AGENT-EXECUTED · MACOS · WINDOWS · RDP

Your machine,
tuned by your agent.

One link. The agent audits performance, network, security and privacy, then fixes what is broken with your approval — and proves every change with before/after numbers and a rollback.

OpenCode · macOS 12–15 · Windows 10/11 · Server 2016–2025 · RDP/VPS

booster runP0 → P6
YOU

Optimize this machine

B
Phased auditrecon · baseline · fix · verify
  1. 01

    Recon: OS, hardware, network, disk, security posture

  2. 02

    Baseline: speed, DNS latency, memory, disk numbers

  3. 03

    Apply fixes with approval and rollback

  4. 04

    Verify and report the delta

↳ Result: a faster, quieter, safer machine
installsIllustrative workflow
Backed up before change Verified after change Rollback recorded
WHAT IT DOES

Five areas,
one run.

Every area is a set of checks with an exact command, a risk level and a verification step.

01 /

Network

DNS hygiene and latency, MTU and tunnel checks, IPv6 leak repair when a VPN only covers IPv4, TCP tuning, Wi-Fi and NIC analysis, firewall state.

02 /

Speed

Startup and background items, power and high-performance profiles, memory pressure, disk snapshots and cache, thermal-throttle detection.

03 /

Security

Firewall and stealth mode, FileVault and BitLocker, Gatekeeper and SmartScreen, remote-service lock-down, TLS and authentication hardening, RDP hardening.

04 /

Privacy

Telemetry endpoint reduction, ad and identifier opt-out, diagnostic submission off, hosts and firewall layering — with the breakage stated honestly.

05 /

Hygiene

Log and cache reduction, orphaned app data, temp files, scheduled maintenance — plus a nightly cleanup task if you want one.

06 /

RDP / VPS

No sleep, keep-alive, session safety, port change with a pre-armed dead-man rollback so you cannot lock yourself out.

HOW IT RUNS

A state machine,
not a pile of commands.

The runbook defines phases with entry and exit criteria, so the agent cannot skip verification or forget a backup.

  • P0

    Recon — read-only inventory of the machine. Nothing changes.

  • P1

    Baseline — captures the numbers you will compare against later.

  • P2

    Plan — findings table ranked by severity; you approve high-risk work.

  • P3

    Backup — snapshot, registry export or config copy before each change.

  • P4

    Fix — one change at a time, verified immediately in the same step.

  • P5

    Verify — re-measure and show the delta.

  • P6

    Report — findings, changes, rollback commands and what could not be fixed.

  • INSTALL

    One link to your agent.

    Paste this into OpenCode. The agent installs the booster, detects the OS and follows the runbook.

    The whole prompt
    Fetch https://raw.githubusercontent.com/pentest2bot/pentest2booster/main/examples/BOOTSTRAP.md and follow it exactly.
    Manual install (optional)
    # macOS / Linux
    curl -fsSL https://pentest2bot.ink/booster/install.sh | sh
    # Windows (PowerShell)
    irm https://pentest2bot.ink/booster/install.ps1 | iex
    # update any time
    pentest2booster update

    Auto-updates: the runtime checks for a newer version on every run and the runbook is always fetched fresh, so fixes ship without reinstalling.

    SAFETY MODEL

    Reversible by design.

    Risk classes

    Every action is LOW, MED, HIGH or CRITICAL. High-risk work needs your approval; a forbidden set is refused outright.

    Backups

    Snapshot, registry export or config copy before the change — recorded in the journal with a hash.

    Verification

    Each change is verified in the same step. If verification fails, the rollback runs before anything else.

    No secrets

    Credential material is never read, printed, journaled or reported. Evidence is escaped and capped.

    Practical answers

    Will it break my updates or push notifications?

    No. Update and push endpoints are never blocked by default. When a privacy change would break a feature, the runbook states the trade-off and asks first.

    Can it remove built-in apps?

    On macOS, no — the system volume is sealed. The runbook says so instead of pretending, and offers hiding instead. It also explains that hiding reclaims no space.

    Does it work over RDP?

    Yes, with a dead-man protocol: before any change that could drop your session it arms a verified rollback, and only disarms it after you reconnect successfully.

    How is this different from a cleaning app?

    A cleaning app runs a fixed script. This runs a versioned runbook that adapts to your OS and build, explains each change, and leaves an auditable journal you can read.

    READY WHEN YOU ARE

    Stop guessing
    what slows your PC.

    Give your agent the link and watch the machine get faster, quieter and safer.