← all publishers

timsonner

@timsonner source repo

172 published skills · page 1 of 2

  1. Penetration Testing · timsonner bundle
    Comprehensive penetration testing workflow using Kali Linux tools via MCP. Guides agents through reconnaissance, vulnerability assessment, exploitation, privilege escalation, and reporting. Use when conducting security assessments, CTF challenges, vulnerability testing, or red team exercises.
    0
    installs
  2. Smbmap · timsonner
    Use for SMB share and permission enumeration during authorized internal pentests. Trigger on validating share exposure, write access, and effective permissions across approved Windows hosts.
    0
    installs
  3. Sqlmap · timsonner
    Use for controlled SQL injection validation during authorized web and API assessments. Trigger on manually triaged injection candidates, request replay validation, and narrow retests where the least invasive proof path is required.
    0
    installs
  4. Winrar · timsonner
    Use for tightly scoped archive creation, compression, and packaging during authorized pentests. Trigger on approved evidence packaging, transfer-path simulation, and validating how compressed archives interact with endpoint or transfer controls.
    0
    installs
  5. Wpscan · timsonner
    Use for WordPress-specific assessment during authorized pentests. Trigger on confirmed WordPress installations, plugin and theme exposure review, version identification, and WordPress-focused retesting.
    0
    installs
  6. Ralph Wiggum Pattern · timsonner
    A Python-focused implementation of the Ralph Wiggum technique for AI-assisted software development
    0
    installs
  7. Usage Github · timsonner
    Using OpenCode with GitHub - repository management, pull requests, and collaboration features
    0
    installs
  8. Usage Gitlab · timsonner
    Using OpenCode with GitLab - repository management, merge requests, and CI/CD features
    0
    installs
  9. AWS CLI · timsonner
    Use for AWS control-plane validation during authorized pentests. Trigger on credentialed cloud review, IAM boundary checks, inventory confirmation, storage exposure review, and verifying what an approved AWS principal can see or access.
    0
    installs
  10. Certipy · timsonner
    Use for Active Directory Certificate Services review during authorized pentests. Trigger on AD CS enumeration, certificate template analysis, enrollment path validation, and understanding whether certificate-based privilege paths exist.
    0
    installs
  11. Dnsenum · timsonner
    Use for domain and subdomain enumeration during authorized pentests. Trigger on DNS-backed host discovery, record review, and expanding an approved domain inventory with conservative enumeration depth.
    0
    installs
  12. Hashcat · timsonner
    Use for offline password hash auditing during authorized pentests when performance or format support makes it the better fit. Trigger on approved hash review, password policy validation, and controlled offline cracking workflows.
    0
    installs
  13. Kubectl · timsonner
    Use for Kubernetes control-plane and workload validation during authorized pentests. Trigger on cluster inventory, RBAC checks, namespace review, pod exposure review, and verifying what an approved Kubernetes identity can access.
    0
    installs
  14. Lazagne · timsonner
    Use for tightly scoped local credential validation during authorized pentests. Trigger on approved host-based credential exposure review, password storage assessment, and determining whether a specific workstation or server stores recoverable credentials.
    0
    installs
  15. Linpeas · timsonner
    Use for Linux privilege-escalation enumeration during authorized pentests. Trigger on approved Linux host review, local misconfiguration discovery, and identifying practical privilege-escalation paths on a specific system.
    0
    installs
  16. Masscan · timsonner
    Use for high-speed network exposure discovery during authorized pentests. Trigger on very large approved address spaces, strict discovery windows, and cases where a fast first-pass port inventory is needed before deeper validation.
    0
    installs
  17. Nbtscan · timsonner
    Use for NetBIOS name enumeration during authorized internal pentests. Trigger on Windows host discovery, hostname to IP correlation, and validating legacy name-service exposure inside approved ranges.
    0
    installs
  18. Netexec · timsonner
    Use for controlled SMB, WinRM, and directory service validation during authorized internal assessments. Trigger on credentialed internal testing, access boundary checks, share review, and validating lateral movement assumptions under strict scope.
    0
    installs
  19. Openvas · timsonner
    Use for vulnerability scanning and baseline exposure review during authorized pentests. Trigger on broad host hygiene assessment, scanner-led coverage of approved environments, and repeatable validation workflows that still require analyst triage.
    0
    installs
  20. Prowler · timsonner
    Use for cloud control-plane posture review, identity analysis, logging coverage checks, and configuration drift assessment during authorized pentests. Trigger on AWS, Azure, or GCP scope where the goal is to review permissions, public exposure, and monitoring gaps.
    0
    installs
  21. Semgrep · timsonner
    Use for white-box application review, code pattern analysis, and secure design verification during authorized pentests. Trigger on source code access, framework-specific review, and validating whether runtime findings are supported by reachable code paths.
    0
    installs
  22. Tcpdump · timsonner
    Use for packet capture and protocol troubleshooting during authorized pentests. Trigger on validating network observations, capturing a narrow traffic slice, and supporting detection or protocol analysis with minimal tooling overhead.
    0
    installs
  23. Whatweb · timsonner
    Use for web technology fingerprinting during authorized pentests. Trigger on identifying frameworks, middleware, CMS signatures, version hints, and prioritizing analysis on confirmed web services.
    0
    installs
  24. Winpeas · timsonner
    Use for Windows privilege-escalation enumeration during authorized pentests. Trigger on approved Windows host review, local misconfiguration discovery, and identifying practical privilege-escalation paths on a specific system.
    0
    installs
  25. Wslc Pentest Workflow · timsonner bundle
    Run authorized pentest workflows inside persistent WSL containers and orchestrate with imported pentest skills (methodology, tool-selection, and tool-specific skills).
    0
    installs
  26. Configure Acp · timsonner
    Configuration for OpenCode ACP Support - setting up OpenCode to work with ACP-compatible editors
    0
    installs
  27. Configure Lsp · timsonner
    Configuration for OpenCode LSP servers - setting up and customizing Language Server Protocol integration
    0
    installs
  28. Configure MCP · timsonner
    Configuration for OpenCode MCP servers - adding local and remote Model Context Protocol tools
    0
    installs
  29. Prerequisites · timsonner
    Prerequisites for using OpenCode - terminal emulator requirements and API key setup
    0
    installs
  30. PDF To Tinker Training · timsonner bundle
    Split PDF books (variable formats) into supervised Tinker Datum pairs for Inkling LoRA fine-tuning via pure Python (sys.executable, Zero-Binary).
    0
    installs
  31. Certutil · timsonner
    Use for tightly scoped certificate handling, hashing, encoding, and approved transfer-path validation during authorized pentests. Trigger on certificate inspection, hash verification, data reformatting, and limited Windows-native transfer or staging checks.
    0
    installs
  32. Dnsrecon · timsonner
    Use for DNS enumeration during authorized pentests. Trigger on zone review, host discovery, record correlation, and building a more complete DNS-backed inventory for approved domains.
    0
    installs
  33. Gitleaks · timsonner
    Use for repository and filesystem secret discovery during authorized pentests. Trigger on code review, repository hygiene assessment, and validating whether credentials or tokens are exposed in approved source material.
    0
    installs
  34. Gobuster · timsonner
    Use for directory, DNS, and virtual host enumeration during authorized pentests. Trigger on hidden content discovery, vhost review, DNS brute-force within approved scope, and narrowing web attack surface gaps.
    0
    installs
  35. Kerbrute · timsonner
    Use for tightly scoped Kerberos user enumeration and low-impact authentication checks during authorized internal pentests. Trigger on approved identity validation, username hypothesis testing, and controlled Kerberos exposure review.
    0
    installs
  36. Mimikatz · timsonner
    Use for tightly scoped Windows credential-material and ticket validation during authorized pentests. Trigger on approved credential-access checks, LSASS exposure review, token and ticket analysis, and proving whether a host boundary exposes sensitive authentication material.
    0
    installs
  37. Procdump · timsonner
    Use for tightly scoped process memory capture during authorized pentests. Trigger on approved process analysis, crash-style debugging, and validating whether a specific process boundary exposes sensitive material.
    0
    installs
  38. Recon Ng · timsonner
    Use for modular passive reconnaissance during authorized pentests. Trigger on domain and company profiling, contact and infrastructure lead generation, and correlating public-source recon with approved scope.
    0
    installs
  39. Seatbelt · timsonner
    Use for Windows host situational awareness and security posture enumeration during authorized pentests. Trigger on approved Windows host review, local configuration inspection, and identifying material privilege or credential exposure on a specific system.
    0
    installs
  40. Snmpwalk · timsonner
    Use for SNMP enumeration during authorized pentests. Trigger on network device discovery, management plane review, community string validation, and understanding what device metadata is exposed over SNMP.
    0
    installs
  41. Agent Workstation Drive · timsonner bundle
    End-to-end agent workstation control: stand up a GNOME Wayland headless RDP desktop in a container, connect with mstsc, and drive the GUI via Windows user32 injection. Use when any harness (Grok, Claude Code, Cursor, Codex, OpenCode, etc.) needs a graphical Linux workstation, remote desktop automation, computer-use beyond the terminal, "drive the desktop", GUI in a container, or to unlock full operator-style agency. Entry skill for agent freedom through capabilities. Related: gnome-wayland-rdp, kde-wayland-rdp, windows-ui-inject, wsl-containers, linux-desktop-rdp-container.
    0
    installs
  42. Skill Creation · timsonner
    A skill to help create OpenCode compatible skill files by adding the required YAML frontmatter to a markdown file
    0
    installs
  43. Pentest Attack Patterns · timsonner
    Reference document containing common attack patterns, payloads, and exploitation techniques for penetration testing including exploit research methodology, web application attacks, command injection, path traversal/LFI, XSS, XXE, SSRF, reverse shells, privilege escalation, password cracking, Windows exploitation, network attacks, database attacks, wireless attacks, and references.
    0
    installs
  44. Bitsadmin · timsonner
    Use for tightly scoped Background Intelligent Transfer Service review during authorized pentests. Trigger on approved job inspection, Windows-native transfer-path validation, and determining whether BITS can support an approved staging or retrieval path.
    0
    installs
  45. Dirbuster · timsonner
    Use for GUI-driven directory and file discovery during authorized web assessments. Trigger on manual content review, curated wordlist-driven discovery, and situations where analysts need visual control over enumeration depth and threading.
    0
    installs
  46. Dirsearch · timsonner
    Use for web path and file enumeration during authorized pentests. Trigger on hidden endpoint discovery, lightweight content enumeration, and repeatable route checks against approved web targets.
    0
    installs
  47. Gowitness · timsonner
    Use for visual triage of web assets, login portals, and exposed interfaces during authorized pentests. Trigger on screenshot capture, human review of web surfaces, and attack surface prioritization.
    0
    installs
  48. Mitmproxy · timsonner
    Use for interactive HTTP and API interception during authorized pentests. Trigger on request and response inspection, workflow debugging, replay needs, and situations where a lightweight programmable proxy fits better than a larger suite.
    0
    installs
  49. Owasp Zap · timsonner
    Use for OWASP-focused web and API testing during authorized pentests. Trigger on proxy-based web review, automated or manual scan support, baseline OWASP Top 10 coverage, and validating application security controls with a lighter-weight interception workflow.
    0
    installs
  50. Powerview · timsonner
    Use for PowerShell-based Active Directory reconnaissance during authorized pentests. Trigger on approved domain object review, group and host relationship analysis, local admin exposure checks, and focused AD discovery inside a bounded scope.
    0
    installs
  51. Responder · timsonner
    Use for name-resolution weakness assessment during authorized internal pentests. Trigger on LLMNR, NBT-NS, or mDNS exposure review, capture-path validation, and measuring whether legacy name resolution creates credential risk.
    0
    installs
  52. Rpcclient · timsonner
    Use for Windows RPC enumeration during authorized internal pentests. Trigger on share and domain discovery, account metadata review, and validating what information a target exposes over SMB and RPC.
    0
    installs
  53. Smbclient · timsonner
    Use for SMB share review and file access validation during authorized internal assessments. Trigger on share enumeration, authenticated access checks, and confirming Windows file exposure within approved scope.
    0
    installs
  54. Subfinder · timsonner
    Use for fast passive subdomain enumeration during authorized external reconnaissance. Trigger on internet-facing scope, domain seed lists, public exposure review, and subdomain inventory validation.
    0
    installs
  55. Wireshark · timsonner
    Use for packet-level protocol review, detection visibility checks, and troubleshooting during authorized pentests. Trigger on validating network observations, confirming cleartext exposure, and comparing attacker activity to available telemetry.
    0
    installs
  56. Configure · timsonner
    Configuration instructions for OpenCode - how to set up LLM providers and API keys
    0
    installs
  57. Configure Rules · timsonner
    Configuration for OpenCode rules - defining custom instructions and behaviors for the AI agent
    0
    installs
  58. Configure Tools · timsonner
    Configuration for OpenCode tools - managing tool permissions and built-in tools like bash, edit, write, read, etc.
    0
    installs
  59. Troubleshooting · timsonner
    Troubleshooting instructions for OpenCode - common issues and solutions
    0
    installs
  60. Bloodhound · timsonner
    Use for Active Directory relationship analysis during authorized internal assessments. Trigger on AD path mapping, privilege chain review, delegated access analysis, and understanding how directory relationships affect attacker movement.
    0
    installs
  61. Burp Suite · timsonner
    Use for manual web and API testing, authenticated workflow review, request replay, and controlled validation during authorized pentests. Trigger on session handling, authorization checks, business logic review, and proof of impact for web findings.
    0
    installs
  62. Evil Winrm · timsonner
    Use for controlled WinRM access validation during authorized internal pentests. Trigger on approved administrative workflow review, WinRM boundary checks, and validating whether an authorized credential can reach a specific Windows host.
    0
    installs
  63. Kube Bench · timsonner
    Use for Kubernetes CIS benchmark review during authorized pentests. Trigger on cluster hardening assessment, node and control-plane configuration review, and validating whether a Kubernetes environment meets baseline security expectations.
    0
    installs
  64. Ldapsearch · timsonner
    Use for LDAP and directory service enumeration during authorized internal assessments. Trigger on identity store review, rootDSE checks, naming context discovery, and validating directory exposure with approved credentials.
    0
    installs
  65. Scoutsuite · timsonner
    Use for cloud posture review across AWS, Azure, and GCP during authorized pentests. Trigger on control-plane inventory, exposed service review, identity analysis, and producing a structured view of cloud configuration risk.
    0
    installs
  66. Sharphound · timsonner
    Use for Active Directory graph collection during authorized pentests. Trigger on approved AD relationship mapping, privilege-path review, local admin exposure review, and generating focused data for BloodHound analysis.
    0
    installs
  67. Testssl Sh · timsonner
    Use for TLS and certificate posture review during authorized pentests. Trigger on checking protocol support, cipher posture, certificate hygiene, and internet-facing HTTPS hardening gaps.
    0
    installs
  68. Trufflehog · timsonner
    Use for repository, filesystem, and remote source secret discovery during authorized pentests. Trigger on secret hunting, token exposure review, and validating whether approved code or history contains material credential leakage.
    0
    installs
  69. Configure Agents · timsonner
    Configuration for OpenCode agents - defining and customizing AI agent behaviors and capabilities
    0
    installs
  70. Configure Models · timsonner
    Configuration for OpenCode models - selecting and configuring LLM providers and specific models
    0
    installs
  71. Configure Skills · timsonner
    Configuration for OpenCode skills - managing and configuring agent skills for reusable behaviors
    0
    installs
  72. Configure Themes · timsonner
    Configuration for OpenCode themes - customizing the visual appearance of the TUI and desktop app
    0
    installs
  73. Feroxbuster · timsonner
    Use for recursive web content discovery during authorized pentests. Trigger on hidden directory discovery, route enumeration, controlled recursion, and fast CLI coverage of approved web targets.
    0
    installs
  74. Kube Hunter · timsonner
    Use for Kubernetes exposure and attack-surface review during authorized pentests. Trigger on cluster endpoint discovery, Kubernetes service exposure analysis, and validating whether a cluster presents remotely reachable weaknesses.
    0
    installs
  75. Onesixtyone · timsonner
    Use for lightweight SNMP community-string validation during authorized pentests. Trigger on quick SNMP exposure checks, network device discovery, and validating whether approved devices accept known or bounded community strings.
    0
    installs
  76. Proxychains · timsonner
    Use for routing approved tools through a bounded proxy path during authorized pentests. Trigger on approved pivot-path testing, segmented service validation, and ensuring a specific tool uses the intended proxy or SOCKS route.
    0
    installs
  77. Searchsploit · timsonner
    Use for exploit and vulnerability reference research during authorized pentests. Trigger on confirmed product versions, CVE review, exploitability triage, and mapping known issues to observed services without running exploit code.
    0
    installs
  78. Theharvester · timsonner
    Use for passive OSINT collection during authorized pentests. Trigger on email, domain, subdomain, and public-source metadata gathering to seed recon without active target interaction.
    0
    installs
  79. Configure Commands · timsonner
    Configuration for OpenCode custom commands - creating and managing custom slash commands for repetitive tasks
    0
    installs
  80. Configure Keybinds · timsonner
    Configuration for OpenCode keybinds - customizing keyboard shortcuts for the TUI and desktop app
    0
    installs
  81. Usage Add Features · timsonner
    How to use OpenCode to add new features to your project - planning, iterating, and building with AI assistance
    0
    installs
  82. Usage Make Changes · timsonner
    How to use OpenCode to make direct changes to your codebase - straightforward modifications and refactoring
    0
    installs
  83. Usage Undo Changes · timsonner
    How to undo and redo changes made by OpenCode - reverting modifications and recovering work
    0
    installs
  84. Enum4linux Ng · timsonner
    Use for SMB and Windows host enumeration during authorized internal assessments. Trigger on Windows file sharing, workgroup or domain discovery, user and share review, and validating internal attack surface assumptions.
    0
    installs
  85. Usage Ask Questions · timsonner
    How to ask OpenCode questions about your codebase - using context, file references, and effective questioning techniques
    0
    installs
  86. Ldapdomaindump · timsonner
    Use for structured Active Directory LDAP inventory during authorized internal pentests. Trigger on approved domain mapping, directory object review, and generating a focused picture of groups, users, and trust relationships.
    0
    installs
  87. Tool Selection · timsonner
    Select pentest tools by methodology phase, target type, and risk tolerance. Use for deciding whether to use amass, subfinder, nmap, owasp-zap, wfuzz, dirb, dnsrecon, netcat, linpeas, winpeas, metasploit-framework, and related tools during authorized assessments.
    0
    installs
  88. Configure Formatters · timsonner
    Configuration for OpenCode formatters - setting up and customizing code formatters for different languages
    0
    installs
  89. Impacket Psexec · timsonner
    Use for tightly scoped remote execution validation over SMB during authorized internal pentests. Trigger on approved administrative boundary checks, service-creation path review, and confirming whether a specific credential can execute on a specific Windows host.
    0
    installs
  90. John The Ripper · timsonner
    Use for offline password hash auditing during authorized pentests. Trigger on approved hash review, password policy validation, and measuring credential resilience without online authentication attempts.
    0
    installs
  91. Proxmox System Administration · timsonner
    Use when operating a Proxmox VE host with least-privilege workflows, reusable VM templates, and auditable hardening.
    0
    installs
  92. Configure Permissions · timsonner
    Configuration for OpenCode permissions - controlling which actions require approval to run
    0
    installs
  93. Impacket Smbexec · timsonner
    Use for tightly scoped SMB-based remote command validation during authorized internal pentests. Trigger on approved execution-boundary checks and confirming whether a specific credential can execute commands on a specific Windows host over SMB.
    0
    installs
  94. Impacket Wmiexec · timsonner
    Use for tightly scoped WMI-based remote execution validation during authorized internal pentests. Trigger on approved Windows management boundary checks and verifying whether a specific credential can execute on a specific host through WMI.
    0
    installs
  95. Configure Custom Tools · timsonner
    Configuration for OpenCode custom tools - creating and managing tools that the LLM can call during conversations
    0
    installs
  96. Impacket Lookupsid · timsonner
    Use for SID and domain object enumeration during authorized internal pentests. Trigger on approved domain metadata review, account discovery validation, and understanding what a target reveals about identities over RPC.
    0
    installs
  97. Impacket Getnpusers · timsonner
    Use for AS-REP roasting exposure review during authorized internal pentests. Trigger on Kerberos preauthentication analysis, user account posture review, and validating whether specific accounts create offline password risk.
    0
    installs
  98. Impacket Ntlmrelayx · timsonner
    Use for tightly controlled NTLM relay validation during authorized internal pentests. Trigger on approved relay-path assessment, protocol hardening review, and confirming whether a captured authentication flow can be relayed to a specific approved target.
    0
    installs
  99. Impacket Getuserspns · timsonner
    Use for SPN enumeration and Kerberoasting exposure review during authorized internal pentests. Trigger on service account analysis, Kerberos posture review, and validating whether SPN-bearing accounts create practical password risk.
    0
    installs
  100. Impacket Secretsdump · timsonner
    Use for tightly scoped credential-material validation during authorized internal pentests. Trigger on approved LSASS, SAM, or NTDS exposure review, privilege-boundary checks, and confirming whether a specific credential path can access sensitive authentication material.
    0
    installs