gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Data Catalog Updater · gabrielmoreiraProcess data catalog updater operations. Auto-activating skill for Data Pipelines. Triggers on: data catalog updater, data catalog updater Part of the Data Pipelines skill category. Use when working with data catalog updater functionality. Trigger with phrases like "data catalog updater", "data updater", "data".
- ▌ Data Lineage Tracker · gabrielmoreiraTrack data lineage tracker operations. Auto-activating skill for Data Pipelines. Triggers on: data lineage tracker, data lineage tracker Part of the Data Pipelines skill category. Use when working with data lineage tracker functionality. Trigger with phrases like "data lineage tracker", "data tracker", "data".
- ▌ Data Quality Checker · gabrielmoreiraValidate data quality checker operations. Auto-activating skill for Data Pipelines. Triggers on: data quality checker, data quality checker Part of the Data Pipelines skill category. Use when working with data quality checker functionality. Trigger with phrases like "data quality checker", "data checker", "data".
- ▌ Luigi Task Generator · gabrielmoreiraGenerate luigi task generator operations. Auto-activating skill for Data Pipelines. Triggers on: luigi task generator, luigi task generator Part of the Data Pipelines skill category. Use when working with luigi task generator functionality. Trigger with phrases like "luigi task generator", "luigi generator", "luigi".
- ▌ Prefect Flow Builder · gabrielmoreiraBuild prefect flow builder operations. Auto-activating skill for Data Pipelines. Triggers on: prefect flow builder, prefect flow builder Part of the Data Pipelines skill category. Use when working with prefect flow builder functionality. Trigger with phrases like "prefect flow builder", "prefect builder", "prefect".
- ▌ SQL Transform Helper · gabrielmoreiraAssist with sql transform helper operations. Auto-activating skill for Data Pipelines. Triggers on: sql transform helper, sql transform helper Part of the Data Pipelines skill category. Use when working with sql transform helper functionality. Trigger with phrases like "sql transform helper", "sql helper", "sql".
- ▌ Correlation Analyzer · gabrielmoreiraAnalyze correlation analyzer operations. Auto-activating skill for Data Analytics. Triggers on: correlation analyzer, correlation analyzer Part of the Data Analytics skill category. Use when analyzing or auditing correlation analyzer. Trigger with phrases like "correlation analyzer", "correlation analyzer", "analyze correlation r".
- ▌ Retention Calculator · gabrielmoreiraConfigure and manage - Calculate retention calculator operations. Auto-activating skill for Data Analytics. Triggers on: retention calculator, retention calculator Part of the Data Analytics skill category. Use when working with retention calculator functionality. Trigger with phrases like "retention calculator", "retention calculator", "retention".
- ▌ Cloudwatch Alarm Creator · gabrielmoreiraCreate cloudwatch alarm creator operations. Auto-activating skill for AWS Skills. Triggers on: cloudwatch alarm creator, cloudwatch alarm creator Part of the AWS Skills skill category. Use when working with cloudwatch alarm creator functionality. Trigger with phrases like "cloudwatch alarm creator", "cloudwatch creator", "cloudwatch".
- ▌ Eventbridge Rule Creator · gabrielmoreiraCreate eventbridge rule creator operations. Auto-activating skill for AWS Skills. Triggers on: eventbridge rule creator, eventbridge rule creator Part of the AWS Skills skill category. Use when working with eventbridge rule creator functionality. Trigger with phrases like "eventbridge rule creator", "eventbridge creator", "eventbridge".
- ▌ Security Group Generator · gabrielmoreiraGenerate security group generator operations. Auto-activating skill for AWS Skills. Triggers on: security group generator, security group generator Part of the AWS Skills skill category. Use when working with security group generator functionality. Trigger with phrases like "security group generator", "security generator", "security".
- ▌ Bigquery Scheduled Query · gabrielmoreiraManage bigquery scheduled query operations. Auto-activating skill for GCP Skills. Triggers on: bigquery scheduled query, bigquery scheduled query Part of the GCP Skills skill category. Use when working with bigquery scheduled query functionality. Trigger with phrases like "bigquery scheduled query", "bigquery query", "bigquery".
- ▌ Cloud Function Generator · gabrielmoreiraGenerate cloud function generator operations. Auto-activating skill for GCP Skills. Triggers on: cloud function generator, cloud function generator Part of the GCP Skills skill category. Use when working with cloud function generator functionality. Trigger with phrases like "cloud function generator", "cloud generator", "cloud".
- ▌ Cloud Logging Sink Setup · gabrielmoreiraConfigure cloud logging sink setup operations. Auto-activating skill for GCP Skills. Triggers on: cloud logging sink setup, cloud logging sink setup Part of the GCP Skills skill category. Use when working with cloud logging sink setup functionality. Trigger with phrases like "cloud logging sink setup", "cloud setup", "cloud".
- ▌ Cloud Run Service Config · gabrielmoreiraConfigure cloud run service config operations. Auto-activating skill for GCP Skills. Triggers on: cloud run service config, cloud run service config Part of the GCP Skills skill category. Use when configuring systems or services. Trigger with phrases like "cloud run service config", "cloud config", "cloud".
- ▌ Cloud SQL Instance Setup · gabrielmoreiraConfigure cloud sql instance setup operations. Auto-activating skill for GCP Skills. Triggers on: cloud sql instance setup, cloud sql instance setup Part of the GCP Skills skill category. Use when working with cloud sql instance setup functionality. Trigger with phrases like "cloud sql instance setup", "cloud setup", "cloud".
- ▌ Firebase Rules Generator · gabrielmoreiraGenerate firebase rules generator operations. Auto-activating skill for GCP Skills. Triggers on: firebase rules generator, firebase rules generator Part of the GCP Skills skill category. Use when working with firebase rules generator functionality. Trigger with phrases like "firebase rules generator", "firebase generator", "firebase".
- ▌ Swagger Doc Creator · gabrielmoreiraCreate swagger doc creator operations. Auto-activating skill for API Development. Triggers on: swagger doc creator, swagger doc creator Part of the API Development skill category. Use when working with swagger doc creator functionality. Trigger with phrases like "swagger doc creator", "swagger creator", "swagger".
- ▌ API Response Cacher · gabrielmoreiraConfigure api response cacher operations. Auto-activating skill for API Integration. Triggers on: api response cacher, api response cacher Part of the API Integration skill category. Use when working with APIs or building integrations. Trigger with phrases like "api response cacher", "api cacher", "api".
- ▌ Sdk Wrapper Creator · gabrielmoreiraCreate sdk wrapper creator operations. Auto-activating skill for API Integration. Triggers on: sdk wrapper creator, sdk wrapper creator Part of the API Integration skill category. Use when working with sdk wrapper creator functionality. Trigger with phrases like "sdk wrapper creator", "sdk creator", "sdk".
- ▌ Document Merger · gabrielmoreiraManage document merger operations. Auto-activating skill for Business Automation. Triggers on: document merger, document merger Part of the Business Automation skill category. Use when working with document merger functionality. Trigger with phrases like "document merger", "document merger", "document".
- ▌ Audit Freight Charge · gabrielmoreira bundleAudit freight charges from invoice, rate agreement, quote, BOL, shipment facts, accessorials, and billing evidence.
- ▌ Manage Freight Claim · gabrielmoreira bundlePrepare freight claim support from damage or loss evidence, shipment documents, value, timeline, and carrier-process constraints.
- ▌ Rdkit Repr · gabrielmoreiraA standardized CLI wrapper for RDKit molecular featurization workflows that handles physicochemical descriptor computation (outputs .csv) and molecular fingerprint extraction (outputs .npy or .csv), with built-in SMILES validation. USE WHEN you need to compute RDKit molecular descriptors or fingerprints from SMILES datasets (.csv/.smi), or when you want to list all available descriptor names and presets.
- ▌ Dotnet Testing Autofixture Customization · gabrielmoreira bundleAutoFixture 進階自訂化技術完整指南。當需要自訂 AutoFixture 建構器或處理特殊型別的測試資料產生規則時使用。涵蓋 DataAnnotations 自動整合、ISpecimenBuilder 實作、優先順序管理。包含 DateTime/數值範圍建構器、泛型化設計與流暢式擴充方法。 Make sure to use this skill whenever the user mentions AutoFixture customization, ISpecimenBuilder, DataAnnotations with AutoFixture, or custom builders for test data generation, even if they don't explicitly ask for customization guidance. Keywords: autofixture customization, autofixture customize, autofixture 自訂, specimen builder, ISpecimenBuilder, RandomDateTimeSequenceGenerator, NumericRangeBuilder, DataAnnotations autofixture, fixture.Customizations, Insert(0), 自訂建構器, NoSpecimen, 泛型化建構器
- ▌ Dotnet Testing Complex Object Comparison · gabrielmoreira bundle處理複雜物件比對與深層驗證的專門技能。當需要比對深層物件、排除特定屬性、處理循環參照、驗證 DTO/Entity 時使用。涵蓋 BeEquivalentTo、Excluding、Including、自訂比對規則等。 Make sure to use this skill whenever the user mentions deep object comparison, BeEquivalentTo, DTO comparison, Excluding properties, or complex object validation in tests, even if they don't explicitly ask for comparison guidance. Keywords: object comparison, 物件比對, deep comparison, 深層比對, BeEquivalentTo, DTO 比對, Entity 驗證, 排除屬性, 循環參照, Excluding, Including, ExcludingNestedObjects, RespectingRuntimeTypes, WithStrictOrdering, 忽略時間戳記, exclude timestamp
- ▌ Dotnet Testing Test Data Builder Pattern · gabrielmoreira bundleTest Data Builder Pattern 完整實作指南。當需要使用建構者模式建立可維護的測試資料或簡化複雜物件的測試準備時使用。涵蓋流暢介面、語意化方法、預設值設計與 Builder 組合模式。 Make sure to use this skill whenever the user mentions test data builder, builder pattern, fluent interface, Object Mother, or test data preparation for complex objects, even if they don't explicitly ask for the builder pattern. Keywords: test data builder, builder pattern test, 測試資料建構器, object mother, fluent interface, 流暢介面, UserBuilder, ProductBuilder, .With(), .Build(), AUser(), 測試資料準備, 複雜物件建立, 語意化測試
- ▌ Client Instruction Schedule · gabrielmoreira bundleBuild a client instruction schedule — a plain-English, Scott Schedule-style Word table that gathers a struggling client's evidence and instructions issue by issue, with a one-page covering note. Use whenever the user asks for a "client instruction schedule", "instruction schedule", "client questionnaire", "schedule of questions for the client", "get instructions from the client on the papers", or says the client is overwhelmed and needs the case broken into manageable questions. Also trigger when asked to turn case papers into a structured request for client input. Do NOT use for court-facing Scott Schedules, pleadings, witness statements, or advice letters — this skill produces a client-facing working document only. Output is always a .docx draft for solicitor review, never a final document.
- ▌ Climate Aligned Contracts Felix Cohen · gabrielmoreira bundleDraft, adapt, and review contracts and clauses aligned with The Chancery Lane Project's methodology for reducing carbon emissions through legal agreements. Use when Claude needs to: (1) Draft new climate-aligned clauses (e.g., net zero commitments, carbon accounting, supply chain decarbonization), (2) Adapt or modify existing contracts to incorporate climate objectives, (3) Review and analyze clauses for alignment with climate goals and decarbonization strategies, (4) Provide guidance on The Chancery Lane Project's house style and drafting methodology for climate-conscious legal work.
- ▌ Disclosure Strategy Mapper Larissa Meredith Flister · gabrielmoreira bundleThis skill maps disclosure strategy from a case summary, pleading, chronology, or early case theory: the document categories that will matter, likely custodians, adverse material, evidential gaps, search themes, and the risks worth confronting early.
- ▌ Settlement Pressure Tester Larissa Meredith Flister · gabrielmoreira bundleThis skill stress-tests a proposed settlement position before an offer goes out or comes back: the assumptions it depends on, your leverage and the opponent’s, the evidential weaknesses, the likely opponent response, and the timing and costs pressures around it. It structures settlement judgment for a better-informed decision; it does not advise whether to settle.
- ▌ Source Locked Verification · gabrielmoreira bundleNo Inference / Source-Locked Verification. Forces Claude to answer ONLY from user-provided materials and/or online sources actually accessed — no inference, no assumptions, no gap-filling. Every factual, legal, numerical, or procedural claim must be anchored to a cited source. Use whenever Claude reviews documents, summarises evidence, checks accuracy, drafts submissions, creates timelines, extracts facts, checks citations, analyses rules, prepares legal arguments, compares documents, verifies claims, produces chronologies, works from uploaded materials, performs legal research, checks case status, or does anything where evidential fidelity matters. Also trigger on: 'source-locked', 'no inference', 'only from the materials', 'don't assume', 'stick to the evidence', 'verify this', 'check this is right', 'work from the documents'. Overrides Claude's default tendency to fill gaps. If evidential accuracy matters, use this skill.
- ▌ Matlab Create Hands On Exercises · gabrielmoreiraUse when prompting a learner to complete hands-on MATLAB coding exercises, guided practice, debugging drills, code tracing, small MATLAB projects, or MATLAB-script assessment during tutoring. Use when the tutor should create a complete runnable MATLAB script, execute it through MATLAB tools, compare the produced outputs with expected outputs, and evaluate MATLAB programming style.
- ▌ 25 Voice Clone Podcast Global · gabrielmoreiraUse when a PERSONAL brand needs AUDIO — voice cloning with ElevenLabs, Murf, or PlayHT, podcast production, audiobooks, and voiceover: short voiceover for TikTok and Reels, a 30 to 60 minute podcast format, and a 1-to-10 repurpose turning one episode into ten clips, in English with US, UK, AU, and SG accents. Trigger on 'voice clone', 'ElevenLabs', 'start a podcast', 'audiobook narration', 'AI voiceover for my videos', 'I hate re-recording the same intro'. Not for — video with a talking-head avatar, see `24-ai-avatar-production-global`; the script being read aloud, see `04-script-video-global`; written long-form posts, see `26-thought-leadership-content-global`.
- ▌ 26 Thought Leadership Content · gabrielmoreiraDung khi mot CA NHAN can viet BAI DAI de xay uy tin, khong phai copy ban hang — 3 cau truc chuan cho thi truong VN gom PAS-Insight cho founder, Story-Lesson-CTA cho coach, Hook-List-Reveal cho creator; 6 cong thuc hook long-form; ky thuat nhip cau; do dai theo nen tang LinkedIn, Facebook, newsletter; ma tran tai su dung 1:5. Kich hoat khi user nhac 'viet bai LinkedIn', 'thought leadership', 'long form post', 'newsletter ca nhan', 'viet bai chuyen sau', 'khong biet viet gi tren trang ca nhan', 'muon duoc coi la chuyen gia'. Khong dung cho — copy quang cao tra tien thi dung skill 05-copy-quang-cao; caption ngan cho fanpage doanh nghiep thi dung skill 37-caption-social; kich ban video ngan thi dung skill 04-script-video.
- ▌ Analyzing Outlook Pst For Email Forensics · gabrielmoreira bundleParse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that requires reconstructing communication patterns or tracing message routing from Outlook archives.
- ▌ Analyzing Persistence Mechanisms In Linux · gabrielmoreira bundleScan Linux systems for persistence mechanisms including crontab/systemd entries, LD_PRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorized_keys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or confirm how an adversary maintained access to a compromised Linux host.
- ▌ Analyzing Windows Lnk Files For Artifacts · gabrielmoreira bundleParse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction. Use when investigating recently-accessed files, tracking removable media or network paths referenced by shortcuts, or building a DFIR timeline from LNK artifacts.
- ▌ Assessing Vector And Embedding Weaknesses · gabrielmoreira bundleTest RAG vector stores (Pinecone, Qdrant, Weaviate, Chroma, pgvector, FAISS) for embedding inversion, cross-tenant data leakage, and data poisoning per OWASP LLM08:2025. Use when performing an authorized security assessment of a RAG pipeline's retrieval layer or auditing multi-tenant vector-store isolation.
- ▌ Attacking OAUTH With Device Code Phishing · gabrielmoreira bundleRun OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID, using TokenTactics-style tooling to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services. Use for authorized red-team engagements simulating device-code or consent-grant phishing against a tenant you have explicit written permission to test.
- ▌ Building Threat Hunt Hypothesis Framework · gabrielmoreira bundleBuild a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender, Splunk, Elastic, Sysmon, Velociraptor, Sigma) and documents findings in a standardized hunt report. Use when planning or running a proactive threat hunt or scoping compromise from an intel- or anomaly-driven lead.
- ▌ Conducting Domain Persistence With Dcsync · gabrielmoreira bundlePerform DCSync attacks by abusing MS-DRSR replication rights (DS-Replication-Get-Changes/-All) to impersonate a Domain Controller and extract KRBTGT, Domain Admin, and service account hashes for Golden Ticket forging, typically with Mimikatz. Use in authorized engagements after finding principals with replication rights, to establish long-term domain persistence, or to validate detections for replication abuse.
- ▌ Conducting Full Scope Red Team Engagement · gabrielmoreira bundlePlan and execute a comprehensive, MITRE ATT&CK-aligned red team engagement spanning threat modeling, reconnaissance, initial access, and post-exploitation to evaluate an organization's detection, prevention, and response against APT-style behavior. Use when scoping or running a full-scope, objective-based engagement, or purple-teaming against a specific threat actor's TTPs.
- ▌ Configuring Active Directory Tiered Model · gabrielmoreira bundleImplement Microsoft's Enhanced Security Admin Environment (ESAE) tiered administration model for Active Directory, covering Tier 0/1/2 separation, privileged access workstations (PAWs), administrative forest design, and authentication policy silos. Use when designing or hardening AD privileged-access architecture, segmenting Domain/Enterprise Admin accounts into tiers, or containing lateral movement and credential theft (pass-the-hash, Kerberoasting, golden tickets).
- ▌ Continuous LLM Red Teaming With Promptfoo · gabrielmoreira bundleWires Promptfoo and DeepTeam into CI/CD for automated, repeatable red-teaming of LLM apps against OWASP LLM Top 10, OWASP Agentic, and MITRE ATLAS presets, failing the build when jailbreak or injection vulnerabilities regress. Use for continuous adversarial testing in CI/CD, a merge-blocking security gate, or comparing model/prompt versions for compliance reporting.
- ▌ Detecting Exfiltration Over Dns With Zeek · gabrielmoreira bundleDetect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains, oversized TXT/NULL records, and anomalous query volume or patterns. Use when investigating suspected DNS tunneling, covert C2 over DNS, or data exfiltration hidden in DNS queries against network traffic captured by Zeek.
- ▌ Detecting Living Off The Land With Lolbas · gabrielmoreira bundleDetect Living Off the Land Binaries (LOLBins/LOLBAS) abuse including certutil, regsvr32, mshta, and rundll32 via process telemetry, Sigma rules, and parent-child process analysis with Sysmon endpoint data. Use when hunting for adversaries abusing built-in Windows binaries to download, execute, or proxy malicious code while evading traditional executable-based detection.
- ▌ Detecting Suspicious Powershell Execution · gabrielmoreira bundleHunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft Defender for Endpoint), Sysmon, and SIEM queries (Splunk, Elastic). Use when proactively threat hunting, triaging EDR/SIEM alerts, or scoping an incident involving malicious PowerShell activity.
- ▌ Eradicating Malware From Infected Systems · gabrielmoreira bundleSystematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux systems using Autoruns, EDR/AV, and YARA, restoring a clean state while preventing re-infection. Use after containment and forensic analysis have identified all compromised systems and persistence mechanisms and you are ready to eradicate and recover.
- ▌ Exploiting Excessive Data Exposure In API · gabrielmoreira bundleTests APIs for excessive data exposure (OWASP API3:2023) by intercepting raw API responses and comparing them against what the UI actually renders, looking for leaked PII, internal identifiers, debug data, or business-sensitive fields the frontend filters but the API still transmits. Use when auditing REST or mobile-app APIs for over-fetching, response filtering bypass, or unintended data leakage in endpoint responses.
- ▌ Exploiting JWT Algorithm Confusion Attack · gabrielmoreira bundleExploits JWT algorithm confusion where the server's verification library trusts the alg named in the token header, by switching RS256 to HS256 (signing with the RSA public key as HMAC secret), setting alg to none, or injecting kid/jku/x5u headers to supply an attacker-controlled key. Use when testing RS256 JWT auth for algorithm downgrade, alg:none bypass, or key-confusion signature forgery.
- ▌ Exploiting Race Condition Vulnerabilities · gabrielmoreira bundleDetects and exploits race condition (TOCTOU) vulnerabilities in web applications using Burp Suite's Turbo Intruder extension and its single-packet attack technique to fire parallel requests that bypass rate limits, duplicate transactions, or overrun usage limits. Use when pentesting endpoints with balances, coupon redemption, or rate limiting that concurrent requests might manipulate.
- ▌ Hunting For Unusual Service Installations · gabrielmoreira bundleDetects suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event log Event ID 7045, analyzing service binary paths, and flagging indicators of persistence mechanisms via Sysmon/EDR telemetry. Use when hunting for new-service persistence after a suspected compromise, when Event ID 7045 fires for an unfamiliar service, or during incident response to enumerate service-based persistence on Windows hosts.
- ▌ Implementing Anti Ransomware Group Policy · gabrielmoreira bundleConfigures Windows Group Policy Objects to block ransomware execution and lateral spread, covering AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction rules, and network protection settings. Use when hardening Windows endpoints against ransomware via GPO, configuring AppLocker or Controlled Folder Access, or building endpoint protection policies through Group Policy.
- ▌ Implementing Immutable Backup With Restic · gabrielmoreira bundleImplements ransomware-resistant backups using restic with S3-compatible Object Lock (AWS S3, MinIO, Backblaze B2), automating backup creation, integrity checks via restic check --read-data, retention enforcement, and restore testing. Use when building immutable backup infrastructure, adding a WORM copy to a 3-2-1-1-0 strategy, or automating scheduled backup-verification workflows.
- ▌ Implementing JWT Signing And Verification · gabrielmoreira bundleImplements secure JWT (RFC 7519) signing and verification using HMAC-SHA256, RSA-PSS, ES256, and EdDSA, including token expiration, claims validation, and defenses against algorithm-confusion, none-algorithm, and key-injection attacks. Use when adding or hardening JWT-based authentication/authorization, or when auditing token verification code for common JWT vulnerabilities.
- ▌ Implementing Nerc Cip Compliance Controls · gabrielmoreira bundleImplements NERC CIP controls for Bulk Electric System (BES) cyber systems: asset categorization (CIP-002), electronic security perimeters (CIP-005), system security management (CIP-007), configuration management (CIP-010), and supply chain risk (CIP-013), including 2025 MFA updates. Use when a registered entity must achieve or maintain NERC CIP compliance, prepare for a Regional Entity audit, or categorize newly commissioned BES cyber systems.
- ▌ Investigating Ransomware Attack Artifacts · gabrielmoreira bundleForensically preserve memory and disk, collect ransom notes and encrypted file samples, and identify the ransomware variant using tools such as ID Ransomware, Volatility, and Chainsaw/Hayabusa to determine the initial access vector and recovery options. Use immediately after discovering ransomware encryption, when scoping the incident forensically, or when documenting evidence for law enforcement and insurance claims.
- ▌ Performing Alert Triage With Elastic Siem · gabrielmoreira bundlePerform systematic alert triage in Elastic Security SIEM—classifying, prioritizing, and investigating alerts using Kibana, ES|QL queries, and ECS-normalized data—to drive SOC analyst workflows. Use when triaging incoming Elastic Security detections, prioritizing an analyst's alert queue, or investigating alerts during SOC operations.
- ▌ Performing Arp Spoofing Attack Simulation · gabrielmoreira bundleSimulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP Inspection, port security, and network monitoring detections. Use when testing whether switches, IDS/IPS, or a SIEM detect ARP spoofing under written authorization; do not use on production networks without explicit approval.
- ▌ Performing Content Security Policy Bypass · gabrielmoreira bundleAnalyze Content-Security-Policy headers and bypass them to achieve cross-site scripting by exploiting unsafe-inline/unsafe-eval, whitelisted JSONP endpoints, base-uri and form-action gaps, and nonce/hash weaknesses, then exfiltrate data even without script-src control. Use during web application security assessments or bug bounty hunting when XSS is found but blocked by CSP, or when auditing CSP header configuration for weaknesses.
- ▌ Performing Indicator Lifecycle Management · gabrielmoreira bundleTracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan, passive DNS), deployment to SIEM/IDS watchlists, hit-rate and false-positive monitoring, confidence-score decay, and automated expiration using MISP/OpenCTI and STIX. Use when building or maintaining a threat intelligence indicator lifecycle process, aging out stale IOCs, or reducing analyst fatigue from low-quality indicators.
- ▌ Performing Kubernetes Penetration Testing · gabrielmoreira bundleEvaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape, peirates, and manual kubectl exploitation to find paths to cluster compromise. Use for an authorized penetration test or hands-on validation that controls actually stop an attacker. Keywords: kube-hunter, Kubescape, peirates, kubelet 10250, anonymous auth, token theft, lateral movement, cluster takeover. Do not use for a configuration-only compliance audit - use performing-kubernetes-cis-benchmark-with-kube-bench.
- ▌ Performing Red Team Phishing With Gophish · gabrielmoreira bundleAutomates GoPhish phishing simulation campaigns using the Python gophish library, creating email templates with tracking pixels, configuring SMTP sending profiles, building target groups from CSV, launching campaigns, and analyzing results such as open rates, click rates, and credential submission statistics. Use when running an authorized phishing simulation or security awareness assessment via GoPhish.
- ▌ Performing Supply Chain Attack Simulation · gabrielmoreira bundleSimulates and detects software supply chain attacks: typosquatting detection via Levenshtein distance against popular PyPI package names, dependency confusion testing against private registries, SHA-256 package hash verification, and known-CVE scanning with pip-audit. Use when auditing a project's dependencies for malicious or confused packages, or when assessing package-registry supply-chain risk.
- ▌ Testing For Open Redirect Vulnerabilities · gabrielmoreira bundleIdentifies and exploits open redirect vulnerabilities by analyzing URL redirection parameters (next, url, redirect, return, goto), applying bypass techniques, and chaining findings into phishing or token-theft exploits, using Burp Suite/OWASP ZAP and Burp Collaborator. Use when testing login/logout flows, OAuth redirect_uri handling, or SSO redirect validation.
- ▌ Testing Prompt Injection In RAG Pipelines · gabrielmoreira bundleProbes Retrieval-Augmented Generation pipelines for indirect prompt injection via poisoned retrieved documents and embedding-space manipulation, using NVIDIA garak, Promptfoo red-team plugins, and Microsoft PyRIT against vector stores like FAISS, Chroma, Pinecone, or pgvector. Use when security-testing a RAG chatbot or document-Q&A system, validating retrieval guardrails, or gating CI/CD on prompt-template/retriever changes.
- ▌ Narco Check · gabrielmoreiraMemory integrity audit. Detects hallucinations, circular confirmations, and state poisoning. Runs automatically after 2 consecutive failures or at nightly deep dive. Uses Opus 4.6 as the auditor model.
- ▌ Writing Level Analysis · gabrielmoreiraMeasure the readability of user-provided or locally authored text with Flesch-Kincaid grade level and corroborating indices. Use when asked for a writing level, readability score, reading grade, or comparison between documents.
- ▌ Syncfusion Maui Toolkit Bottom Sheet · gabrielmoreira bundleImplement the Syncfusion .NET MAUI Bottom Sheet (SfBottomSheet) control with state management, content configuration, gesture support, and customization. Covers setup, content binding, state transitions, styling, events, and interactive patterns for sliding content panels.
- ▌ Syncfusion Maui Toolkit Effects View · gabrielmoreira bundleImplements Syncfusion .NET MAUI Effects View (SfEffectsView) for modern touch interactions and visual feedback. Use when implementing ripple effects, touch feedback animations, selection indicators, scaling animations, or highlight overlays for buttons, cards, lists, or images. Covers touch effects, ripple animations, selection states, and interactive visual feedback.
- ▌ Syncfusion Maui Toolkit Numericentry · gabrielmoreira bundleImplement numeric input with Syncfusion .NET MAUI NumericEntry (SfNumericEntry). Supports currency, percentage, and decimal formatting with validation, min/max restrictions, placeholder text, custom styling, and culture-specific formats. Includes value change modes, events, and accessibility features for professional numeric data entry.
- ▌ Syncfusion Maui Toolkit Polar Charts · gabrielmoreira bundleImplements Syncfusion .NET MAUI Polar Charts (SfPolarChart) for visualizing data in polar coordinates. Use when working with polar charts, radar charts, spider charts, web charts, or circular data visualization. Ideal for displaying data in terms of values and angles, creating line or area series in polar layouts, or comparing multiple data series radially.
- ▌ Syncfusion Maui Toolkit Spark Charts · gabrielmoreira bundleUse this skill ALWAYS when the user needs to implement Syncfusion MAUI Spark Charts. Triggers on spark chart, sparkline, micro-chart, trend visualization, data visualization in small spaces, chart types (line, area, column, win/loss), markers, range bands, axis configuration, data point styling. Also use immediately for chart customization, performance optimization, marker configuration, data binding patterns, accessibility needs.
- ▌ Managing Ssltls Certificates · gabrielmoreira bundleExecute this skill enables AI assistant to manage and monitor ssl/tls certificates using the ssl-certificate-manager plugin. it is activated when the user requests actions related to ssl certificates, such as checking certificate expiry, renewing certificates, ... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
- ▌ Navan Reference Architecture · gabrielmoreira bundleUse when designing a production Navan API integration architecture — API gateway, token management, data sync pipelines, ERP connectors, and monitoring stack. Trigger with "navan reference architecture" or "navan integration architecture".
- ▌ Notion Architecture Variants · gabrielmoreira bundleUse when you are choosing or scaffolding how an app talks to Notion via the API — deciding between a headless CMS (blog/content site), a task tracker (project management), a knowledge base (wiki), a form-submission handler, or a data-pipeline source, and wiring the database schema plus integration code. Trigger with phrases like "notion cms", "notion headless blog", "notion task tracker", "notion wiki", "notion form handler", "notion data pipeline".
- ▌ Obsidian Migration Deep Dive · gabrielmoreira bundleExecute major Obsidian plugin rewrites and migration strategies. Use when migrating to or from Obsidian, performing major plugin rewrites, or re-platforming existing note systems to Obsidian. Trigger with phrases like "migrate to obsidian", "obsidian migration", "convert notes to obsidian", "obsidian replatform".
- ▌ Openevidence Core Workflow A · gabrielmoreiraExecute OpenEvidence primary workflow: Clinical Query & Decision Support. Trigger: "openevidence clinical query & decision support", "primary openevidence workflow".
- ▌ Openevidence Core Workflow B · gabrielmoreiraExecute OpenEvidence secondary workflow: DeepConsult Research Synthesis. Trigger: "openevidence deepconsult research synthesis", "secondary openevidence workflow".
- ▌ Openrouter Compliance Review · gabrielmoreira bundleReview OpenRouter integration for regulatory compliance (SOC2, GDPR, HIPAA). Use when preparing for audits, evaluating data handling, or documenting compliance posture. Triggers: 'openrouter compliance', 'openrouter gdpr', 'openrouter soc2', 'openrouter data residency'.
- ▌ Openrouter Upgrade Migration · gabrielmoreira bundleMigrate to OpenRouter from direct provider APIs or upgrade between SDK/model versions. Triggers: 'openrouter migrate', 'openrouter upgrade', 'switch to openrouter', 'migrate from openai to openrouter'.
- ▌ Optimizing Cache Performance · gabrielmoreira bundleExecute this skill enables AI assistant to analyze and improve application caching strategies. it optimizes cache hit rates, ttl configurations, cache key design, and invalidation strategies. use this skill when the user requests to "optimize cache performance"... Use when optimizing performance. Trigger with phrases like 'optimize', 'performance', or 'speed up'.
- ▌ Oraclecloud Incident Runbook · gabrielmoreira bundleSelf-service incident runbook for OCI outages — health probes, instance recovery, cross-AD/region failover. Use when OCI instances go down, the status page is silent, or you need automated recovery without waiting for support. Trigger with "oraclecloud incident", "oci outage runbook", "oci failover", "oci instance recovery".
- ▌ Oraclecloud Schema Migration · gabrielmoreira bundleMigrate to OCI Autonomous Database — wallet setup, mTLS, Data Pump, and python-oracledb. Use when provisioning Autonomous DB, downloading wallets, or migrating data with Data Pump. Trigger with "autonomous database", "oci adb", "wallet download", "data pump oci", "mtls oracle".
- ▌ Orchestrating Test Execution · gabrielmoreira bundleTest coordinate parallel test execution across multiple environments and frameworks. Use when performing specialized testing. Trigger with phrases like "orchestrate tests", "run parallel tests", or "coordinate test execution".
- ▌ Palantir Migration Deep Dive · gabrielmoreiraExecute major Palantir Foundry migration strategies including data migration, API version upgrades, and platform transitions. Use when migrating data into Foundry, upgrading between API versions, or re-platforming existing integrations. Trigger with phrases like "migrate to palantir", "foundry migration", "palantir data migration", "foundry replatform".
- ▌ Podium Multi Location Router · gabrielmoreira bundleRoute Podium API calls across multiple physical locations with strict per-location credential isolation, pre-flight location-ID verification, an immutable audit trail of every write, idempotent bulk onboarding, and per-location rate-limit budgets that cannot starve each other. Use when running Podium for more than one physical store (an agency operator managing 50+ accounts, a multi-store SMB with 2+ locations, or a compliance team that needs to prove which location received which write). Trigger with "podium multi-location", "podium location router", "podium per-location", "podium location audit", "podium bulk onboarding", "podium location_uid verification".
- ▌ Quicknode Deploy Integration · gabrielmoreiraQuickNode deploy integration — blockchain RPC and Web3 infrastructure integration. Use when working with QuickNode for blockchain development. Trigger with phrases like "quicknode deploy integration", "quicknode-deploy-integration", "blockchain RPC".
- ▌ Quicknode Performance Tuning · gabrielmoreiraQuickNode performance tuning — blockchain RPC and Web3 infrastructure integration. Use when working with QuickNode for blockchain development. Trigger with phrases like "quicknode performance tuning", "quicknode-performance-tuning", "blockchain RPC".
- ▌ Recording Pentest Engagement · gabrielmoreira bundlePackage an engagement's findings, scan outputs, evidence, and signed ROE into a timestamped archive with a SHA-256 manifest covering every file. Establishes chain of custody so legal counsel, internal audit, or an outside SOC can verify the archive hasn't been modified after closeout. Optionally signs the manifest with GPG for cryptographic attestation. Use when: closing an engagement, snapshotting evidence after each scan day, before handing artifacts to customer, or after an emergency-stop event. Threshold: file in tree without a manifest entry, hash mismatch, out-of-tree path referenced in findings, unsigned manifest when signing was requested. Trigger with: "record engagement", "archive evidence", "create chain of custody", "package pentest artifacts".
- ▌ Retellai Migration Deep Dive · gabrielmoreira bundleRetell AI migration deep dive — AI voice agent and phone call automation. Use when working with Retell AI for voice agents, phone calls, or telephony. Trigger with phrases like "retell migration deep dive", "retellai-migration-deep-dive", "voice agent".
- ▌ Salesforce Policy Guardrails · gabrielmoreiraImplement Salesforce lint rules, SOQL injection prevention, and API usage guardrails. Use when enforcing Salesforce integration code quality, preventing SOQL injection, or configuring CI policy checks for Salesforce best practices. Trigger with phrases like "salesforce policy", "salesforce lint", "salesforce guardrails", "SOQL injection", "salesforce eslint", "salesforce code review".
- ▌ Salesforce Upgrade Migration · gabrielmoreiraAnalyze, plan, and execute Salesforce API version upgrades and jsforce major version migrations. Use when upgrading Salesforce API versions, migrating jsforce v1 to v3, or adapting to deprecated API changes. Trigger with phrases like "upgrade salesforce", "salesforce API version", "jsforce upgrade", "salesforce deprecation", "salesforce version migration".
- ▌ Scanning For Gdpr Compliance · gabrielmoreira bundleScan for GDPR compliance issues in data handling and privacy practices. Use when ensuring EU data protection compliance. Trigger with 'scan GDPR compliance', 'check data privacy', or 'validate GDPR'.
- ▌ Scanning For Vulnerabilities · gabrielmoreira bundleExecute this skill enables comprehensive vulnerability scanning using the vulnerability-scanner plugin. it identifies security vulnerabilities in code, dependencies, and configurations, including cve detection. use this skill when the user asks to scan fo... Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.
- ▌ Sentry Architecture Variants · gabrielmoreira bundleConfigure Sentry error tracking and performance monitoring for different application architectures. Use when setting up Sentry for monoliths, microservices, serverless functions, event-driven systems, frontend SPAs, mobile apps, or hybrid deployments. Trigger: "sentry monolith setup", "sentry microservices tracing", "sentry serverless lambda", "sentry event-driven kafka", "sentry react native", "sentry architecture pattern".
- ▌ Shopify Reliability Patterns · gabrielmoreira bundleImplement reliability patterns for Shopify apps including circuit breakers for API outages, webhook retry handling, and graceful degradation. Use when building fault-tolerant Shopify integrations, handling webhook retry storms, or adding resilience to API calls. Trigger with phrases like "shopify reliability", "shopify circuit breaker", "shopify resilience", "shopify fallback", "shopify retry webhook".
- ▌ Speak Reference Architecture · gabrielmoreira bundleProduction architecture for Speak language learning apps: client, API gateway, assessment engine, and progress store. Use when implementing reference architecture, or managing Speak language learning platform operations. Trigger with phrases like "speak reference architecture", "speak reference architecture".
- ▌ Supabase Migration Deep Dive · gabrielmoreira bundleDatabase migration patterns with the Supabase CLI: npx supabase migration new, zero-downtime migrations, data backfill strategies, schema versioning, rollback strategies, and TypeScript type generation. Use when creating database migrations, performing zero-downtime schema changes, backfilling data in production, managing schema versions, or planning rollback strategies. Trigger with "supabase migration", "supabase schema change", "supabase zero downtime", "supabase rollback", "supabase db push", "supabase migration new".