timsonner
- 172 skills
- 0 followers
- 10 hours ago last updated
- ▌ Penetration Testing · timsonner bundleComprehensive penetration testing workflow using Kali Linux tools via MCP. Guides agents through reconnaissance, vulnerability assessment, exploitation, privilege escalation, and reporting. Use when conducting security assessments, CTF challenges, vulnerability testing, or red team exercises.
- ▌ Smbmap · timsonnerUse for SMB share and permission enumeration during authorized internal pentests. Trigger on validating share exposure, write access, and effective permissions across approved Windows hosts.
- ▌ Sqlmap · timsonnerUse for controlled SQL injection validation during authorized web and API assessments. Trigger on manually triaged injection candidates, request replay validation, and narrow retests where the least invasive proof path is required.
- ▌ Winrar · timsonnerUse for tightly scoped archive creation, compression, and packaging during authorized pentests. Trigger on approved evidence packaging, transfer-path simulation, and validating how compressed archives interact with endpoint or transfer controls.
- ▌ Wpscan · timsonnerUse for WordPress-specific assessment during authorized pentests. Trigger on confirmed WordPress installations, plugin and theme exposure review, version identification, and WordPress-focused retesting.
- ▌ Ralph Wiggum Pattern · timsonnerA Python-focused implementation of the Ralph Wiggum technique for AI-assisted software development
- ▌ Usage Github · timsonnerUsing OpenCode with GitHub - repository management, pull requests, and collaboration features
- ▌ Usage Gitlab · timsonnerUsing OpenCode with GitLab - repository management, merge requests, and CI/CD features
- ▌ AWS CLI · timsonnerUse for AWS control-plane validation during authorized pentests. Trigger on credentialed cloud review, IAM boundary checks, inventory confirmation, storage exposure review, and verifying what an approved AWS principal can see or access.
- ▌ Certipy · timsonnerUse for Active Directory Certificate Services review during authorized pentests. Trigger on AD CS enumeration, certificate template analysis, enrollment path validation, and understanding whether certificate-based privilege paths exist.
- ▌ Dnsenum · timsonnerUse for domain and subdomain enumeration during authorized pentests. Trigger on DNS-backed host discovery, record review, and expanding an approved domain inventory with conservative enumeration depth.
- ▌ Hashcat · timsonnerUse for offline password hash auditing during authorized pentests when performance or format support makes it the better fit. Trigger on approved hash review, password policy validation, and controlled offline cracking workflows.
- ▌ Kubectl · timsonnerUse for Kubernetes control-plane and workload validation during authorized pentests. Trigger on cluster inventory, RBAC checks, namespace review, pod exposure review, and verifying what an approved Kubernetes identity can access.
- ▌ Lazagne · timsonnerUse for tightly scoped local credential validation during authorized pentests. Trigger on approved host-based credential exposure review, password storage assessment, and determining whether a specific workstation or server stores recoverable credentials.
- ▌ Linpeas · timsonnerUse for Linux privilege-escalation enumeration during authorized pentests. Trigger on approved Linux host review, local misconfiguration discovery, and identifying practical privilege-escalation paths on a specific system.
- ▌ Masscan · timsonnerUse for high-speed network exposure discovery during authorized pentests. Trigger on very large approved address spaces, strict discovery windows, and cases where a fast first-pass port inventory is needed before deeper validation.
- ▌ Nbtscan · timsonnerUse for NetBIOS name enumeration during authorized internal pentests. Trigger on Windows host discovery, hostname to IP correlation, and validating legacy name-service exposure inside approved ranges.
- ▌ Netexec · timsonnerUse for controlled SMB, WinRM, and directory service validation during authorized internal assessments. Trigger on credentialed internal testing, access boundary checks, share review, and validating lateral movement assumptions under strict scope.
- ▌ Openvas · timsonnerUse for vulnerability scanning and baseline exposure review during authorized pentests. Trigger on broad host hygiene assessment, scanner-led coverage of approved environments, and repeatable validation workflows that still require analyst triage.
- ▌ Prowler · timsonnerUse for cloud control-plane posture review, identity analysis, logging coverage checks, and configuration drift assessment during authorized pentests. Trigger on AWS, Azure, or GCP scope where the goal is to review permissions, public exposure, and monitoring gaps.
- ▌ Semgrep · timsonnerUse for white-box application review, code pattern analysis, and secure design verification during authorized pentests. Trigger on source code access, framework-specific review, and validating whether runtime findings are supported by reachable code paths.
- ▌ Tcpdump · timsonnerUse for packet capture and protocol troubleshooting during authorized pentests. Trigger on validating network observations, capturing a narrow traffic slice, and supporting detection or protocol analysis with minimal tooling overhead.
- ▌ Whatweb · timsonnerUse for web technology fingerprinting during authorized pentests. Trigger on identifying frameworks, middleware, CMS signatures, version hints, and prioritizing analysis on confirmed web services.
- ▌ Winpeas · timsonnerUse for Windows privilege-escalation enumeration during authorized pentests. Trigger on approved Windows host review, local misconfiguration discovery, and identifying practical privilege-escalation paths on a specific system.
- ▌ Wslc Pentest Workflow · timsonner bundleRun authorized pentest workflows inside persistent WSL containers and orchestrate with imported pentest skills (methodology, tool-selection, and tool-specific skills).
- ▌ Configure Acp · timsonnerConfiguration for OpenCode ACP Support - setting up OpenCode to work with ACP-compatible editors
- ▌ Configure Lsp · timsonnerConfiguration for OpenCode LSP servers - setting up and customizing Language Server Protocol integration
- ▌ Configure MCP · timsonnerConfiguration for OpenCode MCP servers - adding local and remote Model Context Protocol tools
- ▌ Prerequisites · timsonnerPrerequisites for using OpenCode - terminal emulator requirements and API key setup
- ▌ PDF To Tinker Training · timsonner bundleSplit PDF books (variable formats) into supervised Tinker Datum pairs for Inkling LoRA fine-tuning via pure Python (sys.executable, Zero-Binary).
- ▌ Certutil · timsonnerUse for tightly scoped certificate handling, hashing, encoding, and approved transfer-path validation during authorized pentests. Trigger on certificate inspection, hash verification, data reformatting, and limited Windows-native transfer or staging checks.
- ▌ Dnsrecon · timsonnerUse for DNS enumeration during authorized pentests. Trigger on zone review, host discovery, record correlation, and building a more complete DNS-backed inventory for approved domains.
- ▌ Gitleaks · timsonnerUse for repository and filesystem secret discovery during authorized pentests. Trigger on code review, repository hygiene assessment, and validating whether credentials or tokens are exposed in approved source material.
- ▌ Gobuster · timsonnerUse for directory, DNS, and virtual host enumeration during authorized pentests. Trigger on hidden content discovery, vhost review, DNS brute-force within approved scope, and narrowing web attack surface gaps.
- ▌ Kerbrute · timsonnerUse for tightly scoped Kerberos user enumeration and low-impact authentication checks during authorized internal pentests. Trigger on approved identity validation, username hypothesis testing, and controlled Kerberos exposure review.
- ▌ Mimikatz · timsonnerUse for tightly scoped Windows credential-material and ticket validation during authorized pentests. Trigger on approved credential-access checks, LSASS exposure review, token and ticket analysis, and proving whether a host boundary exposes sensitive authentication material.
- ▌ Procdump · timsonnerUse for tightly scoped process memory capture during authorized pentests. Trigger on approved process analysis, crash-style debugging, and validating whether a specific process boundary exposes sensitive material.
- ▌ Recon Ng · timsonnerUse for modular passive reconnaissance during authorized pentests. Trigger on domain and company profiling, contact and infrastructure lead generation, and correlating public-source recon with approved scope.
- ▌ Seatbelt · timsonnerUse for Windows host situational awareness and security posture enumeration during authorized pentests. Trigger on approved Windows host review, local configuration inspection, and identifying material privilege or credential exposure on a specific system.
- ▌ Snmpwalk · timsonnerUse for SNMP enumeration during authorized pentests. Trigger on network device discovery, management plane review, community string validation, and understanding what device metadata is exposed over SNMP.
- ▌ Agent Workstation Drive · timsonner bundleEnd-to-end agent workstation control: stand up a GNOME Wayland headless RDP desktop in a container, connect with mstsc, and drive the GUI via Windows user32 injection. Use when any harness (Grok, Claude Code, Cursor, Codex, OpenCode, etc.) needs a graphical Linux workstation, remote desktop automation, computer-use beyond the terminal, "drive the desktop", GUI in a container, or to unlock full operator-style agency. Entry skill for agent freedom through capabilities. Related: gnome-wayland-rdp, kde-wayland-rdp, windows-ui-inject, wsl-containers, linux-desktop-rdp-container.
- ▌ Skill Creation · timsonnerA skill to help create OpenCode compatible skill files by adding the required YAML frontmatter to a markdown file
- ▌ Pentest Attack Patterns · timsonnerReference document containing common attack patterns, payloads, and exploitation techniques for penetration testing including exploit research methodology, web application attacks, command injection, path traversal/LFI, XSS, XXE, SSRF, reverse shells, privilege escalation, password cracking, Windows exploitation, network attacks, database attacks, wireless attacks, and references.
- ▌ Bitsadmin · timsonnerUse for tightly scoped Background Intelligent Transfer Service review during authorized pentests. Trigger on approved job inspection, Windows-native transfer-path validation, and determining whether BITS can support an approved staging or retrieval path.
- ▌ Dirbuster · timsonnerUse for GUI-driven directory and file discovery during authorized web assessments. Trigger on manual content review, curated wordlist-driven discovery, and situations where analysts need visual control over enumeration depth and threading.
- ▌ Dirsearch · timsonnerUse for web path and file enumeration during authorized pentests. Trigger on hidden endpoint discovery, lightweight content enumeration, and repeatable route checks against approved web targets.
- ▌ Gowitness · timsonnerUse for visual triage of web assets, login portals, and exposed interfaces during authorized pentests. Trigger on screenshot capture, human review of web surfaces, and attack surface prioritization.
- ▌ Mitmproxy · timsonnerUse for interactive HTTP and API interception during authorized pentests. Trigger on request and response inspection, workflow debugging, replay needs, and situations where a lightweight programmable proxy fits better than a larger suite.
- ▌ Owasp Zap · timsonnerUse for OWASP-focused web and API testing during authorized pentests. Trigger on proxy-based web review, automated or manual scan support, baseline OWASP Top 10 coverage, and validating application security controls with a lighter-weight interception workflow.
- ▌ Powerview · timsonnerUse for PowerShell-based Active Directory reconnaissance during authorized pentests. Trigger on approved domain object review, group and host relationship analysis, local admin exposure checks, and focused AD discovery inside a bounded scope.
- ▌ Responder · timsonnerUse for name-resolution weakness assessment during authorized internal pentests. Trigger on LLMNR, NBT-NS, or mDNS exposure review, capture-path validation, and measuring whether legacy name resolution creates credential risk.
- ▌ Rpcclient · timsonnerUse for Windows RPC enumeration during authorized internal pentests. Trigger on share and domain discovery, account metadata review, and validating what information a target exposes over SMB and RPC.
- ▌ Smbclient · timsonnerUse for SMB share review and file access validation during authorized internal assessments. Trigger on share enumeration, authenticated access checks, and confirming Windows file exposure within approved scope.
- ▌ Subfinder · timsonnerUse for fast passive subdomain enumeration during authorized external reconnaissance. Trigger on internet-facing scope, domain seed lists, public exposure review, and subdomain inventory validation.
- ▌ Wireshark · timsonnerUse for packet-level protocol review, detection visibility checks, and troubleshooting during authorized pentests. Trigger on validating network observations, confirming cleartext exposure, and comparing attacker activity to available telemetry.
- ▌ Configure · timsonnerConfiguration instructions for OpenCode - how to set up LLM providers and API keys
- ▌ Configure Rules · timsonnerConfiguration for OpenCode rules - defining custom instructions and behaviors for the AI agent
- ▌ Configure Tools · timsonnerConfiguration for OpenCode tools - managing tool permissions and built-in tools like bash, edit, write, read, etc.
- ▌
- ▌ Bloodhound · timsonnerUse for Active Directory relationship analysis during authorized internal assessments. Trigger on AD path mapping, privilege chain review, delegated access analysis, and understanding how directory relationships affect attacker movement.
- ▌ Burp Suite · timsonnerUse for manual web and API testing, authenticated workflow review, request replay, and controlled validation during authorized pentests. Trigger on session handling, authorization checks, business logic review, and proof of impact for web findings.
- ▌ Evil Winrm · timsonnerUse for controlled WinRM access validation during authorized internal pentests. Trigger on approved administrative workflow review, WinRM boundary checks, and validating whether an authorized credential can reach a specific Windows host.
- ▌ Kube Bench · timsonnerUse for Kubernetes CIS benchmark review during authorized pentests. Trigger on cluster hardening assessment, node and control-plane configuration review, and validating whether a Kubernetes environment meets baseline security expectations.
- ▌ Ldapsearch · timsonnerUse for LDAP and directory service enumeration during authorized internal assessments. Trigger on identity store review, rootDSE checks, naming context discovery, and validating directory exposure with approved credentials.
- ▌ Scoutsuite · timsonnerUse for cloud posture review across AWS, Azure, and GCP during authorized pentests. Trigger on control-plane inventory, exposed service review, identity analysis, and producing a structured view of cloud configuration risk.
- ▌ Sharphound · timsonnerUse for Active Directory graph collection during authorized pentests. Trigger on approved AD relationship mapping, privilege-path review, local admin exposure review, and generating focused data for BloodHound analysis.
- ▌ Testssl Sh · timsonnerUse for TLS and certificate posture review during authorized pentests. Trigger on checking protocol support, cipher posture, certificate hygiene, and internet-facing HTTPS hardening gaps.
- ▌ Trufflehog · timsonnerUse for repository, filesystem, and remote source secret discovery during authorized pentests. Trigger on secret hunting, token exposure review, and validating whether approved code or history contains material credential leakage.
- ▌ Configure Agents · timsonnerConfiguration for OpenCode agents - defining and customizing AI agent behaviors and capabilities
- ▌ Configure Models · timsonnerConfiguration for OpenCode models - selecting and configuring LLM providers and specific models
- ▌ Configure Skills · timsonnerConfiguration for OpenCode skills - managing and configuring agent skills for reusable behaviors
- ▌ Configure Themes · timsonnerConfiguration for OpenCode themes - customizing the visual appearance of the TUI and desktop app
- ▌ Feroxbuster · timsonnerUse for recursive web content discovery during authorized pentests. Trigger on hidden directory discovery, route enumeration, controlled recursion, and fast CLI coverage of approved web targets.
- ▌ Kube Hunter · timsonnerUse for Kubernetes exposure and attack-surface review during authorized pentests. Trigger on cluster endpoint discovery, Kubernetes service exposure analysis, and validating whether a cluster presents remotely reachable weaknesses.
- ▌ Onesixtyone · timsonnerUse for lightweight SNMP community-string validation during authorized pentests. Trigger on quick SNMP exposure checks, network device discovery, and validating whether approved devices accept known or bounded community strings.
- ▌ Proxychains · timsonnerUse for routing approved tools through a bounded proxy path during authorized pentests. Trigger on approved pivot-path testing, segmented service validation, and ensuring a specific tool uses the intended proxy or SOCKS route.
- ▌ Searchsploit · timsonnerUse for exploit and vulnerability reference research during authorized pentests. Trigger on confirmed product versions, CVE review, exploitability triage, and mapping known issues to observed services without running exploit code.
- ▌ Theharvester · timsonnerUse for passive OSINT collection during authorized pentests. Trigger on email, domain, subdomain, and public-source metadata gathering to seed recon without active target interaction.
- ▌ Configure Commands · timsonnerConfiguration for OpenCode custom commands - creating and managing custom slash commands for repetitive tasks
- ▌ Configure Keybinds · timsonnerConfiguration for OpenCode keybinds - customizing keyboard shortcuts for the TUI and desktop app
- ▌ Usage Add Features · timsonnerHow to use OpenCode to add new features to your project - planning, iterating, and building with AI assistance
- ▌ Usage Make Changes · timsonnerHow to use OpenCode to make direct changes to your codebase - straightforward modifications and refactoring
- ▌ Usage Undo Changes · timsonnerHow to undo and redo changes made by OpenCode - reverting modifications and recovering work
- ▌ Enum4linux Ng · timsonnerUse for SMB and Windows host enumeration during authorized internal assessments. Trigger on Windows file sharing, workgroup or domain discovery, user and share review, and validating internal attack surface assumptions.
- ▌ Usage Ask Questions · timsonnerHow to ask OpenCode questions about your codebase - using context, file references, and effective questioning techniques
- ▌ Ldapdomaindump · timsonnerUse for structured Active Directory LDAP inventory during authorized internal pentests. Trigger on approved domain mapping, directory object review, and generating a focused picture of groups, users, and trust relationships.
- ▌ Tool Selection · timsonnerSelect pentest tools by methodology phase, target type, and risk tolerance. Use for deciding whether to use amass, subfinder, nmap, owasp-zap, wfuzz, dirb, dnsrecon, netcat, linpeas, winpeas, metasploit-framework, and related tools during authorized assessments.
- ▌ Configure Formatters · timsonnerConfiguration for OpenCode formatters - setting up and customizing code formatters for different languages
- ▌ Impacket Psexec · timsonnerUse for tightly scoped remote execution validation over SMB during authorized internal pentests. Trigger on approved administrative boundary checks, service-creation path review, and confirming whether a specific credential can execute on a specific Windows host.
- ▌ John The Ripper · timsonnerUse for offline password hash auditing during authorized pentests. Trigger on approved hash review, password policy validation, and measuring credential resilience without online authentication attempts.
- ▌ Proxmox System Administration · timsonnerUse when operating a Proxmox VE host with least-privilege workflows, reusable VM templates, and auditable hardening.
- ▌ Configure Permissions · timsonnerConfiguration for OpenCode permissions - controlling which actions require approval to run
- ▌ Impacket Smbexec · timsonnerUse for tightly scoped SMB-based remote command validation during authorized internal pentests. Trigger on approved execution-boundary checks and confirming whether a specific credential can execute commands on a specific Windows host over SMB.
- ▌ Impacket Wmiexec · timsonnerUse for tightly scoped WMI-based remote execution validation during authorized internal pentests. Trigger on approved Windows management boundary checks and verifying whether a specific credential can execute on a specific host through WMI.
- ▌ Configure Custom Tools · timsonnerConfiguration for OpenCode custom tools - creating and managing tools that the LLM can call during conversations
- ▌ Impacket Lookupsid · timsonnerUse for SID and domain object enumeration during authorized internal pentests. Trigger on approved domain metadata review, account discovery validation, and understanding what a target reveals about identities over RPC.
- ▌ Impacket Getnpusers · timsonnerUse for AS-REP roasting exposure review during authorized internal pentests. Trigger on Kerberos preauthentication analysis, user account posture review, and validating whether specific accounts create offline password risk.
- ▌ Impacket Ntlmrelayx · timsonnerUse for tightly controlled NTLM relay validation during authorized internal pentests. Trigger on approved relay-path assessment, protocol hardening review, and confirming whether a captured authentication flow can be relayed to a specific approved target.
- ▌ Impacket Getuserspns · timsonnerUse for SPN enumeration and Kerberoasting exposure review during authorized internal pentests. Trigger on service account analysis, Kerberos posture review, and validating whether SPN-bearing accounts create practical password risk.
- ▌ Impacket Secretsdump · timsonnerUse for tightly scoped credential-material validation during authorized internal pentests. Trigger on approved LSASS, SAM, or NTDS exposure review, privilege-boundary checks, and confirming whether a specific credential path can access sensitive authentication material.