Run THOR scans and propose the exact command line for Windows, Linux, or macOS. Use when the user wants to scan a host, a directory, a mounted image, or a memory dump with THOR v10/v11.
SKILL.md
THOR Scan Skill
Goal: produce a safe, reproducible THOR command line and minimal preflight checks.
Rules
Prefer THOR v10 stable unless the user explicitly wants v11 TechPreview features.
Always start with environment detection: OS, THOR path, license presence, and whether thor-util exists.
Identify if user has full THOR or THOR Lite (different binaries, different capabilities).
Avoid "magic flags". Explain why each non-trivial flag is used.
Default to focusing on forensic / lab workflows; if it's live endpoint scanning, keep it conservative.
Preflight checklist
List the THOR install directory first (ls or dir). This immediately tells you:
Which THOR version you have (binary names contain "lite" for THOR Lite)
What binaries and tools are available
What license files exist
Verify the correct binary exists:
Full THOR: thor64.exe (Windows), thor-linux-64 (Linux), thor-macosx (macOS)