gabrielmoreira
- 21k skills
- 0 followers
- 17 repo stars
- 2 weeks ago last updated
- ▌
- ▌ Site Specification · gabrielmoreiraExtract comprehensive site specifications from simple descriptions. Use when analyzing a user's theme request to determine site type, audience, tone, layout requirements, and typography.
- ▌ Multi Tenant LLM Hosting · gabrielmoreiraDesign secure, multi-tenant LLM hosting platforms with tenant isolation, quotas, billing attribution, noisy-neighbor protection, and per-tenant policy controls.
- ▌ Openclaw Deployment Hardening · gabrielmoreiraSecure OpenClaw deployments with preflight hardening checks, CI/CD guardrails, container runtime restrictions, and post-deploy verification. Use when shipping OpenClaw with Docker, Kubernetes, or automated release pipelines.
- ▌ Crisis Detection Intervention AI · gabrielmoreira bundleDetect crisis signals in user content using NLP, mental health sentiment analysis, and safe intervention protocols. Implements suicide ideation detection, automated escalation, and crisis resource integration. Use for mental health apps, recovery platforms, support communities. Activate on "crisis detection", "suicide prevention", "mental health NLP", "intervention protocol". NOT for general sentiment analysis, medical diagnosis, or replacing professional help.
- ▌ Pydeseq2 Differential Expression · gabrielmoreiraBulk RNA-seq DE with PyDESeq2: load counts, normalize, fit negative binomial models, Wald test (BH-FDR), LFC shrinkage, volcano/MA plots. Use for two-group comparisons, multi-factor designs with batch correction, multiple contrasts.
- ▌ Spikeinterface Electrophysiology · gabrielmoreiraUnified Python framework for extracellular electrophysiology. Load 20+ formats (SpikeGLX, OpenEphys, NWB, Intan, Maxwell, Blackrock), preprocess, run 10+ sorters (Kilosort4, SpykingCircus2, Tridesclous, MountainSort5) via one API, compute quality metrics (SNR, ISI, firing rate), compare sorters, export NWB/Phy. For format-agnostic multi-sorter workflows. For Neuropixels-specific PSTH/decoding use neuropixels.
- ▌ Writing Linkedin Posts · gabrielmoreira bundleCreate engaging, authentic LinkedIn posts like a Top Voice. Use this skill when asked to write LinkedIn content, social media posts for LinkedIn, professional thought leadership content, or help with LinkedIn engagement strategy. Triggers include requests for LinkedIn posts, professional social content, thought leadership pieces, or viral/engaging LinkedIn content.
- ▌ Post Merge Scan · gabrielmoreiraScan recent merges to main for follow-up cleanup: TODOs, deprecations, broken doc links, stale flags. Use in post-merge cleanup loops.
- ▌ Lcx Doctor · gabrielmoreiraDiagnose LazyCodex and Codex CLI installation health against the latest sources. Use whenever the user asks for a doctor or health check, says LazyCodex, lazycodex-ai, omo-codex, or Codex behaves oddly after an install, update, or config change, suspects a stale, drifted, or broken setup, or wants the local install audited and compared with the latest LazyCodex and Codex code.
- ▌ Youtube Research Automation · gabrielmoreiraDesign agent workflows that pull YouTube transcripts, search videos and channels, and monitor new uploads without Google API quotas or OAuth setup
- ▌ Doordash Group Orders · gabrielmoreiraGroup food ordering through the DoorDash CLI (dd-cli) from a persistent team roster. One request ("lunch for the team") fans out into a single merged cart with every line attributed to its eater via a person-to-cart-item-id ledger, per-person cost split with fee proration, payer rotation history, and a checkout gate that re-derives allergen conflicts against the roster live. Use when ordering for multiple people — team lunch, incident-response food, "collect orders from the thread" — or for /whose-turn payer rotation questions. Handles paste-a-thread intake: paste a Slack/chat thread and it builds the order ledger from it.
- ▌ Doordash Order Ledger · gabrielmoreiraAccountability layer for agent-driven DoorDash ordering. Works with the doordash-audit-log hook (which appends every dd-cli invocation to an append-only audit log) and the /doordash-report command to answer "what has my AI been ordering and what did it cost" from data instead of memory. Use when the user asks about their DoorDash spending, ordering patterns, what the agent did in past sessions, or wants jq recipes for querying the audit log. Covers log schema, query patterns, rotation, and privacy guidance.
- ▌ Prisma Schema Helper · gabrielmoreiraConfigure with prisma schema helper operations. Auto-activating skill for Backend Development. Triggers on: prisma schema helper, prisma schema helper Part of the Backend Development skill category. Use when working with prisma schema helper functionality. Trigger with phrases like "prisma schema helper", "prisma helper", "prisma".
- ▌ Rabbitmq Queue Setup · gabrielmoreiraConfigure rabbitmq queue setup operations. Auto-activating skill for Backend Development. Triggers on: rabbitmq queue setup, rabbitmq queue setup Part of the Backend Development skill category. Use when working with rabbitmq queue setup functionality. Trigger with phrases like "rabbitmq queue setup", "rabbitmq setup", "rabbitmq".
- ▌ Hyperparameter Tuner · gabrielmoreiraManage hyperparameter tuner operations. Auto-activating skill for ML Training. Triggers on: hyperparameter tuner, hyperparameter tuner Part of the ML Training skill category. Use when working with hyperparameter tuner functionality. Trigger with phrases like "hyperparameter tuner", "hyperparameter tuner", "hyperparameter".
- ▌ Optuna Study Creator · gabrielmoreiraCreate optuna study creator operations. Auto-activating skill for ML Training. Triggers on: optuna study creator, optuna study creator Part of the ML Training skill category. Use when working with optuna study creator functionality. Trigger with phrases like "optuna study creator", "optuna creator", "optuna".
- ▌ Prediction Monitor · gabrielmoreiraMonitor prediction monitor operations. Auto-activating skill for ML Deployment. Triggers on: prediction monitor, prediction monitor Part of the ML Deployment skill category. Use when monitoring systems or services. Trigger with phrases like "prediction monitor", "prediction monitor", "prediction".
- ▌ Vertex AI Deployer · gabrielmoreiraDeploy vertex ai deployer operations. Auto-activating skill for ML Deployment. Triggers on: vertex ai deployer, vertex ai deployer Part of the ML Deployment skill category. Use when deploying applications or services. Trigger with phrases like "vertex ai deployer", "vertex deployer", "deploy vertex ai er".
- ▌ Mocha Test Setup · gabrielmoreiraConfigure mocha test setup operations. Auto-activating skill for Test Automation. Triggers on: mocha test setup, mocha test setup Part of the Test Automation skill category. Use when writing or running tests. Trigger with phrases like "mocha test setup", "mocha setup", "mocha".
- ▌ Spy Setup Helper · gabrielmoreiraAssist with spy setup helper operations. Auto-activating skill for Test Automation. Triggers on: spy setup helper, spy setup helper Part of the Test Automation skill category. Use when working with spy setup helper functionality. Trigger with phrases like "spy setup helper", "spy helper", "spy".
- ▌ Flink Job Creator · gabrielmoreiraCreate flink job creator operations. Auto-activating skill for Data Pipelines. Triggers on: flink job creator, flink job creator Part of the Data Pipelines skill category. Use when working with flink job creator functionality. Trigger with phrases like "flink job creator", "flink creator", "flink".
- ▌ Spark Job Creator · gabrielmoreiraCreate spark job creator operations. Auto-activating skill for Data Pipelines. Triggers on: spark job creator, spark job creator Part of the Data Pipelines skill category. Use when working with spark job creator functionality. Trigger with phrases like "spark job creator", "spark creator", "spark".
- ▌ Cte Query Builder · gabrielmoreiraBuild cte query builder operations. Auto-activating skill for Data Analytics. Triggers on: cte query builder, cte query builder Part of the Data Analytics skill category. Use when working with cte query builder functionality. Trigger with phrases like "cte query builder", "cte builder", "cte".
- ▌ Async API Caller · gabrielmoreiraConfigure async api caller operations. Auto-activating skill for API Integration. Triggers on: async api caller, async api caller Part of the API Integration skill category. Use when working with APIs or building integrations. Trigger with phrases like "async api caller", "async caller", "async".
- ▌ Mindmap Generator · gabrielmoreiraGenerate mindmap generator operations. Auto-activating skill for Visual Content. Triggers on: mindmap generator, mindmap generator Part of the Visual Content skill category. Use when working with mindmap generator functionality. Trigger with phrases like "mindmap generator", "mindmap generator", "mindmap".
- ▌ Org Chart Creator · gabrielmoreiraCreate org chart creator operations. Auto-activating skill for Visual Content. Triggers on: org chart creator, org chart creator Part of the Visual Content skill category. Use when working with org chart creator functionality. Trigger with phrases like "org chart creator", "org creator", "org".
- ▌ Email Parser · gabrielmoreiraConfigure and manage - Parse email parser operations. Auto-activating skill for Business Automation. Triggers on: email parser, email parser Part of the Business Automation skill category. Use when working with email parser functionality. Trigger with phrases like "email parser", "email parser", "email".
- ▌ Inspect Received Goods · gabrielmoreira bundleInspect received goods for visible condition, identity, packaging, labeling, and hold-or-release evidence.
- ▌ Plan Inbound Receiving · gabrielmoreira bundlePlan inbound receiving work from appointment, load, dock, labor, document, and exception inputs.
- ▌ Calculate Days On Hand · gabrielmoreira bundleCalculate days on hand from on-hand inventory and average daily demand or daily cost consumption.
- ▌ Calculate Safety Stock · gabrielmoreira bundleCalculate safety stock using supplied demand variability, lead-time variability, service factor, or approved policy inputs.
- ▌ Optimize Pick Path · gabrielmoreira bundleOptimize pick paths from pick lists, locations, zones, travel distance, sequence constraints, equipment, and safety boundaries.
- ▌ Plan Batch Picking · gabrielmoreira bundlePlan batch picking from order lines, common SKUs, container limits, sort method, cutoffs, and accuracy controls.
- ▌ Plan Replenishment · gabrielmoreira bundlePlan warehouse replenishment from forward-pick demand, reserve stock, priorities, locations, labor, and cutoffs.
- ▌ Inspect Returned Goods · gabrielmoreira bundleInspect returned goods from item condition, photos, reason code, packaging, quantity, controls, and review requirements.
- ▌ Plan Reserve Storage · gabrielmoreira bundlePlan reserve storage from inventory profile, storage requirements, replenishment need, movement rules, and capacity constraints.
- ▌ Analyze Demurrage · gabrielmoreira bundleAnalyze demurrage from container, rail, terminal, or port events, free time, tariff rules, invoices, and source evidence.
- ▌ Analyze Detention · gabrielmoreira bundleAnalyze detention from appointment times, arrival and departure events, free time, charge rules, dock delays, and invoice evidence.
- ▌ Lammps Deepmd · gabrielmoreiraA tool and knowledge base for running molecular dynamics (MD) simulations in LAMMPS with the DeePMD-kit plugin. It handles input script preparation, ensemble selection (NVE/NVT/NPT), and job execution via `uv` or offline binaries. USE WHEN you need to set up, write, explain, or execute a LAMMPS molecular dynamics simulation using a DeePMD machine learning potential (e.g., `graph.pb`).
- ▌ Lammps Reaxff · gabrielmoreiraRun reactive molecular dynamics simulations in LAMMPS with the ReaxFF potential, including preparing input scripts (pair_style reaxff + fix qeq/reaxff), mapping LAMMPS atom types to elements via pair_coeff, choosing ensembles (NVE/NVT/NPT), and adding common ReaxFF diagnostics such as species analysis. Use when the user wants LAMMPS+ReaxFF workflows or needs a working, annotated `input.lammps` template.
- ▌ Relax · gabrielmoreiraPrepare CP2K geometry-relaxation task inputs from a user-provided structure and optimization settings. Use when the user needs ion-only or cell-coupled optimization with explicit optimizer and convergence controls.
- ▌ Dotnet Testing Code Coverage Analysis · gabrielmoreira bundle程式碼覆蓋率分析完整指南。當需要分析程式碼覆蓋率、產生覆蓋率報告或設定 CI/CD 覆蓋率檢查時使用。涵蓋 Coverlet 設定、報告產生、指標解讀與循環複雜度整合。包含 Fine Code Coverage、VS Code 內建工具與最佳實踐。 Make sure to use this skill whenever the user mentions code coverage, Coverlet, coverage report, branch coverage, cyclomatic complexity, or test quality metrics, even if they don't explicitly ask for coverage analysis. Keywords: code coverage, 程式碼覆蓋率, 覆蓋率分析, coverage report, Coverlet, Fine Code Coverage, dotnet-coverage, ReportGenerator, line coverage, branch coverage, 行覆蓋率, 分支覆蓋率, cyclomatic complexity, 循環複雜度, runsettings, cobertura
- ▌ Dotnet Testing Unit Test Fundamentals · gabrielmoreira bundle.NET 單元測試基礎與 FIRST 原則的專門技能。當需要建立單元測試、了解測試基礎、學習 3A Pattern、掌握測試最佳實踐時使用。涵蓋 FIRST 原則、AAA Pattern、Fact/Theory、測試金字塔等。 Make sure to use this skill whenever the user mentions unit testing fundamentals, FIRST principles, AAA/3A pattern, or wants to learn how to write basic .NET tests, even if they don't explicitly ask for fundamentals guidance. Keywords: unit test, 單元測試, unit testing, test fundamentals, 測試基礎, FIRST principle, FIRST 原則, 3A pattern, AAA pattern, Arrange Act Assert, Fact, Theory, InlineData, 如何寫測試, testing best practices, 建立單元測試
- ▌ Ticket Routing Playbook · gabrielmoreira bundleHow to pick the owning team and the priority for an inbound support ticket, including what to do when a ticket spans two teams. Use when triaging a ticket.
- ▌ Eu AI Act Triage Oliver Schmidt Prietz · gabrielmoreira bundleFast 15-25 minute triage for preliminary EU AI Act classification and compliance assessment. This skill should be used when the user asks to "do a quick AI Act assessment", "check if the AI Act applies to us", "run a preliminary classification", "do an AI Act triage", "quick check", "preliminary assessment", "Schnellprüfung", "Ersteinschätzung", or needs a fast initial assessment before committing to full analysis.
- ▌ Opposing Counsel Review · gabrielmoreira bundleAct as experienced opposing counsel to attack, undermine, and expose weaknesses in a legal argument, submission, witness statement, or structured reasoning. Produces a six-part adversarial analysis: 1. A core theory of attack identifying the single most effective way to defeat the argument; 2. A reconstructed version of the opposing argument stripped of rhetoric to expose its fragility; 3. Primary lines of attack grouped by category (legal misstatement, evidential gaps, causation failures, internal inconsistency, over-reliance on assertion, procedural weakness); 4. An "if I were the judge" section showing how a sceptical tribunal would dismantle the argument; 5. Surgical strikes - 3 to 5 high-impact points ready for oral submissions; and 6. An analysis of what the argument is trying to hide. Written in formal, adversarial British English for a legally trained audience.
- ▌ Campaign Operations Knowledge Builder · gabrielmoreira将活动目标、用户路径、渠道分工、物料资产、时间节奏、风险预案和复盘结论等资料,整理成符合 Agent Knowledge v0.6 document-first 标准、可被 AI 安全调用的运营类知识库。适用于用户要求“整理活动 / Campaign 运营知识库”“沉淀运营 SOP”“把运营资料变成项目资料”“维护运营知识库”的场景。
- ▌ Matlab Evaluate Tutor Quality · gabrielmoreiraUse when reviewing, auditing, scoring, or improving a real or synthetic MATLAB AI tutor transcript, tutoring prompt, generated lesson, exercise, feedback sequence, or skill behavior for MATLAB accuracy, active learning, assignment guardrails, feedback quality, debugging support, transfer prompts, and instructor-facing quality recommendations.
- ▌ Simulink Customize A2l · gabrielmoreiraCustomize A2L (ASAP2) files generated from Simulink models using coder.asap2 and coder.mapping APIs. Use this skill when adding COMPU_METHODs, creating GROUPs, converting STD_AXIS to COM_AXIS, adding BIT_OPERATIONs, creating VARIANT_CODING, excluding measurements or struct elements, removing DEFAULT_EVENT_LIST, or any A2L customization for calibration tool compatibility (INCA, CANape). Also use when the user mentions ASAP2, ECU calibration data, A2L export.
- ▌ Azure AI Translation Text Py · gabrielmoreiraAzure AI Text Translation SDK for real-time text translation, transliteration, language detection, and dictionary lookup. Use for translating text content in applications. Triggers: "text translation", "translator", "translate text", "transliterate", "TextTranslationClient".
- ▌ Azure Speech To Text REST Py · gabrielmoreiraAzure Speech to Text REST API for short audio (Python). Use for simple speech recognition of audio files up to 60 seconds without the Speech SDK. Triggers: "speech to text REST", "short audio transcription", "speech recognition REST API", "STT REST", "recognize speech REST". DO NOT USE FOR: Long audio (>60 seconds), real-time streaming, batch transcription, custom speech models, speech translation. Use Speech SDK or Batch Transcription API instead.
- ▌ 23 Personal Brand Strategy · gabrielmoreiraDung khi mot CA NHAN — founder, coach, creator — can chien luoc thuong hieu ca nhan 12 thang: chon niche, positioning statement ca nhan, story arc 3 chuong, 4 content pillar, thang authority 5 nac va lo trinh tang truong theo quy. Doc file context tu skill 22 truoc khi viet. Kich hoat khi user nhac 'chien luoc personal brand', 'dinh vi ca nhan', 'chon niche', 'content pillar ca nhan', 'story arc', 'founder positioning', 'toi nen noi ve chu de gi', 'xay hinh anh chuyen gia'. Khong dung cho — dinh vi cho DOANH NGHIEP hay san pham thi dung skill 58-positioning; ke hoach marketing cong ty thi dung skill 00-ke-hoach-mkt; tao file context ca nhan lan dau thi chay skill 22-personal-brand-context truoc.
- ▌ 27 Personal Brand Monetize · gabrielmoreiraDung khi mot CA NHAN da co nguoi theo doi va muon RA TIEN — 3 phien ban funnel cho founder, coach, creator; offer ladder tu mien phi den high-ticket; tam ly gia cho dich vu gan voi con nguoi; inbound vs outbound; dam phan brand deal cho creator; thue va phap ly ca nhan tai VN. Kich hoat khi user nhac 'kiem tien tu personal brand', 'offer ladder ca nhan', 'ban khoa hoc', 'coaching 1-1', 'nhan booking sponsorship', 'nhieu follower ma khong ra tien', 'founder lead gen'. Khong dung cho — dinh gia san pham cua DOANH NGHIEP thi dung skill 17-pricing-strategy; dong goi offer cho san pham cong ty thi dung skill 31-offer-design; chuoi email nuoi duong thi dung skill 14-email-marketing.
- ▌ Agency Autonomous Optimization Architect · gabrielmoreiraIntelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs.
- ▌ Agency Xr Cockpit Interaction Specialist · gabrielmoreiraSpecialist in designing and developing immersive cockpit-based control systems for XR environments
- ▌ Abusing Shadow Credentials For Privesc · gabrielmoreira bundleTake over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/AddKeyCredentialLink over a target, as a stealthier alternative to ForceChangePassword, during authorized red-team engagements.
- ▌ Analyzing Android Malware With Apktool · gabrielmoreira bundlePerform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination detection, and identification of obfuscated code, dynamic code loading, and reflection-based API calls. Use to statically triage a suspicious APK without executing it or to build mobile malware detection rules.
- ▌ Analyzing Windows Prefetch With Python · gabrielmoreira bundleParse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. Use when investigating renamed or masquerading binaries, verifying program execution timelines, or hunting for suspicious execution patterns in incident response.
- ▌ Deploying Honeytokens And Canarytokens · gabrielmoreira bundlePlants Canarytokens-based decoy artifacts (honey credentials, DNS tokens, web-bug URLs, AWS keys, documents, kubeconfigs) using Thinkst's open-source Canarytokens project and alerts via email or webhook when a token is touched. Use for high-fidelity intrusion detection in low-telemetry areas like file shares or credential stores, or to catch credential dumping and data-theft staging.
- ▌ Deploying Tailscale For Zero Trust Vpn · gabrielmoreira bundleDeploys and configures Tailscale (or self-hosted Headscale) as a WireGuard-based zero trust mesh VPN, setting up identity-aware ACLs, exit nodes, subnet routers, and MagicDNS for encrypted peer-to-peer connectivity. Use when replacing traditional VPN servers with an identity-authenticated mesh network or enforcing granular per-device access control lists.
- ▌ Detecting Attacks On Historian Servers · gabrielmoreira bundleDetect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement indicators as historians pivot between IT and OT networks. Use when monitoring historians bridging IT/OT zones for compromise, investigating historian-specific CVE exploitation, or validating historian data integrity after a suspected OT incident.
- ▌ Detecting Cloud Threats With Guardduty · gabrielmoreira bundleDeploy and operationalize Amazon GuardDuty, covering protection plans for S3, EKS, EC2 runtime monitoring, and Lambda, interpreting finding severity, and building automated response with EventBridge and Lambda. Use when establishing threat detection for AWS accounts, investigating findings on compromised instances or credential abuse, or building automated incident-response playbooks.
- ▌ Detecting Command And Control Over Dns · gabrielmoreira bundleDetect command-and-control (C2) traffic tunneled over DNS from tools like Iodine, dnscat2, dns2tcp, and Cobalt Strike DNS beacon, using Shannon entropy analysis of query subdomains, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signatures. Use when investigating suspected DNS tunneling, classifying DGA domains, detecting DNS beaconing, or building DNS anomaly rules for a SOC/SIEM.
- ▌ Detecting Lateral Movement With Splunk · gabrielmoreira bundleDetect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service (WMI/PsExec/RDP) abuse. Use when hunting for MITRE ATT&CK TA0008 lateral movement activity or investigating suspected pivoting between hosts during an incident, with Splunk as the SIEM.
- ▌ Executing Red Team Engagement Planning · gabrielmoreira bundleBuild the foundational red team engagement plan - scope definition, Rules of Engagement (restrictions, communication plan, emergency stop procedures, legal authorization), MITRE ATT&CK-aligned threat profile selection, and operational timelines - producing an engagement brief for stakeholder approval. Use before any offensive testing begins, when scoping a full-scope, assumed-breach, objective-based, or purple-team engagement.
- ▌ Exploiting Kerberoasting With Impacket · gabrielmoreira bundlePerforms Kerberoasting (MITRE ATT&CK T1558.003) using Impacket's GetUserSPNs.py to request Kerberos TGS tickets for SPN-registered service accounts, then cracks the extracted RC4/AES-encrypted hashes offline to recover service account credentials. Use during authorized Active Directory penetration tests or red-team engagements for credential access against service accounts via Kerberos ticket-granting-service requests.
- ▌ Extracting Config From Agent Tesla Rat · gabrielmoreira bundleExtracts embedded configuration from Agent Tesla RAT samples, including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints, via .NET decompilation and memory analysis. Use when analyzing a suspected or confirmed Agent Tesla sample and you need to recover its exfiltration channel and C2 configuration for threat intelligence or incident response.
- ▌ Hunting For Domain Fronting C2 Traffic · gabrielmoreira bundleDetects domain fronting C2 traffic by analyzing SNI-vs-HTTP-Host-header mismatches in proxy logs and inspecting TLS certificate discrepancies with pyOpenSSL. Use when hunting for command-and-control traffic hidden behind legitimate CDN domains, or when investigating proxy/TLS logs for signs of domain fronting evasion.
- ▌ Hunting For Scheduled Task Persistence · gabrielmoreira bundleRuns a hypothesis-driven threat hunt for Windows Scheduled Task persistence (T1053), guiding SIEM/EDR queries against task creation events (e.g. Event ID 4698), suspicious task actions, and unusual scheduling patterns. Use when hunting for scheduled-task persistence, after threat intel flags related campaigns, during incident response, or when alerts fire on schtasks/at.exe activity.
- ▌ Hunting For Startup Folder Persistence · gabrielmoreira bundleDetects T1547.001 startup folder persistence by monitoring Windows startup directories for suspicious file creation, cross-referencing Autoruns entries, and running a Python watchdog script for real-time filesystem monitoring. Use when hunting for malware or implants that survive reboot via startup-folder placement, or when validating autoruns/EDR findings against known-good startup baselines.
- ▌ Hunting For Suspicious Scheduled Tasks · gabrielmoreira bundleHunts for adversary persistence and execution via Windows scheduled tasks (T1053.005) by analyzing Security Event ID 4698 task-creation events, suspicious task properties, and unusual execution patterns from schtasks.exe/at.exe. Use after detecting schtasks or at.exe in process creation logs, during incident response to enumerate persistence on compromised hosts, or when Event ID 4698 fires for an unusual task.
- ▌ Hunting For T1098 Account Manipulation · gabrielmoreira bundleHunts for MITRE ATT&CK T1098 account manipulation - shadow admin creation, SID history injection, group membership changes, and credential modifications - by analyzing Windows Security Event Log IDs 4738, 4728, 4732, 4756, 4670, and 5136. Use when investigating suspected privilege persistence in Active Directory, after detecting anomalous group/credential changes, or during incident response to trace account tampering.
- ▌ Implementing API Key Security Controls · gabrielmoreira bundleImplements secure API key generation with sufficient entropy, server-side hashing (SHA-256/bcrypt) instead of plaintext storage, per-key scoping to endpoints/IPs/rate limits, zero-downtime rotation, and automated leak monitoring across GitHub repos, logs, and client-side code. Use when designing API key formats, building key rotation or revocation workflows, or protecting server-to-server API credentials from leakage, brute force, and abuse.
- ▌ Implementing Zero Trust Network Access · gabrielmoreira bundleConfigures Zero Trust Network Access (ZTNA) in AWS, Azure, and GCP using identity-aware proxies, micro-segmentation, and continuous verification with conditional access policies, replacing VPN-based access with BeyondCorp-style architectures. Use when replacing VPN remote access with identity-based controls, limiting lateral movement via micro-segmentation, or exposing cloud workloads to authenticated users without public internet exposure.
- ▌ Migrating To Post Quantum Cryptography · gabrielmoreira bundleBuild a cryptographic inventory/CBOM with OpenSSL 3.5+, deploy hybrid post-quantum key exchange (X25519MLKEM768) on TLS/VPN/SSH endpoints, generate ML-KEM/ML-DSA keys and PQC/hybrid certificates, and prioritize migration by harvest-now-decrypt-later (HNDL) exposure per NIST SP 1800-38. Use when inventorying enterprise cryptography for quantum-readiness, enabling hybrid PQC key exchange, or issuing and verifying PQC/hybrid certificates.
- ▌ Performing AI Driven Osint Correlation · gabrielmoreira bundleUse AI/LLM-based reasoning with Sherlock, theHarvester, and SpiderFoot to correlate OSINT findings—usernames, emails, social profiles, domain records, breach databases, and dark-web mentions—into unified, confidence-scored intelligence profiles with link analysis. Use when raw OSINT data from multiple sources needs merging into one target profile or resolving identity linkage across platforms.
- ▌ Performing Directory Traversal Testing · gabrielmoreira bundleTest web applications for path traversal and Local/Remote File Inclusion vulnerabilities by manipulating file path parameters, applying encoding and filter-bypass techniques, automating discovery with ffuf and dotdotpwn, and reading high-value files or achieving code execution. Use during authorized penetration tests of file download, view, or include functionality, or when assessing APIs that accept file names or file paths as parameters.
- ▌ Performing Ssl Tls Security Assessment · gabrielmoreira bundleAssess SSL/TLS server configurations using the sslyze Python scanning library to evaluate supported protocol versions, cipher suite strength, certificate chain validation, HSTS enforcement, OCSP stapling, and known vulnerabilities such as Heartbleed and ROBOT. Use when conducting a security assessment of a server's TLS configuration or verifying remediation of cipher/certificate weaknesses.
- ▌ Recovering Deleted Files With Photorec · gabrielmoreira bundleRecovers deleted files from disk images and storage media using PhotoRec's file signature-based carving engine, which works regardless of file system damage or corruption. Use when recovering deleted or lost files from a forensic disk image, damaged storage device, or corrupted file system during evidence recovery.
- ▌ Remediating S3 Bucket Misconfiguration · gabrielmoreira bundleProvides step-by-step procedures for remediating Amazon S3 bucket misconfigurations that expose sensitive data: enabling S3 Block Public Access, auditing bucket policies and ACLs, enforcing encryption, configuring access logging, and deploying automated remediation with AWS Config and Lambda. Use when AWS Config or Security Hub flags public or unencrypted S3 buckets, or preparing audit evidence for storage security controls.
- ▌ Scanning Containers With Trivy In Cicd · gabrielmoreira bundleIntegrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and to enforce severity-based quality gates that block vulnerable images from being deployed. Use when building Docker images in CI/CD and needing automated vulnerability scanning and pass/fail gates before registry push or production deployment.
- ▌ Securing Azure With Microsoft Defender · gabrielmoreira bundleDeploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring recommendations, and managing Secure Score via the unified Defender portal. Use when onboarding workloads to Defender for Cloud or setting up cloud workload protection and threat monitoring.
- ▌ Testing API Security With Owasp Top 10 · gabrielmoreira bundleSystematically assesses REST, GraphQL, and gRPC API endpoints against the OWASP API Security Top 10 (2023) using Burp Suite and Postman for automated and manual testing. Use during authorized API penetration tests, before deploying new endpoints to production, or when validating API gateway controls and rate limiting.
- ▌ Testing Ransomware Recovery Procedures · gabrielmoreira bundleTests and validates ransomware recovery procedures - backup restore operations (e.g. with Restic), RTO/RPO target verification, recovery sequencing, and clean-restore validation - to confirm organizational resilience against destructive ransomware attacks. Use when validating that recovery plans work under realistic conditions, measuring RTO/RPO against business requirements, or testing restore integrity after simulated encryption.
- ▌ Exploring MCP Tool Original User Motive · gabrielmoreiraBuild a starting-point taxonomy for an MCP tool — what users were trying to accomplish before they reached the tool — and publish it as a PostHog notebook. Reconstructs each session's goal from its opening tool calls, then clusters those goals into named categories with size, share, and facet mix. Use when the user asks "why do people use this tool?", "what are users actually trying to do?", "what problem brings people here?", "where do these sessions start?", "segment usage of <tool> by goal", or wants a Clio-style taxonomy of MCP usage. Complements exploring-mcp-intent-clusters, which groups what agents did per call rather than why the session began. The agent running this skill writes the goal labels itself, reading the corpus query output session by session — the bundled scripts cover the mechanical facets but measurably lose the goal's altitude, so do not delegate that field to them.
- ▌ Synonyms · gabrielmoreiraGenerate synonyms for words or phrases. Use this skill when the user needs alternative words with similar meanings, wants to expand vocabulary, or seeks varied expressions for writing.
- ▌ Threejs Exposure Color Grading · gabrielmoreira bundleBuild a measured exposure and grading path in Three.js. Use for a 64x36 encoded luminance meter, asynchronous readback, weighted log-average exposure, asymmetric adaptation, single tone-map ownership, and a generated 32-cube post-tone-map LUT.
- ▌ Threejs Precipitation Surfaces · gabrielmoreira bundleBuild coupled precipitation and affected surfaces in Three.js. Use for falling snow, snow accumulation, model snow caps, wet asphalt puddles, procedural ripple normals, splash flipbooks, rain streaks, shared weather envelopes, and surface wetness or coverage transitions.
- ▌ Syncfusion Maui Toolkit Accordion · gabrielmoreira bundleImplements Syncfusion .NET MAUI Accordion (SfAccordion) - a vertically collapsible panel with stacked headers for expanding/collapsing content. Use when working with accordions, collapsible panels, expandable lists, employee lists with details, or FAQ sections in .NET MAUI applications. Covers AccordionItem configuration, expand modes, and grouped content display.
- ▌ Syncfusion Maui Toolkit Migration · gabrielmoreira bundleMigrate from Syncfusion® .NET MAUI to Syncfusion® Toolkit for .NET MAUI. Covers namespace updates, API changes, configuration methods, and step-by-step migration patterns with minimal code modifications for 20+ components.
- ▌ Syncfusion Maui Toolkit Otp Input · gabrielmoreira bundleImplement OTP Input controls in .NET MAUI applications for authentication flows. Covers input types (Number, Text, Password), styling modes (Outlined, Filled, Underlined), event handling, value binding, validation patterns, and accessibility. Use this skill when building SMS/email OTP verification, multi-step authentication, or secure login forms.
- ▌ Sales Motion Design · gabrielmoreiraWhen the user wants to choose between PLG and sales-led, design a sales motion, optimize time-to-first-value, or build a value-before-purchase experience. Also use when the user mentions 'PLG,' 'product-led growth,' 'sales-led,' 'sales motion,' 'free trial,' 'freemium,' 'self-serve,' 'demo-first,' 'time-to-first-value,' 'TTFV,' or 'agent-led sales.' This skill covers sales motion selection, value delivery design, and go-to-market motion architecture. Do NOT use for technical implementation, code review, or software architecture.
- ▌ Codex Autoresearch · gabrielmoreiraTriage improvement work and run or resume accepted measured loops in a local project. Architecture, documentation, UX, product study, open research, taste, and one-shot fixes stay direct unless the user explicitly requests repeated measurement with a complete experiment contract.
- ▌ Ton Vulnerability Scanner · gabrielmoreiraScans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.
- ▌ Supply Chain Risk Auditor · gabrielmoreiraAudits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.
- ▌ AI Coding Agents Plugins · gabrielmoreiraDesigns plugin systems for coding-agent runtimes and CLIs. Use when adding plugin manifests, extension points, built-in plugins, or reloadable agent integrations.
- ▌ QA API Testing Contracts · gabrielmoreiraAPI contract testing across REST, GraphQL, gRPC, AsyncAPI, webhooks, and workflow contracts. Use when you need schema validation, breaking-change detection, and CI quality gates.
- ▌ Software Database Design · gabrielmoreiraDesigns database schemas, migrations, and data models for PostgreSQL, MySQL, MongoDB, and Redis. Use when planning tables, relationships, indexes, or ORM-backed schema changes.
- ▌ Software Security Appsec · gabrielmoreiraProvides application security guidance for design and implementation. Use when reviewing auth, data handling, supply-chain controls, or AppSec architecture.