gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌ Verify Inbound Shipment · gabrielmoreira bundleVerify inbound shipment facts against PO, ASN, BOL, packing list, labels, counts, and received goods.
- ▌ Analyze Inventory Aging · gabrielmoreira bundleAnalyze inventory aging from receipt dates, movement history, on-hand quantities, value, and aging policy.
- ▌ Calculate Reorder Point · gabrielmoreira bundleCalculate inventory reorder points from average demand, lead time, and safety stock with explicit units and assumptions.
- ▌ Plan Physical Inventory · gabrielmoreira bundlePlan physical inventory events with freeze rules, count scope, labor, reconciliation, and restart controls.
- ▌ Map Logistics Flow · gabrielmoreira bundleMap logistics process steps, nodes, roles, documents, system transactions, handoffs, and exceptions.
- ▌ Verify Outbound Shipment · gabrielmoreira bundleVerify outbound shipments against order, pick, pack, label, document, carrier, staging, and handoff evidence.
- ▌ Process Customer Return · gabrielmoreira bundleProcess customer returns from request, order, item, condition, policy, authorization, receipt, disposition, and review boundaries.
- ▌ Select Storage System · gabrielmoreira bundleSelect storage systems by comparing SKU profile, load profile, velocity, access, density, and building constraints.
- ▌ Static · gabrielmoreiraPrepare CP2K single-point (static) task inputs from a user-provided structure and essential DFT settings. Use when the user needs total-energy/electronic SCF evaluation with explicit CP2K basis/potential and SCF controls.
- ▌ Revealjs Presenter · gabrielmoreira bundleGenerate RevealJS HTML presentations with reliable layout, professional typography, and effective visual communication. Use when creating slide decks, pitch presentations, technical talks, or any reveal.js output.
- ▌ Dotnet Testing Advanced Aspire Testing · gabrielmoreira bundle.NET Aspire Testing 整合測試框架完整指南。當需要測試 .NET Aspire 分散式應用程式、設定 AppHost 測試或從 Testcontainers 遷移至 Aspire 測試時使用。涵蓋 DistributedApplicationTestingBuilder、容器生命週期管理、多服務編排、Respawn 配置與時間可測試性設計。 Make sure to use this skill whenever the user mentions .NET Aspire, AppHost testing, DistributedApplicationTestingBuilder, cloud-native testing, or migrating from Testcontainers to Aspire, even if they don't explicitly ask for Aspire testing guidance. Keywords: aspire testing, .NET Aspire, DistributedApplicationTestingBuilder, AppHost testing, 分散式測試, AspireAppFixture, IAsyncLifetime, ContainerLifetime.Session, 雲原生測試, 多服務整合, Aspire.Hosting.Testing, Respawn
- ▌ Dotnet Testing Advanced Tunit Advanced · gabrielmoreira bundleTUnit 進階應用完整指南。當需要使用 TUnit 進行資料驅動測試、依賴注入或整合測試時使用。涵蓋 MethodDataSource、ClassDataSource、Matrix Tests、Properties 過濾。包含 Retry/Timeout 控制、WebApplicationFactory 整合、Testcontainers 多服務編排。 Make sure to use this skill whenever the user mentions TUnit advanced, MethodDataSource, ClassDataSource, Matrix Tests, TUnit dependency injection, TUnit Retry/Timeout, or TUnit WebApplicationFactory, even if they don't explicitly ask for TUnit advanced features. Keywords: TUnit advanced, TUnit 進階, MethodDataSource, ClassDataSource, Matrix Tests, MatrixDataSource, MicrosoftDependencyInjectionDataSource, Property, Retry, Timeout, 資料驅動測試, 測試過濾, WebApplicationFactory TUnit, 多容器編排
- ▌ Dotnet Testing Test Naming Conventions · gabrielmoreira bundle測試命名規範與最佳實踐的專門技能。當需要為測試方法命名、改進測試可讀性、建立命名標準時使用。涵蓋三段式命名法、中文命名建議、測試類別命名等。 Make sure to use this skill whenever the user mentions test naming, how to name tests, test readability, or test method naming conventions, even if they don't explicitly ask for naming guidance. Keywords: test naming, 測試命名, naming conventions, 命名規範, 三段式命名, three-part naming, method_scenario_expected, 方法_情境_預期, 如何命名測試, 測試可讀性, test readability, 命名最佳實踐, 測試報告, test documentation
- ▌ Kotlin Tooling Immutable Collections 0 5 X Migration · gabrielmoreiraMigrate Kotlin (and Java) code from kotlinx.collections.immutable 0.3.x / 0.4.x to the latest 0.5.x. The 0.5.x line renames every copy-returning method on PersistentList / PersistentMap / PersistentSet / PersistentCollection to a participial form per KEEP-0459 (add→adding, removeAt→removingAt, set→replacingAt, put→putting, clear→cleared, …) and deprecates the old names (WARNING, with ReplaceWith). Driven by the compiler: bump the version, recompile, and apply the rename each deprecation warning names. Use when the user mentions kotlinx.collections.immutable 0.5.x, PersistentList migration, "Use adding() instead", KEEP-0459, or sees deprecation warnings from kotlinx.collections.immutable.
- ▌ Eu AI Act Classification Oliver Schmidt Prietz · gabrielmoreira bundleDetermines whether a technology qualifies as an AI system under Art. 3(1) of the EU AI Act and classifies its risk tier (prohibited, high-risk, GPAI with systemic risk, limited risk, minimal risk). This skill should be used when the user asks to "classify an AI system under the AI Act", "determine the AI Act risk tier", "check if something is an AI system", "assess prohibited practices", "check high-risk classification", "determine Art. 6 exception applicability", or mentions "KI-Verordnung", "Risikoklassifizierung", Art. 5, Annex III, or GPAI systemic risk.
- ▌ Persuasive Legal Writing · gabrielmoreira bundleApply elite legal writing techniques drawn from Justice Kagan, Boies & Olson, and other top advocates to any legal document — briefs, submissions, letters, opinions, memos, or persuasive correspondence. This skill covers both prose craft (clarity, examples, parallel construction, voice, quoting) and architectural strategy (argument sequencing, framing, openings, endings). Use this skill whenever the user asks you to draft, edit, or improve legal writing and wants it to be genuinely persuasive — not just correct. Also trigger when the user mentions 'make it more persuasive', 'sharpen this', 'strengthen the argument', 'rewrite this section', 'punch it up', 'legal writing', 'draft a brief', 'draft a submission', 'write like a top advocate', or asks you to improve the rhetoric, flow, or force of any legal document. This skill complements the larissa-legal-voice skill (which handles tone and personal voice) by adding the persuasive technique layer on top.
- ▌ Sustainable Opposing Counsel Review · gabrielmoreira bundleProduces an adversarial attack on a legal argument that survives reply. Runs the opposing-counsel discipline twice: an unrestrained first pass, then the same instrument turned on that pass to cut every point that collapses under challenge - attacks on conceded facts, wrong-forum objections, speculation about documents and motives, gotchas with innocent explanations, overclaims, self-refuting assertions, and padding. The deliverable is one standalone attack containing only what can be defended, capped at five heads, not a discussion of the discarded draft. Use to attack, stress-test, red-team or rebut a submission, brief, motion, witness statement, letter or structured legal reasoning. Triggers on "attack this but only with points that hold", "no cheap shots", "what survives reply", "which points can I actually defend", "give me the version I can file", "double-pass adversarial review". Also use when an earlier adversarial review came back overlong or scattershot. Formal British English.
- ▌ Organization Knowhow Knowledge Builder · gabrielmoreira将团队 SOP、交付流程、角色职责、项目复盘、FAQ、决策边界和升级机制,整理成符合 Agent Knowledge v0.6 document-first 标准、可被 AI 安全调用的组织经验知识库。适用于用户要求“整理组织知识库”“沉淀团队 SOP”“把交付经验变成项目资料”“维护组织 know-how”的场景。
- ▌ Simulink Requirements · gabrielmoreiraUse this skill for all requirements-related work in a MATLAB MBSE project using the Requirements Toolbox (slreq). Covers creating and populating requirement sets, derivation links, test case requirements, verification coverage, reading and tracing links across requirement sets and models, checking link health, allocating requirements to components (Implement links), and building traceability reports. Trigger when the user asks about slreq API, slreqx files, slmx link files, outLinks/inLinks, traceability matrices, coverage analysis, broken links, or mapping requirements to architecture components. Use proactively for any requirements or traceability task.
- ▌ Simulink Control Motors · gabrielmoreiraBuild motor control solutions using Motor Control Blockset for PMSM, induction motors, BLDC, and SynRM. Implement field oriented control, sensorless FOC, six-step control, speed control, current control, and torque control. Configure SVPWM, flux weakening, MTPA, MTPV, control of non-linear motors, inverter control, and motor parameter estimation. Compose motor drive models, tune gains, and generate embedded code.
- ▌ Kitty Explain · gabrielmoreiraGenerate a "Kitty Explain" meme-style cat visual explainer for summarized content of documents, articles, URLs, or concepts. Use when user asks something similar to "explain by cats".
- ▌ Acquiring Disk Image With Dd And Dcfldd · gabrielmoreira bundleCreate forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
- ▌ Analyzing Campaign Attribution Evidence · gabrielmoreira bundleSystematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.
- ▌ Analyzing Cloud Storage Access Patterns · gabrielmoreira bundleDetect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and API-call spikes (e.g. GetObject) via statistical baselines and time-series anomaly detection. Use when investigating suspected cloud data exfiltration or building related detection rules.
- ▌ Analyzing Mft For Deleted File Recovery · gabrielmoreira bundleAnalyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT, and X-Ways Forensics to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space. Use when recovering evidence of deleted files, reconstructing NTFS file-system timelines, or detecting anti-forensic timestomping during a Windows forensic examination.
- ▌ Analyzing Ransomware Network Indicators · gabrielmoreira bundleIdentify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data. Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption exfiltration during incident response.
- ▌ Analyzing Usb Device Connection History · gabrielmoreira bundleCorrelate Windows registry keys (USBSTOR, MountedDevices), Event Logs, and setupapi.dev.log to reconstruct USB device connection history, first/last-plugged timestamps, and drive letter mappings. Use when investigating removable media usage, tracking device provenance, or building a timeline for suspected data exfiltration.
- ▌ Auditing MCP Servers For Tool Poisoning · gabrielmoreira bundleAudit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and description pinning. Use before adding a new MCP server to an agent stack, when reviewing an internal MCP server, detecting rug pulls, or investigating an agent's unexpected tool-driven behavior.
- ▌ Benchmarking Kubernetes With Kube Bench · gabrielmoreira bundleInstalls and runs the kube-bench tool against a Kubernetes cluster as a Job, DaemonSet, or standalone binary, selecting the correct benchmark version and targets (control plane, etcd, kubelet, worker nodes) and emitting JSON or JUnit output for pipelines. Use when setting kube-bench up for the first time, choosing which benchmark version and node targets to run, wiring it into CI, or troubleshooting skipped or misdetected checks. Keywords: kube-bench, DaemonSet, --benchmark, --targets, JSON output, JUnit, CI integration. Do not use for interpreting the findings or producing an audit report - use performing-kubernetes-cis-benchmark-with-kube-bench.
- ▌ Building Patch Tuesday Response Process · gabrielmoreira bundleEstablish a repeatable operational process for triaging, testing, and deploying Microsoft Patch Tuesday security updates (Windows, Office, Exchange, SQL Server, Azure) via WSUS/SCCM within risk-based remediation SLAs, from advisory review through validation. Use when building or improving a monthly patch management workflow or prioritizing which CVEs to remediate first.
- ▌ Detecting Azure Service Principal Abuse · gabrielmoreira bundleDetect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role assignment, admin consent bypass, and service principal enumeration. Use when investigating suspected privilege escalation or persistence via service principals, or building threat-hunting queries for Entra ID identity abuse.
- ▌ Detecting Compromised Cloud Credentials · gabrielmoreira bundleDetect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft Defender for Identity, and Google SCC Event Threat Detection. Use when investigating alerts about cloud API activity from unfamiliar locations, responding to an exposed-credential notification, or scoping a credential compromise.
- ▌ Detecting Credential Dumping Techniques · gabrielmoreira bundleDetect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g. via Mimikatz) using Sysmon Event ID 10 process-access logging, Windows Security logs, and SIEM correlation rules. Use when hunting for credential-theft activity on Windows/Active Directory hosts or triaging EDR alerts on LSASS access.
- ▌ Detecting Email Forwarding Rules Attack · gabrielmoreira bundleDetect malicious inbox/mail-flow forwarding rules that adversaries create to maintain persistent access to email communications for intelligence collection and business email compromise. Use when hunting for suspicious auto-forwarding, hidden mailbox rules, or T1114-style email collection persistence after a compromised account or BEC incident.
- ▌ Detecting Privilege Escalation Attempts · gabrielmoreira bundleDetect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. Use when threat hunting for T1068-style privilege escalation, triaging EDR/SIEM alerts on suspicious privilege changes, scoping compromise during incident response, or validating detection coverage in a purple team exercise.
- ▌ Detecting Supply Chain Attacks In CI CD · gabrielmoreira bundleScans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
- ▌ Exploiting Constrained Delegation Abuse · gabrielmoreira bundleExploits Kerberos Constrained Delegation misconfigurations in Active Directory using Impacket's findDelegation.py and getST.py (or Rubeus/Kekeo on Windows) to abuse S4U2Self and S4U2Proxy and impersonate privileged users. Use during authorized Active Directory penetration tests or red-team engagements for lateral movement and privilege escalation after finding an account trusted for constrained delegation.
- ▌ Exploiting Mass Assignment In REST Apis · gabrielmoreira bundleDiscovers and exploits mass assignment (autobinding) in REST APIs by injecting unexpected or hidden parameters (e.g. role, isAdmin, plan) into create/update requests, using Burp Suite Intruder, Arjun, and param-miner to find bindable fields on ORM-backed endpoints (Rails, Django, Laravel, Spring). Use when testing REST APIs for privilege escalation or authorization bypass via unintended parameter binding.
- ▌ Extracting Credentials From Memory Dump · gabrielmoreira bundleExtracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz. Use when performing memory forensics or incident response on an LSASS or full memory dump and you need to recover credentials or Kerberos material for investigation.
- ▌ Extracting Windows Event Logs Artifacts · gabrielmoreira bundleExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
- ▌ Hunting For Unusual Network Connections · gabrielmoreira bundleRuns a hypothesis-driven threat hunt for command-and-control activity (T1071) by querying SIEM/EDR network telemetry for anomalous outbound traffic, rare destinations, non-standard ports, and unusual connection frequencies from endpoints. Use when hunting for beaconing/C2 traffic, after threat intel flags suspicious infrastructure, or when alerts fire on anomalous connections.
- ▌ Implementing AWS Nitro Enclave Security · gabrielmoreira bundleBuild AWS Nitro Enclave confidential computing environments using nitro-cli to create enclave images, configure attestation-aware KMS policies with PCR condition keys, validate attestation documents against the Nitro PKI root, and set up vsock/kmstool-enclave-cli pipelines for processing PII, keys, and health records. Use for Nitro Enclave setup, attestation validation, or scoping KMS to an enclave image hash.
- ▌ Implementing Code Signing For Artifacts · gabrielmoreira bundleImplements code signing for build artifacts (binaries, packages, containers) using GPG, Sigstore, and platform-specific signing tools, establishing trust chains and verifying signatures in deployment pipelines. Use when establishing artifact integrity checks against supply-chain tampering, proving authenticity to customers, building zero-trust pipelines that reject unsigned artifacts, or meeting SLSA Level 2+ provenance requirements.
- ▌ Implementing Network Traffic Baselining · gabrielmoreira bundleBuilds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Python pandas, computing hourly/daily volume distributions, per-host and protocol/port statistics, and top-talker profiles, then flags outliers via z-score and IQR anomaly detection. Use when a SOC analyst needs to establish normal traffic patterns and surface deviations such as data exfiltration spikes, beaconing, or unusual port usage from historical flow data.
- ▌ Implementing Ransomware Backup Strategy · gabrielmoreira bundleDesigns a ransomware-resilient backup strategy using the 3-2-1-1-0 methodology (3 copies, 2 media types, 1 offsite, 1 immutable/air-gapped, 0 restore errors), configuring RPO/RTO-aligned schedules, isolating backup credentials, and automating restore testing. Use when planning ransomware backup resilience or air-gapped/immutable backup architecture.
- ▌ Implementing Soar Playbook For Phishing · gabrielmoreira bundleAutomates phishing incident response by calling the Splunk SOAR (Phantom) REST API to create containers, attach artifacts (emails, URLs, attachments), and trigger response playbooks. Use when building or wiring up a Splunk SOAR phishing playbook, ingesting a suspected phishing report into SOAR, or automating containment and triage for phishing incidents.
- ▌ Implementing Zero Trust With Beyondcorp · gabrielmoreira bundleConfigures Google BeyondCorp Enterprise Identity-Aware Proxy (IAP) as the access enforcement point for web applications, defining Access Context Manager access levels from device trust and network attributes, and auditing the resulting policies for compliance. Use when eliminating perimeter/VPN trust for GCP resources or internal apps, or when setting up identity- and device-posture-based access controls on Google Cloud.
- ▌ Mapping Attack Paths With Bloodhound Ce · gabrielmoreira bundleCollect Active Directory data with SharpHound and Entra ID data with AzureHound, ingest into BloodHound Community Edition, and analyze on-prem, cloud, and hybrid attack paths using built-in queries and custom Cypher. Use during authorized red-team or penetration-test engagements to map privilege-escalation chains toward domain/tenant compromise.
- ▌ Performing Binary Exploitation Analysis · gabrielmoreira bundleAnalyze ELF binaries for memory-corruption vulnerabilities and build proof-of-concept exploits using pwntools, checksec, and ROPgadget for buffer overflows and ROP chains. Use when a penetration test or CTF challenge requires evaluating compiler mitigations (NX, ASLR, stack canaries, PIE, RELRO) or developing a working exploit to demonstrate impact.
- ▌ Performing Disk Forensics Investigation · gabrielmoreira bundleConduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition, deleted file recovery, and artifact examination. Use when a security incident requires forensic analysis of persistent storage or when evidence must be preserved for legal or HR proceedings.
- ▌ Performing GRAPHQL Introspection Attack · gabrielmoreira bundlePerforms GraphQL introspection attacks that extract the full API schema (types, queries, mutations, subscriptions, field definitions), map the attack surface, test query depth/complexity limits, and exploit GraphQL-specific weaknesses such as batching attacks, alias-based brute force, and nested query DoS. Use for GraphQL security testing, schema enumeration, or GraphQL API penetration testing.
- ▌ Performing Insider Threat Investigation · gabrielmoreira bundleInvestigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies, combining digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Use when DLP alerts flag large data transfers to personal cloud storage or USB devices, when UBA detects anomalous access patterns for a user account, or when investigating employee data theft, privilege misuse, or internal threat detection requests.
- ▌ Performing Nist Csf Maturity Assessment · gabrielmoreira bundleConduct a NIST Cybersecurity Framework (CSF) 2.0 maturity assessment across the six core Functions (Govern, Identify, Protect, Detect, Respond, Recover), scoring organizational posture against the four Implementation Tiers (Partial, Risk-Informed, Repeatable, Adaptive) and producing an improvement roadmap. Use when benchmarking an organization's cybersecurity program maturity or preparing a CSF-based gap analysis and remediation plan.
- ▌ Performing Privileged Account Discovery · gabrielmoreira bundleDiscovers and inventories privileged accounts across enterprise infrastructure, including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin accounts, using automated scanning and risk classification. Use when building a privileged account inventory, onboarding accounts to a PAM solution, or scoping which accounts need privileged-access controls.
- ▌ Performing Ransomware Tabletop Exercise · gabrielmoreira bundlePlans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and backup destruction, then evaluates responses against NIST CSF and CISA guidelines. Use when planning or running a ransomware tabletop exercise or incident response readiness drill.
- ▌ Reverse Engineering Malware With Ghidra · gabrielmoreira bundleReverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to study internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Use when static or dynamic analysis flags suspicious functionality needing deeper code review, such as reversing C2 protocols, encryption algorithms, custom obfuscation, or a sample's exploit mechanism.
- ▌ Securing Container Registry With Harbor · gabrielmoreira bundleConfigures the security features of the Harbor open-source container registry - integrated Trivy scanning, Cosign and Notary content trust policies, project-level RBAC, immutable tag and retention rules, and OIDC authentication - to enforce provenance and block deployment of vulnerable images. Use when deploying or hardening Harbor, or when compliance requires that only signed and scanned images can be pulled. Keywords: Harbor, project policy, content trust, immutable tag, retention, robot account, OIDC, replication. Do not use for signing images with Cosign outside a registry - use implementing-image-provenance-verification-with-cosign.
- ▌ Multimodal Orchestration · gabrielmoreiraCoordinating text, image, voice, and tool-use modalities in a single interaction.
- ▌ Retentioneering Product Analytics · gabrielmoreira bundleAnalyze event logs, clickstreams, user paths, product funnels, retention, behavioral segments, transition graphs, step matrices, sequence patterns, and customer journeys using Retentioneering. Use when the user provides CSV, Parquet, pandas, or database event data containing user, event, and timestamp columns, or asks why users convert, churn, loop, abandon a flow, or follow particular product paths. Do not use for qualitative journey-mapping workshops or aggregate website traffic without user-level event sequences.
- ▌ Threejs Procedural Architecture · gabrielmoreira bundleBuild authored procedural buildings and architectural kits in Three.js. Use for massing grammars, exposed-edge analysis, façade bays, profiles, arches, cornices, roofs, ornaments, material-slot mesh compilation, deterministic variants, and procedural city assets.
- ▌ Copilot Session Report · gabrielmoreiraGenerate a detailed report of a Copilot CLI session — tools, skills, MCPs used, problem/solution narrative, files modified, testing results, key learnings, tool assessments, and pending work. Use when asked to create a session report, summarize a session, document what was done, or generate a session writeup.
- ▌ Playwright Automation Fill In Form · gabrielmoreiraUse when a developer needs to automate filling in a web form without submitting it — when they say 'fill in the form at URL', 'automate this form', 'enter these values in the web form', or 'test form input'. Uses Playwright MCP with accessible locators (getByLabel, getByRole, getByPlaceholder). Fills text with fill(), selects dropdowns with selectOption(), handles file uploads with setInputFiles(). ALWAYS stops before submitting — shows a filled-values summary and waits for human review. Auto-loads when form filling, web automation, input testing, or Playwright form interaction is mentioned.
- ▌ The Jury · gabrielmoreiraUse when a question, decision, plan, tradeoff, or claim needs a rigorous verdict and one perspective is not enough. Spawns a panel of 3 to 5 subagent jurors that form independent blind opinions, deliberate anonymously under an anti-anchoring and anti-sycophancy protocol, and return one committed verdict with confidence, preserved dissent, and a concrete next action. Domain-agnostic across engineering, architecture, data, product, hiring, strategy, vendor choice, build-vs-buy, and research design. Trigger phrases include "convene a jury", "have agents debate and decide", "get a panel to decide", "multi-agent decision", "stress-test this and decide", "monte um juri", "tribunal de agentes", "painel para decidir". Do NOT use to only critique without deciding (use the-fool for that), to build a plan or write the solution itself, or for simple factual lookups.
- ▌ Harness Eval · gabrielmoreiraEvaluate a repo agent harness (AGENTS.md, rules, skills, skill refs) for broken paths/commands, redundant instructions, and usefulness using a stack-agnostic dual-judge protocol with planted traps. HIGH PRIORITY questionnaires at top: Q1 optional docs, Q2 B/C budget before Track A (certainty/tokens). A always runs after Q2; B/C opt-in. ADRs/RFCs excluded from T2. Mixed apply uses 11-mixed-apply.md (KEEP/CUT). Use when the user says harness eval, harness-eval, harness debug, audit AGENTS.md, audit skills/rules, instruction audit, redundancy of agent instructions, usefulness of skills, Ship/Review/Hold/Slim/Keep-core for harness, or wants Track A/B/C harness evaluation. Do NOT use for harness setup or init, feature spec-driven work (tlc-spec-driven), or applying Ship/Slim trims unless the user explicitly asks after the report.
- ▌ Token Integration Analyzer · gabrielmoreiraToken integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, assesses contract composition and owner privileges, performs on-chain scarcity analysis, and evaluates how protocols handle non-standard tokens. Use when integrating or accepting arbitrary ERC20/ERC721 tokens, auditing a token implementation for standards conformity, or assessing risk from weird tokens such as fee-on-transfer, rebasing, missing return values, or blocklists.
- ▌ AI Coding Agents Sessions · gabrielmoreiraDesigns session lifecycle for coding-agent runtimes. Use when implementing resume, transcript restoration, checkpoint rewind, cross-worktree recovery, or session-state persistence.
- ▌ Dev Dependency Management · gabrielmoreiraGuides dependency management across languages and ecosystems. Use when choosing package managers, lockfiles, update policy, security scanning, SBOMs, or monorepo patterns.
- ▌ Containing Active Breach · gabrielmoreiraExecutes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.
- ▌ Pentesting Ajp · gabrielmoreiraTesting Apache JServ Protocol (AJP13) connectors (default 8009/TCP) for the Ghostcat LFI/RCE vulnerability (CVE-2020-1938), trusted-request-attribute abuse, AJP secret brute forcing, and reaching the Tomcat Manager via an nginx/Apache AJP proxy during authorized engagements.
- ▌ Pentesting Dns · gabrielmoreiraTesting DNS services (default 53/TCP+UDP, 5353/UDP mDNS) for zone transfers (AXFR), version/banner disclosure, subdomain and reverse-lookup enumeration, open recursion/amplification, DNSSEC and CAA misconfiguration, and Active Directory SRV record discovery during authorized engagements.
- ▌ Pentesting Ftp · gabrielmoreiraTesting FTP services (default port 21, plus FileZilla admin 14147) for anonymous access, default/weak credentials, FTP bounce port scanning and protocol relay, writable webroot uploads, and dangerous vsFTPd/ProFTPD configuration during authorized engagements.
- ▌ Pentesting Nfs · gabrielmoreiraTesting NFS services (default port 2049, with rpcbind/mountd on 111 and dynamic ports) for exported share enumeration, missing authentication, UID/GID impersonation, no_root_squash/no_all_squash misconfiguration, subtree_check export escape, and group-based file access (e.g., /etc/shadow) during authorized engagements.
- ▌ Pentesting Ntp · gabrielmoreiraTesting NTP services (default 123/UDP for time data and legacy control, 4460/TCP for NTS-KE/TLS) for monlist/Mode-7 amplification exposure, remote query/control leakage, time-shift MITM, weak NTS-KE TLS, and known ntpd/chrony/ntpd-rs CVEs during authorized engagements.
- ▌ Pentesting Rdp · gabrielmoreiraTesting the Remote Desktop Protocol (RDP, 3389/tcp ms-wbt-server) during authorized engagements. Covers encryption/NLA fingerprinting and NTLM info with nmap NSE, credential validation and pre/post-auth screenshots with netexec, password brute force (mindful of lockout), pass-the-hash logon with xfreerdp, session hijacking via tscon, RDS shadowing, RDP tunneling, and BlueKeep (CVE-2019-0708) / MS12-020 awareness.
- ▌ Pentesting Smb · gabrielmoreiraTesting SMB/CIFS file-sharing services (TCP 445, and 139 over NetBIOS) on Windows and Samba hosts during authorized engagements. Covers share enumeration, null/guest session abuse, user and RID enumeration, credentialed access with netexec/crackmapexec, password spraying, command execution (psexec/wmiexec/smbexec/atexec), SAM/LSA dumping, and notable CVEs such as EternalBlue (MS17-010).
- ▌ Pentesting Ssh · gabrielmoreiraTesting SSH services (default port 22) for weak algorithms/host keys, default and brute-forceable credentials, key-based auth gaps, SFTP shell escapes and tunneling, auth-method downgrade, and high-impact CVEs (regreSSHion CVE-2024-6387, XZ backdoor CVE-2024-3094, Erlang/OTP CVE-2025-32433, libssh CVE-2018-10933) during authorized engagements.
- ▌ Pentesting Vnc · gabrielmoreiraTesting VNC remote desktop services using the Remote Frame Buffer (RFB) protocol during authorized engagements. VNC commonly listens on 5900/5901 (and web clients on 5800/5801). Covers RFB fingerprinting, no-auth / RealVNC auth-bypass detection with nmap NSE and Metasploit, password brute force, decrypting the weak 3DES-stored ~/.vnc/passwd, and gaining graphical desktop control.
- ▌ Pentesting X11 · gabrielmoreiraTesting the X Window System (X11) display server during authorized engagements. X11 listens on TCP 6000+<display> and the local Unix socket /tmp/.X11-unix/X<display>. Covers detecting unauthenticated ("xhost +") access with nmap NSE and Metasploit, abusing MIT-MAGIC-COOKIE-1 auth tokens from ~/.Xauthority, window/clipboard enumeration, keystroke sniffing (xspy), screenshotting (xwd), live shadowing, and keystroke injection (xdotool) for command execution.
- ▌ Competition Kernel Container Escape · gabrielmoreiraInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for kernel attack surface, namespace and cgroup boundaries, container isolation assumptions, syscall paths, and escape primitive verification. Use when the user asks to analyze container-to-host escape paths, kernel exploit prerequisites, namespace crossover, capability misuse, or prove whether an exploit primitive crosses the sandbox boundary. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- ▌ Agui Dotnet Streaming Chat · gabrielmoreiraGet started with the AG-UI .NET SDK: bootstrap and run your first streaming-chat app (client + server) with the AG-UI .NET NuGet packages (AGUI.Client, AGUI.Server, AGUI.Formatting, AGUI.Abstractions). USE FOR: which packages to install and how to wire them; constructing an AGUIChatClient against an endpoint and streaming the reply as Microsoft.Extensions.AI IChatClient / ChatResponseUpdate; hosting an AG-UI POST endpoint yourself over any IChatClient; running a single- or multi-turn conversation; STATELESS agents (client owns history, resends it every turn) vs HOSTED / conversation-holding agents (server keeps the session, client pins a thread id). DO NOT USE FOR: changing the AG-UI .NET SDK itself (use the agui-dotnet-* contributor skills); server tools (agui-dotnet-server-tools); client tools (agui-dotnet-client-tools); interrupts / human-in-the-loop; shared state; generative UI; multimodal; or protobuf transport.
- ▌ Cerna Analysis · gabrielmoreiraUse when building a ceRNA regulatory network from a key gene list by combining bundled miRNA-mRNA and miRNA-lncRNA database files, with flat-file CSV exports and PDF visualization in a single output directory. NOT for: differential expression, single-cell analysis, enrichment analysis, or workflows without a key gene list.
- ▌ Knn Imputation · gabrielmoreiraUse when filtering genes with high missingness and then imputing missing values in a bulk expression matrix with group-aware KNN through DMwR2, where donor samples are restricted by one annotation column before imputation. For strata with 10 or fewer samples, the script falls back to row-wise direct filling with mean or median. NOT for: single-cell data, multi-column stratification, non-tabular inputs, network access, or interactive workflows.
- ▌ Wgcna Analysis · gabrielmoreiraUse when building a weighted gene co-expression network from a bulk expression matrix and a sample group file, filtering variable genes by MAD, identifying co-expression modules with WGCNA, correlating modules with traits, and exporting module-level plots and gene tables. NOT for single-cell RNA-seq, differential expression testing, methylation analysis, or datasets that are too small for WGCNA after quality control.
- ▌ Authorship Credit Gen · gabrielmoreiraUse when determining author order on research manuscripts, assigning CRediT contributor roles for transparency, documenting individual contributions to collaborative projects, or resolving authorship disputes in multi-institutional research. Generates fair and transparent auth...
- ▌ Find Paper References · gabrielmoreiraAutomatically find references for academic paper Markdown files. Reads full paper text, identifies each knowledge point requiring citation (epidemiological data, mechanism descriptions, existing research conclusions, etc.), searches PubMed for 3-5 most relevant articles per kn...
- ▌ Nih Biosketch Builder · gabrielmoreiraGenerate NIH Biosketch documents compliant with the 2022 OMB-approved.
- ▌ Regulatory Submission · gabrielmoreiraPrepare FDA/EMA regulatory submissions (IND/NDA/BLA/510(k)/PMA/MAA) in CTD format. Generate module outlines (Modules 1-5), run ICH compliance checks (ALCOA+, E6 GCP, Q1-Q12), verify data integrity, and produce submission-ready dossiers with cover letters and checklists.
- ▌ Style Journal Rewrite · gabrielmoreiraRewrite drafts according to target writing style or target journal format. Triggers when user says "rewrite in XX style", "match this tone", "format for XX journal", "rewrite following this format". Input can be .docx / .md / .txt or conversation text.
- ▌ Phylogenetic Tree Styler · gabrielmoreiraAnalyze data with `phylogenetic-tree-styler` using a reproducible workflow, explicit validation, and structured outputs for review-ready interpretation.
- ▌ Rct Bias Assessment Rob · gabrielmoreiraAutomates Risk of Bias 2 (ROB2) assessment for RCT papers by analyzing text against specific domains and synthesizing a report. Use when you need to assess the quality of a clinical trial paper or evaluate risk of bias.
- ▌ Toxicity Structure Alert · gabrielmoreiraAnalyze data with `toxicity-structure-alert` using a reproducible workflow, explicit validation, and structured outputs for review-ready interpretation.
- ▌ Literature Close Read · gabrielmoreiraProduce a structured close-reading report from a paper's full PDF-to-Markdown text (with `## Page XX` pagination and image references) when you need to systematically extract background, research questions, methods, results, limitations, and reproducible experimental details.
- ▌ Medical Vector Search · gabrielmoreiraVector database retrieval and evidence-based answering for medical research topics. Use when users need knowledge-base-backed answers about methodology, disease mechanisms, drug effects, clinical research, or research tools. Input is a medical research question; output is a st...
- ▌ Pmc Official Download · gabrielmoreiraDownload PubMed/PMC literature using officially permitted PMC methods. Whenever the user wants to download PMC full text, batch-retrieve PMC Open Access Subset articles, save full text corresponding to PMID/PMCID locally, or needs to determine whether a PubMed article can be l...
- ▌ Target Novelty Scorer · gabrielmoreiraScore the novelty of biological targets through literature mining and.
- ▌ Market Research Report Generator · gabrielmoreiraGenerates professional market research reports by analyzing business intent, decision levels, and conducting multi-source data retrieval (Web, PubMed, Clinical Trials).
- ▌ Clinic Research Design · gabrielmoreiraGenerates a structured prompt framework for clinical study protocols. Supports Diagnostic, Efficacy, Etiology, and Prognosis studies. Calculates sample size and provides logic guides for LLMs.
- ▌ Inclusion Criteria Gen · gabrielmoreiraGenerate and optimize clinical trial subject inclusion/exclusion criteria to balance scientific rigor with recruitment feasibility.
- ▌ Tres Settings Management · gabrielmoreiraManage Organization Settings and Platform Settings via the TRES MCP GraphQL API. Use when users ask about org settings, platform settings, configuration, feature flags, enable/disable platforms, balance diff, commit strategy, cost basis, ERP, pricing, sync boundaries, or any setting read/write operation. Trigger phrases include "get settings", "show settings", "update settings", "change settings", "enable platform", "disable platform", "balance diff", "commit strategy", "cost basis strategy", "set min sync date", "configure", "turn on", "turn off".
- ▌ Developmental Gene Panel Design Workflow · gabrielmoreiraPanel design for DEVELOPING / dynamic systems (embryonic organs, differentiation, regeneration). The target experiment is usually a LATE / terminal stage, but the biology is a trajectory: terminal cell types are end-products of earlier lineage programs. A panel built from the target stage alone resolves terminal STATES but systematically misses the developmental REGULATORS that produced them. This workflow therefore uses TWO references — the target-stage dataset (cell-state resolution) and an independent EARLIER-stage reference (developmental origin) — combines them under an explicit budget split, and benchmarks on the target stage.