patterns · gabrielmoreira bundleScan a source tree for SQL-injection vulnerable patterns: string concatenation into queries, f-string interpolation in SQL, string-format substitution into raw queries, deprecated cursor methods (cursor.execute with % formatting), Knex / Sequelize raw() with template interpolation, sequelize.query with replacements. Use when: pre-commit code review, post-feature SQL-touching release, inheriting a legacy codebase that predates ORMs, or post-bug-report investigation. Threshold: any source line where SQL keywords (SELECT / INSERT / UPDATE / DELETE / FROM / WHERE) appear in a string that's being built via concatenation, f-string, %-format, or .format() with variable input. Trigger with: "scan for sqli", "sql injection patterns", "check raw queries", "audit cursor.execute".
- ▌ Documenso Reference Architecture · gabrielmoreira bundleImplement Documenso reference architecture with best-practice project layout. Use when designing new Documenso integrations, reviewing project structure, or establishing architecture standards for document signing applications. Trigger with phrases like "documenso architecture", "documenso best practices", "documenso project structure", "how to organize documenso".
- ▌ Firecrawl Reference Architecture · gabrielmoreiraImplement Firecrawl reference architecture with scrape/crawl/map/extract pipelines. Use when designing new Firecrawl integrations, reviewing project structure, or building content ingestion pipelines for AI/RAG applications. Trigger with phrases like "firecrawl architecture", "firecrawl project structure", "firecrawl pipeline", "firecrawl RAG", "firecrawl knowledge base".
- ▌ Fireflies Reference Architecture · gabrielmoreiraDesign meeting intelligence architecture with Fireflies.ai GraphQL API, webhooks, and CRM sync. Use when designing new integrations, planning transcript pipelines, or establishing architecture for meeting analytics platforms. Trigger with phrases like "fireflies architecture", "fireflies design", "fireflies project structure", "meeting intelligence pipeline".
- ▌ Hootsuite Reference Architecture · gabrielmoreiraImplement Hootsuite reference architecture with best-practice project layout. Use when designing new Hootsuite integrations, reviewing project structure, or establishing architecture standards for Hootsuite applications. Trigger with phrases like "hootsuite architecture", "hootsuite best practices", "hootsuite project structure", "how to organize hootsuite", "hootsuite layout".
- ▌ Hubspot Deal Pipeline Automation · gabrielmoreira bundleAutomate and audit HubSpot deal pipeline operations without destroying real pipeline — covering stage automation loops, stale-deal safe-close logic, forecast reconciliation, custom property drift detection, quota dashboard cache-busting, and multi-pipeline duplicate detection. Use when writing or debugging workflow automations that move deals between stages, auditing pipelines for stale or duplicated opportunities, reconciling forecast numbers that disagree across reports, or hardening RevOps dashboards against property deletions and reporting-cache lag. Trigger with "hubspot deal pipeline", "hubspot stage automation", "hubspot stale deals", "hubspot forecast reconciliation", "hubspot quota dashboard", "hubspot duplicate deals", "revops pipeline audit".
- ▌ Instantly Reference Architecture · gabrielmoreiraImplement Instantly.ai reference architecture with best-practice project layout. Use when designing new Instantly integrations, planning multi-campaign systems, or building an outreach automation platform. Trigger with phrases like "instantly architecture", "instantly project structure", "instantly reference design", "instantly system design", "instantly integration layout".
- ▌ Langchain Reference Architecture · gabrielmoreira bundleA reference layered architecture for production LangChain 1.0 / LangGraph 1.0 services — LLM factory with version-safe defaults, chain/graph registry, retriever and tool DI, Pydantic-validated config, per-request tenant scoping, middleware ordering, checkpointer selection per environment. Use when starting a new service, refactoring a tangled chain, or onboarding a team to existing code. Trigger with "langchain architecture", "langchain llm factory", "langchain chain registry", "langchain dependency injection", "langchain project structure".
- ▌ Maintainx Reference Architecture · gabrielmoreira bundleProduction-grade architecture patterns for MaintainX integrations. Use when designing system architecture, planning integrations, or building enterprise-scale MaintainX solutions. Trigger with phrases like "maintainx architecture", "maintainx design", "maintainx system design", "maintainx enterprise", "maintainx patterns".
- ▌ Monitoring Database Transactions · gabrielmoreira bundleMonitor use when you need to work with monitoring and observability. This skill provides health monitoring and alerting with comprehensive guidance and automation. Trigger with phrases like "monitor system health", "set up alerts", or "track metrics".
- ▌ Podium Review Request Automation · gabrielmoreira bundleTrigger Podium review requests from Shopify order-shipped events and survive the delivery-side failures — cooldown-window violations, ship-event races with refunds, failed-send silent rejections, dropped review-response webhooks, multi-platform routing misconfig, and opt-out compliance gaps. Use when wiring Shopify orders-fulfilled to Podium review campaigns, building a cooldown gate, ingesting review-response webhooks, or auditing opt-out compliance across flows. Trigger with "podium review request", "shopify review automation", "podium cooldown", "review response webhook", "podium opt-out audit", "review platform routing".
- ▌ Processing Computer Vision Tasks · gabrielmoreira bundleProcess images using object detection, classification, and segmentation. Use when requesting "analyze image", "object detection", "image classification", or "computer vision". Trigger with relevant phrases based on skill purpose.
- ▌ Quicknode Reference Architecture · gabrielmoreiraQuickNode reference architecture — blockchain RPC and Web3 infrastructure integration. Use when working with QuickNode for blockchain development. Trigger with phrases like "quicknode reference architecture", "quicknode-reference-architecture", "blockchain RPC".
- ▌ Responding To Security Incidents · gabrielmoreira bundleAnalyze and guide security incident response, investigation, and remediation processes. Use when you need to handle security breaches, classify incidents, develop response playbooks, gather forensic evidence, or coordinate remediation efforts. Trigger with phrases like "security incident response", "ransomware attack response", "data breach investigation", "incident playbook", or "security forensics".
- ▌ Scanning For Data Privacy Issues · gabrielmoreira bundleScan for data privacy issues and sensitive information exposure. Use when reviewing data handling practices. Trigger with 'scan privacy issues', 'check sensitive data', or 'validate data protection'.
- ▌ Scanning For Xss Vulnerabilities · gabrielmoreira bundleExecute this skill enables AI assistant to automatically scan for xss (cross-site scripting) vulnerabilities in code. it is triggered when the user requests to "scan for xss vulnerabilities", "check for xss", or uses the command "/xss". the skill identifies ref... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
- ▌ Shopify Advanced Troubleshooting · gabrielmoreira bundleDebug complex Shopify API issues using cost analysis, request tracing, webhook delivery inspection, and GraphQL introspection. Use when encountering intermittent failures, throttling mysteries, or webhook delivery gaps. Trigger with phrases like "shopify hard bug", "shopify mystery error", "shopify deep debug", "difficult shopify issue", "shopify intermittent failure".
- ▌ Training Machine Learning Models · gabrielmoreira bundleBuild train machine learning models with automated workflows. Analyzes datasets, selects model types (classification, regression), configures parameters, trains with cross-validation, and saves model artifacts. Use when asked to "train model" or "evalua... Trigger with relevant phrases based on skill purpose.
- ▌ Commit Message Formatter · gabrielmoreiraManage commit message formatter operations. Auto-activating skill for DevOps Basics. Triggers on: commit message formatter, commit message formatter Part of the DevOps Basics skill category. Use when working with commit message formatter functionality. Trigger with phrases like "commit message formatter", "commit formatter", "commit".
- ▌ Key Rotation Manager · gabrielmoreiraManage key rotation manager operations. Auto-activating skill for Security Advanced. Triggers on: key rotation manager, key rotation manager Part of the Security Advanced skill category. Use when working with key rotation manager functionality. Trigger with phrases like "key rotation manager", "key manager", "key".
- ▌ Threat Model Creator · gabrielmoreiraCreate threat model creator operations. Auto-activating skill for Security Advanced. Triggers on: threat model creator, threat model creator Part of the Security Advanced skill category. Use when working with threat model creator functionality. Trigger with phrases like "threat model creator", "threat creator", "threat".