timsonner
- 172 skills
- 0 followers
- 11 hours ago last updated
- ▌ Metasploit Framework · timsonnerUse for controlled auxiliary scanning, exploit research, and narrowly bounded validation during authorized pentests. Trigger on approved module-driven checks, repeatable proof paths, and situations where a framework-managed workflow is safer than ad hoc execution.
- ▌ Linux Exploit Suggester · timsonnerUse for Linux kernel and local-exposure suggestion review during authorized pentests. Trigger on approved Linux host analysis, kernel-version triage, and identifying which local privilege-escalation vectors may merit manual validation.
- ▌ Podman · timsonnerUse when creating, running, exec'ing, composing, or tearing down Podman containers on this host (incl. Cockpit). Prefer Podman over Docker for new work; never confuse with libvirt VMs.
- ▌
- ▌ Agy Harness · timsonnerDrive the Antigravity (Gemini) CLI (`agy` / `agy.exe`) from another agent: winget install, one-shot --print, continue conversations, models. Triggers: "/agy-harness", agy, antigravity, gemini cli.
- ▌ Copilot Python Sdk · timsonnerPython SDK for programmatic control of GitHub Copilot CLI via JSON-RPC
- ▌
- ▌ Sdk · timsonnerOpenCode SDK - how to extend and customize OpenCode using the software development kit
- ▌ Tui · timsonnerTerminal User Interface (TUI) instructions for OpenCode - how to navigate and use the OpenCode TUI
- ▌ Codex Harness · timsonnerDrive the OpenAI Codex CLI (`codex` / `codex exec`) from another agent: official Windows installer, one-shot exec --json, resume, sandbox. Triggers: "/codex-harness", Codex CLI, codex exec.
- ▌ Pentest Tools Reference · timsonnerComprehensive reference for penetration testing tools available in Kali Linux including network scanners, web application testing tools, exploitation tools, password attacks, network tools, enumeration tools, privilege escalation tools, utility commands, DNS tools, wordlists, tool combinations, common flags, installation references, and attribution guidelines.
- ▌ Defender Opsec · timsonnerHarden Windows Defender privacy settings for authorized pentest engagements. Disables telemetry uploads, sample submission, and cloud reporting to prevent leaking target info, credentials, and tooling to Microsoft. Includes exclusion management and post-engagement re-enablement.
- ▌ Drive Hyprland · timsonner bundleDrive a live Hyprland desktop on the local Linux session: list and focus windows, switch workspaces, move the cursor, click (ydotool), type (wtype), screenshot, and open URLs. Use when the user wants to click around the desktop, switch workspace, focus an app, type into a window, take a window screenshot, open a site, navigate the compositor, or runs /drive-hyprland. Not for editing Hyprland config. Not the Windows/RDP workstation-drive loop.
- ▌ Hermes Harness · timsonnerDrive the Nous Hermes Agent CLI (`hermes`) from another agent: official install.ps1, one-shot -z / chat -q -Q, resume, --yolo, ACP/MCP. Triggers: "/hermes-harness", Hermes CLI, hermes -z, Nous Research hermes.
- ▌
- ▌
- ▌ Usage · timsonnerUsage instructions for OpenCode - how to ask questions, add features, make changes, and undo changes
- ▌ Wsl Containers · timsonner bundleBuild, run, debug, and publish Linux containers with Microsoft wslc on Windows (no Docker Desktop). Covers wslc CLI, no commit (export/import), DNS/apt, Hub and ghcr.io publish, system session / privileged, and Microsoft.WSL.Containers API. Use when: wslc, wslc.exe, WSL containers, wsl-containers, wslc-containers, "/wslc-containers", "/wsl-containers", ghcr.io login with wslc.
- ▌ Copilot Harness · timsonner bundleDrive the GitHub Copilot CLI (`copilot` / `copilot.exe`) from another agent: winget install, one-shot -p/--prompt, continue/resume sessions, models, skills. Triggers: "/copilot-harness", GitHub Copilot CLI, copilot -p, copilot.exe.
- ▌ Harness Offload · timsonner bundleOffload one bounded job to agy, opencode, copilot, codex, or hermes via a shared contract (worker, dir, prompt, allow_tools, session). Use when the host agent should hand a task to another CLI and get back session_id + stdout. Triggers: "/harness-offload", offload contract, Invoke-HarnessOffload.
- ▌ Kde Wayland Rdp · timsonner bundleHeadless KDE Plasma on kwin_wayland --virtual with KRdp (not xrdp/X11). Use when packaging or debugging latest Plasma 6.7+ Wayland remote desktop in a container: kwin virtual OpenGL vs QPainter, vgem/DRM nodes, wslc seccomp EPERM on /dev/dri, KWIN_COMPOSE=O2, KRdp --plasma --virtual-monitor, mstsc CredSSP + FreeRDP NetworkAutoDetect RTT drop, PipeWire screencast "Unsupported compositing type", titlebar close/min/drag opening Kickoff (fake_input pointer at 0,0). Companion client: windows-ui-inject. GNOME/GRD: gnome-wayland-rdp. Plasma+xrdp: linux-desktop-rdp-container. Triggers: "/kde-wayland-rdp", "/kde-wayland-container", "latest KDE Wayland", "KRdp", "kwin_wayland --virtual".
- ▌ Server · timsonnerOpenCode Server - how to run and manage the OpenCode server for API access and integrations
- ▌ Opencode Harness · timsonnerDrive the OpenCode CLI (`opencode`) from another agent or terminal: install, one-shot `opencode run`, TUI, models (including opencode/big-pickle), agents. Windows winget SST.opencode. Triggers: "/opencode-harness", opencode, big pickle.
- ▌ Install · timsonnerInstallation instructions for OpenCode - various methods including script, Node.js, Homebrew, Arch Linux, and Windows
- ▌ Network · timsonnerNetwork configuration for OpenCode - proxy settings, network troubleshooting, and connectivity options
- ▌ Plugins · timsonnerOpenCode Plugins - how to find, install, and use plugins to extend OpenCode functionality
- ▌ Windows · timsonnerWindows-specific instructions for OpenCode - installation and usage on Windows systems
- ▌ Gnome Wayland Rdp · timsonner bundleHeadless GNOME Shell on Wayland with gnome-remote-desktop (GRD) for RDP — the GDM/GNOME-native path (not xrdp/X11). Use when packaging or debugging GNOME 46+ (especially 50+) remote desktop in a container or lab VM: gnome-shell --wayland --headless, grdctl --headless, PipeWire streams, FUSE clipboard aborts, black RDP after Connect, session bus races, Azure Linux or Fedora-sourced GNOME RPMs, or when xrdp cannot run GNOME because --x11 is gone. Companion client UI: skill windows-ui-inject. Latest Plasma Wayland + KRdp: skill kde-wayland-rdp. X11/XFCE/Plasma+xrdp: skill linux-desktop-rdp-container.
- ▌ Usage Go · timsonnerUsing OpenCode with Go projects - specific workflows and tips for Go development
- ▌ Windows UI Inject · timsonner bundleInject mouse and keyboard input on Windows via PowerShell and user32 when computer-use is screenshot-only (tier "read") or when driving non-browser UI such as mstsc RDP dialogs. Use for Edge/Chrome/Firefox navigation under read-only browser grants, "granted at tier read", Claude-in-Chrome disconnected, Remote Desktop Connection security/credentials dialogs, Connect vs Learn more, or any frontmost non-elevated window that screenshots can see but MCP cannot click. Triggers: "/windows-ui-inject", "windows-ui-inject", "browser-read-bypass", "/browser-read-bypass", user32, mstsc Connect.
- ▌ Customize · timsonnerCustomization instructions for OpenCode - how to pick themes, customize keybinds, configure formatters, create custom commands, and modify OpenCode config
- ▌ Ecosystem · timsonnerOpenCode Ecosystem - tools, integrations, and community resources surrounding OpenCode
- ▌ Providers · timsonnerLLM provider configuration for OpenCode - how to set up and use different language model providers
- ▌ Usage Ide · timsonnerUsing OpenCode with IDE extensions - VS Code, JetBrains, and other editor integrations
- ▌ Usage Tui · timsonnerUsing OpenCode's Terminal User Interface (TUI) - navigation, modes, and productivity tips
- ▌ Usage Web · timsonnerUsing OpenCode for web development - HTML, CSS, JavaScript, and frontend frameworks
- ▌
- ▌ 7zip · timsonnerUse for tightly scoped archive creation, compression, and packaging during authorized pentests. Trigger on approved evidence packaging, transfer-size reduction, and validating whether archive controls or DLP-related assumptions affect the assessment.
- ▌ Curl · timsonnerUse for HTTP, HTTPS, and data-transfer validation during authorized pentests. Trigger on controlled request replay, header inspection, API debugging, and limited staging or retrieval checks against approved endpoints.
- ▌ Dirb · timsonnerUse for classic directory and file brute forcing during authorized web assessments. Trigger on hidden content discovery, low-complexity web path review, and quick coverage of approved web targets with conservative wordlists.
- ▌ Ffuf · timsonnerUse for controlled web content discovery, endpoint enumeration, and narrow retest of hidden routes during authorized pentests. Trigger on finding directories, files, API routes, and admin paths within approved web scope.
- ▌ Nmap · timsonnerUse for network discovery, service enumeration, exposure verification, and narrow retesting during authorized pentests. Trigger on identifying live hosts, open ports, service banners, remote administration paths, and segmentation assumptions.
- ▌ Pacu · timsonnerUse for AWS-focused adversary simulation and control-plane validation during authorized pentests. Trigger on approved AWS privilege path review, service-specific assessment, and understanding what an authorized AWS principal can realistically do.
- ▌ Pspy · timsonnerUse for process and cron monitoring during authorized Linux pentests. Trigger on observing privileged task execution, identifying command paths for escalation hypotheses, and validating whether scheduled or transient processes create practical local attack paths.
- ▌ Browser Read Bypass · timsonnerAlias for windows-ui-inject. Inject mouse and keyboard on Windows via user32 when computer-use is screenshot-only or when driving mstsc. Triggers: "/browser-read-bypass", browser-read-bypass.
- ▌ Buzz Hermes Gateway · timsonnerUse when connecting Hermes Agent gateway to a Block Buzz community (CLI, allowlist/hex, env load, mention rules).
- ▌ Enterprise · timsonnerEnterprise features and configuration for OpenCode - team deployment, security, and administration
- ▌
- ▌ Pentest Methodology · timsonnerComprehensive penetration testing workflow using Kali Linux tools via MCP. Guides agents through reconnaissance, vulnerability assessment, exploitation, privilege escalation, and reporting. Use when conducting security assessments, CTF challenges, vulnerability testing, or red team exercises.
- ▌ Amass · timsonnerUse for external asset discovery, subdomain mapping, and ownership-focused reconnaissance during authorized pentests. Trigger on internet-facing scope, domain inventory gaps, external attack surface mapping, and domain relationship review.
- ▌ Httpx · timsonnerUse for HTTP service probing, web asset confirmation, technology hints, and endpoint inventory during authorized pentests. Trigger on checking which hosts answer HTTP or HTTPS, identifying admin panels, and building a web testing queue.
- ▌ Hydra · timsonnerUse for tightly scoped credential validation during authorized pentests. Trigger on approved login checks, low-rate credential hypothesis testing, and confirming whether a specific service accepts a known or narrowly bounded credential set.
- ▌ Mitm6 · timsonnerUse for IPv6 and WPAD-related name-resolution assessment during authorized internal pentests. Trigger on approved relay-path testing, identity exposure review, and measuring whether IPv6 behavior enables credential risk.
- ▌ Nikto · timsonnerUse for web server misconfiguration review and broad HTTP hygiene checks during authorized pentests. Trigger on internet-facing web services, default content, risky headers, and server-side hardening gaps.
- ▌ Plink · timsonnerUse for tightly scoped SSH-based port forwarding and remote access validation during authorized pentests. Trigger on approved reachability checks, local or remote port-forward review, and proving whether a named pivot path is technically possible.
- ▌ Socat · timsonnerUse for tightly scoped socket relays, port forwarding, and protocol bridging during authorized pentests. Trigger on approved path testing, local-to-remote forwarding, and validating whether a named connectivity path can be bridged safely.
- ▌ Trivy · timsonnerUse for container, filesystem, and IaC review during authorized pentests. Trigger on image assessment, dependency and configuration review, Kubernetes manifest checks, and identifying exposure that affects deployed workloads.
- ▌ Wfuzz · timsonnerUse for web content, parameter, and header fuzzing during authorized pentests. Trigger on hidden endpoint discovery, parameter discovery, virtual host testing, and controlled input variation during web and API assessments.
- ▌ Proxmox Vm Recovery · timsonnerHandles troubleshooting and recovery of virtual machines (VMs) stuck during boot on Proxmox VE hosts. Activate this skill when a user reports a VM (especially Windows 11/UEFI guest) failing to boot, hanging at the OVMF logo, or showing "Start boot option" loading screens.
- ▌ Read Canvas Browser · timsonnerUse this skill when browser text and accessibility tools fail because the page renders content in a canvas and you need to inspect or interact with it visually.
- ▌ Buzz Relay Self Host · timsonner bundleUse when self-hosting Block Buzz, mobile pairing, Hermes gateway, or always-on buzz-acp agents.
- ▌ Adfind · timsonnerUse for focused Active Directory object enumeration during authorized pentests. Trigger on approved user, group, computer, and trust review, LDAP-backed metadata collection, and validating domain assumptions with low-impact queries.
- ▌ Az CLI · timsonnerUse for Azure control-plane validation during authorized pentests. Trigger on credentialed Azure review, role and subscription checks, storage exposure review, and verifying what an approved Azure identity can access.
- ▌ Chisel · timsonnerUse for tightly scoped tunneling and SOCKS or port-forward validation during authorized pentests. Trigger on approved network path testing, segmented service reachability review, and confirming whether a specific pivot path is technically possible.
- ▌ Commix · timsonnerUse for controlled command-injection validation during authorized web and API assessments. Trigger on manually triaged injection candidates, request replay validation, and narrow retests where the least invasive proof path is required.
- ▌ Dalfox · timsonnerUse for tightly scoped XSS validation during authorized web assessments. Trigger on reflected or stored XSS candidate triage, payload verification, and repeatable retest of confirmed cross-site scripting weaknesses.
- ▌ Gcloud · timsonnerUse for GCP control-plane validation during authorized pentests. Trigger on credentialed Google Cloud review, project and IAM scope checks, storage exposure review, and verifying what an approved identity can access.
- ▌ Nessus · timsonnerUse for credentialed or non-credentialed vulnerability scanning during authorized pentests. Trigger on baseline exposure review, broad host hygiene assessment, and producing scanner-led coverage that still requires analyst triage and validation.
- ▌ Netcat · timsonnerUse for basic TCP or UDP connectivity, banner grabbing, listener setup, and controlled data-path validation during authorized pentests. Trigger on socket testing, simple transfer checks, and proving whether a specific network path is reachable.
- ▌ Nuclei · timsonnerUse for templated vulnerability checks, exposure validation, and misconfiguration review during authorized pentests. Trigger on confirming likely web, network, or cloud exposures after discovery has narrowed the target set.
- ▌ Rclone · timsonnerUse for tightly scoped file transfer and cloud-storage access validation during authorized pentests. Trigger on approved exfiltration-path simulation, storage exposure review, and determining whether a specific path allows unauthorized bulk transfer.
- ▌ Rubeus · timsonnerUse for tightly scoped Kerberos ticket and account validation during authorized pentests. Trigger on approved ticket analysis, Kerberos exposure review, and proving whether a specific account or host permits unsafe ticket operations.