add Commando tool catalog as lazy discovery tree (10 categories, ~55 tools) + fix native tool arg parsing + unicode-safe stdout

This commit is contained in:
drjones
2026-09-18 18:40:50 -07:00
parent 5a97d04875
commit 8b52a1faad
2 changed files with 270 additions and 27 deletions

View File

@@ -1,15 +1,55 @@
# METATRON — lightweight Ollama terminal harness
A minimal terminal harness for talking to Ollama (hosted on nightmare `10.30.20.29:11434`)
with full system access and internet search. Type `metatron` to launch.
with full system access, internet search, and the Commando tool catalog organized as a
lazy discovery tree. Type `metatron` to launch.
## Flow
1. **Model selection** — fetches the live model list from nightmare, numbered menu.
1. **Model selection** — fetches the live model list from nightmare, numbered menu
(sizes shown, `Enter` reuses the last model).
2. **Chat** — streaming REPL against the selected model.
3. **System access** — `!command` runs a shell command directly, and the model can also
call `run_command` natively (function calling).
4. **Search** — `?query` searches the internet (SearXNG), and the model can call
`web_search` natively.
3. **System access** — `!command` runs a shell command directly; the model can also call
`run_command` natively (function calling).
4. **Search** — `?query` searches (SearXNG); `?fetch <url>` reads a page.
5. **Tool discovery tree** — the Commando toolset is organized by category and discovered
lazily, so the model never has all tools dumped into context at once.
## Tool discovery tree
The catalog (~55 tools across 10 categories) is NOT sent to the model. Instead the model
gets 4 native tools and drills in on demand:
```
list_categories -> see the 10 categories (recon, web, exploit, post, crack,
wireless, sniff, osint, forensics, utils)
list_tools("<category>") -> see the tools + usage in one category
run_command -> actually execute a tool
web_search -> internet facts
```
Categories:
- **recon** (10) — nmap, masscan, rustscan, netdiscover, arp-scan, amass, sublist3r,
theHarvester, dnsrecon, whatweb
- **web** (7) — nikto, gobuster, dirb, ffuf, wpscan, sqlmap, commix
- **exploit** (3) — msfconsole, searchsploit, msfvenom
- **post** (10) — impacket-*, crackmapexec, evil-winrm, mimikatz, bloodhound-python, responder
- **crack** (4) — hashcat, john, hydra, medusa
- **wireless** (3) — aircrack-ng, airmon-ng, bettercap
- **sniff** (4) — tshark, tcpdump, mitmproxy, ettercap
- **osint** (4) — theHarvester, sherlock, holehe, spiderfoot
- **forensics** (4) — volatility, binwalk, exiftool, strings
- **utils** (6) — nc, socat, proxychains, curl, certutil, powershell
## Controls
| Input | Action |
|-------|--------|
| `exit` / `quit` | leave |
| `!<command>` | run a shell command directly |
| `?<query>` | search the internet (SearXNG) directly |
| `?fetch <url>` | read a page's text |
| `/tools` | list tool categories |
| `/tools <cat>` | list tools in a category |
| `/save` | save the session to markdown |
| `/help` | help |
## Requirements
- Python 3.11 (stdlib only — `urllib`, `subprocess`, `json`). No pip deps.
@@ -23,20 +63,15 @@ setx PATH "%PATH%;C:\Tools\metatron"
```
Then `metatron` from any shell.
## Controls
| Input | Action |
|-------|--------|
| `exit` / `quit` | leave |
| `!<command>` | run a shell command directly |
| `?<query>` | search the internet (SearXNG) directly |
## Hardcoded
- Ollama URL: `http://10.30.20.29:11434`
- SearXNG URL: `http://10.30.20.35:6969` (self-hosted meta-search, CT 516)
- System prompt + `run_command` / `web_search` tool definitions
- System prompt, tool catalog, and `run_command` / `web_search` / `list_categories` /
`list_tools` tool definitions
- Only the model list is dynamic (fetched from `/api/tags`).
## Search notes
- `?<query>` is the guaranteed path (no LLM needed).
- Native `web_search` tool-calling can degenerate on nightmare `.29`'s qwen3.8fast —
the `?` escape always works.
## Notes
- `?<query>` is the guaranteed search path (no LLM needed).
- Native tool-calling can degenerate on nightmare `.29` under GPU load; the manual
escapes (`!`, `?`, `/tools`) always work.
- `keep_alive: "30m"` keeps the model resident to avoid reload latency.