← all publishers

timsonner

@timsonner source repo

172 published skills · page 2 of 2

  1. Metasploit Framework · timsonner
    Use for controlled auxiliary scanning, exploit research, and narrowly bounded validation during authorized pentests. Trigger on approved module-driven checks, repeatable proof paths, and situations where a framework-managed workflow is safer than ad hoc execution.
    0
    installs
  2. Linux Exploit Suggester · timsonner
    Use for Linux kernel and local-exposure suggestion review during authorized pentests. Trigger on approved Linux host analysis, kernel-version triage, and identifying which local privilege-escalation vectors may merit manual validation.
    0
    installs
  3. Podman · timsonner
    Use when creating, running, exec'ing, composing, or tearing down Podman containers on this host (incl. Cockpit). Prefer Podman over Docker for new work; never confuse with libvirt VMs.
    0
    installs
  4. MCP Server · timsonner
    Specification for building Model Context Protocol servers using Python
    0
    installs
  5. Agy Harness · timsonner
    Drive the Antigravity (Gemini) CLI (`agy` / `agy.exe`) from another agent: winget install, one-shot --print, continue conversations, models. Triggers: "/agy-harness", agy, antigravity, gemini cli.
    0
    installs
  6. Copilot Python Sdk · timsonner
    Python SDK for programmatic control of GitHub Copilot CLI via JSON-RPC
    0
    installs
  7. Go · timsonner
    Go language support in OpenCode - how to work with Go projects using OpenCode
    0
    installs
  8. Sdk · timsonner
    OpenCode SDK - how to extend and customize OpenCode using the software development kit
    0
    installs
  9. Tui · timsonner
    Terminal User Interface (TUI) instructions for OpenCode - how to navigate and use the OpenCode TUI
    0
    installs
  10. Codex Harness · timsonner
    Drive the OpenAI Codex CLI (`codex` / `codex exec`) from another agent: official Windows installer, one-shot exec --json, resume, sandbox. Triggers: "/codex-harness", Codex CLI, codex exec.
    0
    installs
  11. Pentest Tools Reference · timsonner
    Comprehensive reference for penetration testing tools available in Kali Linux including network scanners, web application testing tools, exploitation tools, password attacks, network tools, enumeration tools, privilege escalation tools, utility commands, DNS tools, wordlists, tool combinations, common flags, installation references, and attribution guidelines.
    0
    installs
  12. Defender Opsec · timsonner
    Harden Windows Defender privacy settings for authorized pentest engagements. Disables telemetry uploads, sample submission, and cloud reporting to prevent leaking target info, credentials, and tooling to Microsoft. Includes exclusion management and post-engagement re-enablement.
    0
    installs
  13. Drive Hyprland · timsonner bundle
    Drive a live Hyprland desktop on the local Linux session: list and focus windows, switch workspaces, move the cursor, click (ydotool), type (wtype), screenshot, and open URLs. Use when the user wants to click around the desktop, switch workspace, focus an app, type into a window, take a window screenshot, open a site, navigate the compositor, or runs /drive-hyprland. Not for editing Hyprland config. Not the Windows/RDP workstation-drive loop.
    0
    installs
  14. Hermes Harness · timsonner
    Drive the Nous Hermes Agent CLI (`hermes`) from another agent: official install.ps1, one-shot -z / chat -q -Q, resume, --yolo, ACP/MCP. Triggers: "/hermes-harness", Hermes CLI, hermes -z, Nous Research hermes.
    0
    installs
  15. Intro · timsonner
    Introduction to OpenCode - overview of what OpenCode is and how to get started
    0
    installs
  16. Share · timsonner
    Sharing instructions for OpenCode - how to share conversations with your team
    0
    installs
  17. Usage · timsonner
    Usage instructions for OpenCode - how to ask questions, add features, make changes, and undo changes
    0
    installs
  18. Wsl Containers · timsonner bundle
    Build, run, debug, and publish Linux containers with Microsoft wslc on Windows (no Docker Desktop). Covers wslc CLI, no commit (export/import), DNS/apt, Hub and ghcr.io publish, system session / privileged, and Microsoft.WSL.Containers API. Use when: wslc, wslc.exe, WSL containers, wsl-containers, wslc-containers, "/wslc-containers", "/wsl-containers", ghcr.io login with wslc.
    0
    installs
  19. Copilot Harness · timsonner bundle
    Drive the GitHub Copilot CLI (`copilot` / `copilot.exe`) from another agent: winget install, one-shot -p/--prompt, continue/resume sessions, models, skills. Triggers: "/copilot-harness", GitHub Copilot CLI, copilot -p, copilot.exe.
    0
    installs
  20. Harness Offload · timsonner bundle
    Offload one bounded job to agy, opencode, copilot, codex, or hermes via a shared contract (worker, dir, prompt, allow_tools, session). Use when the host agent should hand a task to another CLI and get back session_id + stdout. Triggers: "/harness-offload", offload contract, Invoke-HarnessOffload.
    0
    installs
  21. Kde Wayland Rdp · timsonner bundle
    Headless KDE Plasma on kwin_wayland --virtual with KRdp (not xrdp/X11). Use when packaging or debugging latest Plasma 6.7+ Wayland remote desktop in a container: kwin virtual OpenGL vs QPainter, vgem/DRM nodes, wslc seccomp EPERM on /dev/dri, KWIN_COMPOSE=O2, KRdp --plasma --virtual-monitor, mstsc CredSSP + FreeRDP NetworkAutoDetect RTT drop, PipeWire screencast "Unsupported compositing type", titlebar close/min/drag opening Kickoff (fake_input pointer at 0,0). Companion client: windows-ui-inject. GNOME/GRD: gnome-wayland-rdp. Plasma+xrdp: linux-desktop-rdp-container. Triggers: "/kde-wayland-rdp", "/kde-wayland-container", "latest KDE Wayland", "KRdp", "kwin_wayland --virtual".
    0
    installs
  22. Server · timsonner
    OpenCode Server - how to run and manage the OpenCode server for API access and integrations
    0
    installs
  23. Opencode Harness · timsonner
    Drive the OpenCode CLI (`opencode`) from another agent or terminal: install, one-shot `opencode run`, TUI, models (including opencode/big-pickle), agents. Windows winget SST.opencode. Triggers: "/opencode-harness", opencode, big pickle.
    0
    installs
  24. Install · timsonner
    Installation instructions for OpenCode - various methods including script, Node.js, Homebrew, Arch Linux, and Windows
    0
    installs
  25. Network · timsonner
    Network configuration for OpenCode - proxy settings, network troubleshooting, and connectivity options
    0
    installs
  26. Plugins · timsonner
    OpenCode Plugins - how to find, install, and use plugins to extend OpenCode functionality
    0
    installs
  27. Windows · timsonner
    Windows-specific instructions for OpenCode - installation and usage on Windows systems
    0
    installs
  28. Gnome Wayland Rdp · timsonner bundle
    Headless GNOME Shell on Wayland with gnome-remote-desktop (GRD) for RDP — the GDM/GNOME-native path (not xrdp/X11). Use when packaging or debugging GNOME 46+ (especially 50+) remote desktop in a container or lab VM: gnome-shell --wayland --headless, grdctl --headless, PipeWire streams, FUSE clipboard aborts, black RDP after Connect, session bus races, Azure Linux or Fedora-sourced GNOME RPMs, or when xrdp cannot run GNOME because --x11 is gone. Companion client UI: skill windows-ui-inject. Latest Plasma Wayland + KRdp: skill kde-wayland-rdp. X11/XFCE/Plasma+xrdp: skill linux-desktop-rdp-container.
    0
    installs
  29. Usage Go · timsonner
    Using OpenCode with Go projects - specific workflows and tips for Go development
    0
    installs
  30. Windows UI Inject · timsonner bundle
    Inject mouse and keyboard input on Windows via PowerShell and user32 when computer-use is screenshot-only (tier "read") or when driving non-browser UI such as mstsc RDP dialogs. Use for Edge/Chrome/Firefox navigation under read-only browser grants, "granted at tier read", Claude-in-Chrome disconnected, Remote Desktop Connection security/credentials dialogs, Connect vs Learn more, or any frontmost non-elevated window that screenshots can see but MCP cannot click. Triggers: "/windows-ui-inject", "windows-ui-inject", "browser-read-bypass", "/browser-read-bypass", user32, mstsc Connect.
    0
    installs
  31. Customize · timsonner
    Customization instructions for OpenCode - how to pick themes, customize keybinds, configure formatters, create custom commands, and modify OpenCode config
    0
    installs
  32. Ecosystem · timsonner
    OpenCode Ecosystem - tools, integrations, and community resources surrounding OpenCode
    0
    installs
  33. Providers · timsonner
    LLM provider configuration for OpenCode - how to set up and use different language model providers
    0
    installs
  34. Usage Ide · timsonner
    Using OpenCode with IDE extensions - VS Code, JetBrains, and other editor integrations
    0
    installs
  35. Usage Tui · timsonner
    Using OpenCode's Terminal User Interface (TUI) - navigation, modes, and productivity tips
    0
    installs
  36. Usage Web · timsonner
    Using OpenCode for web development - HTML, CSS, JavaScript, and frontend frameworks
    0
    installs
  37. Usage Zen · timsonner
    Using OpenCode Zen - curated list of tested and verified LLM models
    0
    installs
  38. 7zip · timsonner
    Use for tightly scoped archive creation, compression, and packaging during authorized pentests. Trigger on approved evidence packaging, transfer-size reduction, and validating whether archive controls or DLP-related assumptions affect the assessment.
    0
    installs
  39. Curl · timsonner
    Use for HTTP, HTTPS, and data-transfer validation during authorized pentests. Trigger on controlled request replay, header inspection, API debugging, and limited staging or retrieval checks against approved endpoints.
    0
    installs
  40. Dirb · timsonner
    Use for classic directory and file brute forcing during authorized web assessments. Trigger on hidden content discovery, low-complexity web path review, and quick coverage of approved web targets with conservative wordlists.
    0
    installs
  41. Ffuf · timsonner
    Use for controlled web content discovery, endpoint enumeration, and narrow retest of hidden routes during authorized pentests. Trigger on finding directories, files, API routes, and admin paths within approved web scope.
    0
    installs
  42. Nmap · timsonner
    Use for network discovery, service enumeration, exposure verification, and narrow retesting during authorized pentests. Trigger on identifying live hosts, open ports, service banners, remote administration paths, and segmentation assumptions.
    0
    installs
  43. Pacu · timsonner
    Use for AWS-focused adversary simulation and control-plane validation during authorized pentests. Trigger on approved AWS privilege path review, service-specific assessment, and understanding what an authorized AWS principal can realistically do.
    0
    installs
  44. Pspy · timsonner
    Use for process and cron monitoring during authorized Linux pentests. Trigger on observing privileged task execution, identifying command paths for escalation hypotheses, and validating whether scheduled or transient processes create practical local attack paths.
    0
    installs
  45. Browser Read Bypass · timsonner
    Alias for windows-ui-inject. Inject mouse and keyboard on Windows via user32 when computer-use is screenshot-only or when driving mstsc. Triggers: "/browser-read-bypass", browser-read-bypass.
    0
    installs
  46. Buzz Hermes Gateway · timsonner
    Use when connecting Hermes Agent gateway to a Block Buzz community (CLI, allowlist/hex, env load, mention rules).
    0
    installs
  47. Enterprise · timsonner
    Enterprise features and configuration for OpenCode - team deployment, security, and administration
    0
    installs
  48. Initialize · timsonner
    Initialize
    0
    installs
  49. Pentest Methodology · timsonner
    Comprehensive penetration testing workflow using Kali Linux tools via MCP. Guides agents through reconnaissance, vulnerability assessment, exploitation, privilege escalation, and reporting. Use when conducting security assessments, CTF challenges, vulnerability testing, or red team exercises.
    0
    installs
  50. Amass · timsonner
    Use for external asset discovery, subdomain mapping, and ownership-focused reconnaissance during authorized pentests. Trigger on internet-facing scope, domain inventory gaps, external attack surface mapping, and domain relationship review.
    0
    installs
  51. Httpx · timsonner
    Use for HTTP service probing, web asset confirmation, technology hints, and endpoint inventory during authorized pentests. Trigger on checking which hosts answer HTTP or HTTPS, identifying admin panels, and building a web testing queue.
    0
    installs
  52. Hydra · timsonner
    Use for tightly scoped credential validation during authorized pentests. Trigger on approved login checks, low-rate credential hypothesis testing, and confirming whether a specific service accepts a known or narrowly bounded credential set.
    0
    installs
  53. Mitm6 · timsonner
    Use for IPv6 and WPAD-related name-resolution assessment during authorized internal pentests. Trigger on approved relay-path testing, identity exposure review, and measuring whether IPv6 behavior enables credential risk.
    0
    installs
  54. Nikto · timsonner
    Use for web server misconfiguration review and broad HTTP hygiene checks during authorized pentests. Trigger on internet-facing web services, default content, risky headers, and server-side hardening gaps.
    0
    installs
  55. Plink · timsonner
    Use for tightly scoped SSH-based port forwarding and remote access validation during authorized pentests. Trigger on approved reachability checks, local or remote port-forward review, and proving whether a named pivot path is technically possible.
    0
    installs
  56. Socat · timsonner
    Use for tightly scoped socket relays, port forwarding, and protocol bridging during authorized pentests. Trigger on approved path testing, local-to-remote forwarding, and validating whether a named connectivity path can be bridged safely.
    0
    installs
  57. Trivy · timsonner
    Use for container, filesystem, and IaC review during authorized pentests. Trigger on image assessment, dependency and configuration review, Kubernetes manifest checks, and identifying exposure that affects deployed workloads.
    0
    installs
  58. Wfuzz · timsonner
    Use for web content, parameter, and header fuzzing during authorized pentests. Trigger on hidden endpoint discovery, parameter discovery, virtual host testing, and controlled input variation during web and API assessments.
    0
    installs
  59. Proxmox Vm Recovery · timsonner
    Handles troubleshooting and recovery of virtual machines (VMs) stuck during boot on Proxmox VE hosts. Activate this skill when a user reports a VM (especially Windows 11/UEFI guest) failing to boot, hanging at the OVMF logo, or showing "Start boot option" loading screens.
    0
    installs
  60. Read Canvas Browser · timsonner
    Use this skill when browser text and accessibility tools fail because the page renders content in a canvas and you need to inspect or interact with it visually.
    0
    installs
  61. Buzz Relay Self Host · timsonner bundle
    Use when self-hosting Block Buzz, mobile pairing, Hermes gateway, or always-on buzz-acp agents.
    0
    installs
  62. Adfind · timsonner
    Use for focused Active Directory object enumeration during authorized pentests. Trigger on approved user, group, computer, and trust review, LDAP-backed metadata collection, and validating domain assumptions with low-impact queries.
    0
    installs
  63. Az CLI · timsonner
    Use for Azure control-plane validation during authorized pentests. Trigger on credentialed Azure review, role and subscription checks, storage exposure review, and verifying what an approved Azure identity can access.
    0
    installs
  64. Chisel · timsonner
    Use for tightly scoped tunneling and SOCKS or port-forward validation during authorized pentests. Trigger on approved network path testing, segmented service reachability review, and confirming whether a specific pivot path is technically possible.
    0
    installs
  65. Commix · timsonner
    Use for controlled command-injection validation during authorized web and API assessments. Trigger on manually triaged injection candidates, request replay validation, and narrow retests where the least invasive proof path is required.
    0
    installs
  66. Dalfox · timsonner
    Use for tightly scoped XSS validation during authorized web assessments. Trigger on reflected or stored XSS candidate triage, payload verification, and repeatable retest of confirmed cross-site scripting weaknesses.
    0
    installs
  67. Gcloud · timsonner
    Use for GCP control-plane validation during authorized pentests. Trigger on credentialed Google Cloud review, project and IAM scope checks, storage exposure review, and verifying what an approved identity can access.
    0
    installs
  68. Nessus · timsonner
    Use for credentialed or non-credentialed vulnerability scanning during authorized pentests. Trigger on baseline exposure review, broad host hygiene assessment, and producing scanner-led coverage that still requires analyst triage and validation.
    0
    installs
  69. Netcat · timsonner
    Use for basic TCP or UDP connectivity, banner grabbing, listener setup, and controlled data-path validation during authorized pentests. Trigger on socket testing, simple transfer checks, and proving whether a specific network path is reachable.
    0
    installs
  70. Nuclei · timsonner
    Use for templated vulnerability checks, exposure validation, and misconfiguration review during authorized pentests. Trigger on confirming likely web, network, or cloud exposures after discovery has narrowed the target set.
    0
    installs
  71. Rclone · timsonner
    Use for tightly scoped file transfer and cloud-storage access validation during authorized pentests. Trigger on approved exfiltration-path simulation, storage exposure review, and determining whether a specific path allows unauthorized bulk transfer.
    0
    installs
  72. Rubeus · timsonner
    Use for tightly scoped Kerberos ticket and account validation during authorized pentests. Trigger on approved ticket analysis, Kerberos exposure review, and proving whether a specific account or host permits unsafe ticket operations.
    0
    installs