Maicon Gambini
Community@MaiconGambini · São Paulo - SP, Brazil
Maicon Gambini's registry delivers 114 skills for agent harness engineering, OWASP WSTG penetration testing, and full-stack TypeScript/Python development standards.
Agent Skills by Maicon Gambini
Showing 110 vetted skills indexed across 1 GitHub repositories.
playwright-cli
Automate browser interactions and test web pages using Playwright CLI commands.
harness-context-layer
Audit agent context readiness and generate ARCHITECTURE.md, PRODUCT.md, and RELIABILITY.md from codebase analysis.
research
Investigate questions against primary sources and save cited findings as Markdown files.
wstg-business-logic
Tests business logic flaws, workflow bypasses, and file upload weaknesses during penetration tests.
domain-modeling
Builds and maintains project domain glossaries and architectural decision records.
frontend-dev-guidelines
Enforces opinionated React and TypeScript standards for Suspense-first, feature-based frontend development.
using-git-worktrees
Creates isolated git worktrees with directory selection, ignore verification, and baseline test validation.
backend-dev-guidelines
Enforces layered architecture standards for Node.js Express TypeScript microservices.
harness-refine
Generates and routes rule proposals from trajectory findings by blast radius.
python-testing-patterns
Implement pytest test suites with fixtures, mocking, parameterization, and coverage reporting.
wstg-weak-cryptography
Tests TLS configurations, padding oracles, unencrypted channels, and weak encryption per OWASP WSTG.
harness-runtime-feedback
Builds a runtime evidence plan covering logs, health checks, error signals, and observability for task validation.
wstg-authentication
Tests web application authentication mechanisms using the OWASP WSTG methodology.
frontend-developer
Build React and Next.js components with responsive layouts and client-side state management.
harness-worktree-lifecycle
Reports git worktree status and recommends safe cleanup without deleting files.
python-packaging
Create distributable Python packages with pyproject.toml and publish them to PyPI.
test-driven-development
Enforces red-green-refactor TDD workflow requiring failing tests before writing production code.
frontend-ui-dark-ts
Builds dark-themed React applications with Tailwind CSS, glassmorphism effects, and Framer Motion animations.
wstg-input-validation
Tests web applications for injection and input validation flaws using OWASP WSTG methodology.
systematic-debugging
Diagnose bugs through a four-phase root cause investigation process before proposing fixes.
wayfinder
Plans large efforts as decision tickets on an issue tracker and resolves them one per session.
frontend-mobile-development-component-scaffold
Generate React and React Native components with TypeScript types, tests, styles, and Storybook stories.
harness-progress-log
Updates harness progress files while preserving blockers and decisions.
modular-monolith
Design modular monolith architectures with enforced module boundaries and migration-ready structure.
Frequently Asked Questions About Maicon Gambini
FAQPage SchemaWhat tasks can I accomplish with Maicon Gambini's skill registry?▼
You can execute OWASP WSTG v4.2 penetration tests across 12 categories, orchestrate multi-session agent harnesses with PREVC gates and handoffs, enforce React/Next.js and FastAPI coding standards, run test-driven development cycles, manage git worktrees, resolve merge conflicts, and audit MCP server configurations for secret leaks.
Who is the target audience for these skills?▼
The registry targets penetration testers and security assessors using the WSTG suites, full-stack engineers building TypeScript/React and Python/FastAPI services, and platform engineers operating OpenCode or Cursor agent harnesses who need session continuity, quality gates, and role-separated planner-generator-evaluator workflows.
How do the harness skills work in practice during a session?▼
Start with harness-session-start to discover instructions and state, decompose work via harness-wip-control into one atomic task, execute under prevc-workflow with evaluator rubrics and quality gates, then finish with harness-clean-handoff recording evidence, blockers, and verification commands before committing.
Are these skills open source and what do they cost?▼
The skills are free community and personal contributions; nextjs-supabase-auth is Apache 2.0 licensed, the WSTG suites derive from the OWASP Web Security Testing Guide v4.2, and frontend-slides credits a public GitHub source. No paid licensing is indicated anywhere in the manifest.
What prerequisites or dependencies do these skills require?▼
playwright-cli requires Bash access to playwright-cli, npx, and npm. Python skills assume uv, pytest, FastAPI, SQLAlchemy, and Pydantic. Frontend skills assume Node.js with React 19, Next.js 14/15, Tailwind CSS, and MUI v7. Harness skills assume an OpenCode or Cursor environment with git.