metasploit

Warn

Audited by Socket on Mar 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s footprint is coherent with a Metasploit-centric penetration testing workflow: it can generate payloads, perform service scanning, and attach reverse-shell listeners. This is powerful and can be misused if targets are unauthorized, so it requires strict scope/authorization controls. The installation path relies on Metasploit being present or installable via official Nightly installers, which is acceptable for legitimate tooling but warrants caution. Data flows involve local command execution and reverse-shell callbacks to user-controlled hosts, with no evident automatic exfiltration to third parties. Overall verdict: SUSPICIOUS (due to high-risk, powerful capabilities and potential for unauthorized use) with a securityRisk of 0.65 and malware score 0.25. Confidence in assessment: 0.75.

Confidence: 75%Severity: 65%
Audit Metadata
Analyzed At
Mar 7, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/PatrykQuantumNomad%2Fnetworking-tools%2Fmetasploit%2F@7bfc089f1a741cd8a60ab973b9eeb5b94217c0ac