metasploit-framework

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is an actionable how-to for installing and operating Metasploit and includes numerous high-risk, offensive operations: generating and delivering reverse shells, credential harvesting, persistence, privilege escalation, and automated brute-force scanning. The greatest technical supply-chain risk shown is the installer download-and-run pattern (curl -> chmod -> execute) using an unpinned remote script. The content is dual-use — legitimate for authorized penetration testing but easily abused if executed without strict legal authorization, human oversight, and operational controls. Recommend: restrict use of this skill to authenticated, audited environments; disallow automated or autonomous execution of commands that perform network exploitation or credential harvesting; prefer pinned, verified installer sources and verify checksums/signatures before executing installers.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 11:44 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fmetasploit-framework%2F@08d84adb0aec871ae57f1847d21eeb54a68cc715