Network
DNS hygiene and latency, MTU and tunnel checks, IPv6 leak repair when a VPN only covers IPv4, TCP tuning, Wi-Fi and NIC analysis, firewall state.
One link. The agent audits performance, network, security and privacy, then fixes what is broken with your approval — and proves every change with before/after numbers and a rollback.
OpenCode · macOS 12–15 · Windows 10/11 · Server 2016–2025 · RDP/VPS
Optimize this machine
Recon: OS, hardware, network, disk, security posture
✓Baseline: speed, DNS latency, memory, disk numbers
✓Apply fixes with approval and rollback
✓Verify and report the delta
✓Every area is a set of checks with an exact command, a risk level and a verification step.
DNS hygiene and latency, MTU and tunnel checks, IPv6 leak repair when a VPN only covers IPv4, TCP tuning, Wi-Fi and NIC analysis, firewall state.
Startup and background items, power and high-performance profiles, memory pressure, disk snapshots and cache, thermal-throttle detection.
Firewall and stealth mode, FileVault and BitLocker, Gatekeeper and SmartScreen, remote-service lock-down, TLS and authentication hardening, RDP hardening.
Telemetry endpoint reduction, ad and identifier opt-out, diagnostic submission off, hosts and firewall layering — with the breakage stated honestly.
Log and cache reduction, orphaned app data, temp files, scheduled maintenance — plus a nightly cleanup task if you want one.
No sleep, keep-alive, session safety, port change with a pre-armed dead-man rollback so you cannot lock yourself out.
The runbook defines phases with entry and exit criteria, so the agent cannot skip verification or forget a backup.
Recon — read-only inventory of the machine. Nothing changes.
Baseline — captures the numbers you will compare against later.
Plan — findings table ranked by severity; you approve high-risk work.
Backup — snapshot, registry export or config copy before each change.
Fix — one change at a time, verified immediately in the same step.
Verify — re-measure and show the delta.
Report — findings, changes, rollback commands and what could not be fixed.
Paste this into OpenCode. The agent installs the booster, detects the OS and follows the runbook.
Fetch https://raw.githubusercontent.com/pentest2bot/pentest2booster/main/examples/BOOTSTRAP.md and follow it exactly.# macOS / Linux
curl -fsSL https://pentest2bot.ink/booster/install.sh | sh
# Windows (PowerShell)
irm https://pentest2bot.ink/booster/install.ps1 | iex
# update any time
pentest2booster updateAuto-updates: the runtime checks for a newer version on every run and the runbook is always fetched fresh, so fixes ship without reinstalling.
Every action is LOW, MED, HIGH or CRITICAL. High-risk work needs your approval; a forbidden set is refused outright.
Snapshot, registry export or config copy before the change — recorded in the journal with a hash.
Each change is verified in the same step. If verification fails, the rollback runs before anything else.
Credential material is never read, printed, journaled or reported. Evidence is escaped and capped.
No. Update and push endpoints are never blocked by default. When a privacy change would break a feature, the runbook states the trade-off and asks first.
On macOS, no — the system volume is sealed. The runbook says so instead of pretending, and offers hiding instead. It also explains that hiding reclaims no space.
Yes, with a dead-man protocol: before any change that could drop your session it arms a verified rollback, and only disarms it after you reconnect successfully.
A cleaning app runs a fixed script. This runs a versioned runbook that adapts to your OS and build, explains each change, and leaves an auditable journal you can read.
Give your agent the link and watch the machine get faster, quieter and safer.