What problem does it solve? It gives the agent a structured, scope-gated workflow for running authorized penetration tests against Tyler's own devices, so recon, vulnerability scanning, and exploitation happen in a controlled and repeatable way instead of ad-hoc command guessing. ## Core Features & Use Cases - Scope-gated engagement workflow: scope.sh records the authorized target before any active packet, with passive recon first and explicit consent required before active exploitation. - Full Kali toolchain plus MCP servers: nmap, masscan, nuclei, sqlmap, ffuf, metasploit, impacket, BloodHound, certipy, and GhostPack binaries, with cyproxio MCP servers (sec-nmap, sec-sqlmap, sec-nuclei, etc.) exposing tools directly to the agent. - Reference playbooks: LAN host discovery with NetBIOS/RDP credential-attack guidance and WSL2 disk-pressure recovery procedures for the Kali environment. - Use Case: Ask the agent to assess a Windows machine on your home network; it scopes the target, runs recon.sh and vulnscan.sh, reports findings, and only proceeds to active steps after your approval. ## Quick Start Ask the agent to scope and run a passive recon and vulnerability scan against one of your own devices on the LAN, then review the findings before authorizing any active testing.