Versioned security assessment

Report ID: SA-BFB7D06B

7/6/2026, 12:57:56 AM

pentest-metasploit security assessment v7

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
pentest-metasploit
Version
v7
Maintainer
AgentSecOps
Coverage
5 Files scanned · 1,975 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

Critical

56 confirmed security findings require attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

The audit confirms that the skill is high-risk dual-use offensive security content centered on Metasploit. Most template and reference-file alerts are documentation false positives, but SKILL.md contains concrete exploit, payload, post-exploitation, credential access, persistence, pivoting, evasion, and phishing guidance. No prompt injection attempt was found in the reviewed files.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

5 Files scanned · 1,975 Lines analyzed

103 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Observed in 2 evidence locations

Network access

May connect to external services.

Observed in 24 evidence locations

Filesystem access

May read or write local files.

Observed in 1 evidence location

Env variables

May read values from the process environment.

Observed in 18 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 55 evidence locations

Capability review items (47)
Critical
Ruby/shell backtick execution
- `post/windows/gather/hashdump` - Extract password hashes (requires SYSTEM privileges)
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
Ruby/shell backtick execution
- `post/windows/gather/credentials/credential_collector` - Gather stored credentials
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
Ruby/shell backtick execution
- `post/windows/manage/persistence_exe` - Establish persistence (if explicitly authorized)
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
Ruby/shell backtick execution
```bash
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
Ruby/shell backtick execution
```
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
Ruby/shell backtick execution
```bash
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
Ruby/shell backtick execution
```bash
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
Ruby/shell backtick execution
```
The flagged command context covers payload generation, phishing delivery, credential collection, persistence, evasion, or automated exploitation. These are concrete high-risk offensive actions.
Critical
PowerShell invocation
- **Empire**: Handoff sessions to PowerShell Empire framework
The skill describes handing sessions to PowerShell Empire, a post-exploitation framework. This supports offensive C2-style operations.
High
Hardcoded URL
curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash
The hardcoded URL is part of a command that downloads and executes a remote installer. The network location itself is not malicious, but it creates a supply-chain dependency.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
- `post/multi/recon/local_exploit_suggester` - Identify privilege escalation opportunities
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
1. Background current session: `background`
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
2. Select escalation module: `use exploit/windows/local/<escalation-module>`
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
3. Set session: `set SESSION <session-id>`
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
4. Run exploit: `exploit`
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
- **Nmap Integration**: Import reconnaissance data with `db_import`
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
Ruby/shell backtick execution
```bash
The flagged Markdown command context provides operational Metasploit, Meterpreter, proxying, or exploit workflow steps. These commands can materially enable unauthorized testing if misused.
High
SOCKS proxy
socks4 127.0.0.1 1080
The SOCKS proxy is configured for pivoting through a compromised host. That is a real lateral-movement capability in the workflow.
Medium
Ruby/shell backtick execution
```bash
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.
Medium
Ruby/shell backtick execution
```
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.
Medium
Ruby/shell backtick execution
```bash
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.
Medium
Ruby/shell backtick execution
```
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.
Medium
Ruby/shell backtick execution
```bash
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.
Medium
Ruby/shell backtick execution
```
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.
Medium
Ruby/shell backtick execution
```bash
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.
Medium
Ruby/shell backtick execution
```
The flagged Markdown command block belongs to a Metasploit workflow rather than ordinary shell documentation. It guides setup or operation of an offensive testing framework.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (56)

RISK-001 Critical
Pipe to shell pattern
curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash
The CI template downloads an install script over the network and pipes it directly to bash. This is a real supply-chain execution risk if the template is used.
RISK-002 Critical
Metasploit framework
name: pentest-metasploit
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-003 Critical
Metasploit framework
security assessments using Metasploit Framework. Use when: (1) Validating vulnerabilities in
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-004 Critical
Metasploit framework
tags: [pentest, metasploit, exploitation, post-exploitation, vulnerability-validation, red-team]
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-005 Critical
Metasploit framework
packages: [metasploit-framework]
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-006 Critical
Metasploit framework
# Metasploit Framework Penetration Testing
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-007 Critical
Metasploit framework
Metasploit Framework is the industry-standard platform for penetration testing, vulnerability valida
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-008 Critical
Metasploit framework
Initialize Metasploit console and verify database connectivity:
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-009 Critical
Metasploit framework
# Initialize Metasploit database
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-010 Critical
Metasploit framework
# Launch Metasploit console
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-011 Critical
Metasploit framework
msf6 exploit(windows/smb/ms17_010_eternalblue) > set PAYLOAD windows/x64/meterpreter/reverse_https
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-012 Critical
Metasploit framework
meterpreter > sysinfo
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-013 Critical
Metasploit framework
meterpreter > getuid
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-014 Critical
Metasploit framework
meterpreter > getprivs
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-015 Critical
Metasploit framework
meterpreter > ipconfig
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-016 Critical
Metasploit framework
meterpreter > route
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-017 Critical
Metasploit framework
meterpreter > ps
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-018 Critical
Metasploit framework
meterpreter > run post/windows/gather/enum_av_excluded
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-019 Critical
Metasploit framework
meterpreter > run post/windows/gather/enum_logged_on_users
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-020 Critical
Metasploit framework
meterpreter > run post/multi/recon/local_exploit_suggester
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-021 Critical
Metasploit framework
meterpreter > ps
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-022 Critical
Metasploit framework
meterpreter > migrate <stable-process-pid>
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-023 Critical
Metasploit framework
meterpreter > getsystem
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-024 Critical
Metasploit framework
meterpreter > getuid
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-025 Critical
Metasploit framework
meterpreter > run post/windows/gather/arp_scanner RHOSTS=<internal-subnet>
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-026 Critical
Metasploit framework
meterpreter > run auxiliary/scanner/smb/smb_version
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-027 Critical
Metasploit framework
meterpreter > run autoroute -s <internal-subnet>/24
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-028 Critical
Metasploit framework
msf6 exploit(...) > set PAYLOAD linux/x64/meterpreter/reverse_tcp
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-029 Critical
Metasploit framework
msf6 exploit(office_word_macro) > set PAYLOAD windows/meterpreter/reverse_https
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-030 Critical
Metasploit framework
msf6 exploit(multi/handler) > set PAYLOAD windows/meterpreter/reverse_https
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-031 Critical
Metasploit framework
# Headless Metasploit resource script
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-032 Critical
Metasploit framework
set PAYLOAD windows/x64/meterpreter/reverse_tcp
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-033 Critical
Metasploit framework
Map Metasploit activities to ATT&CK framework:
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-034 Critical
Metasploit framework
msf6 evasion(...) > set PAYLOAD windows/meterpreter/reverse_https
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-035 Critical
Metasploit framework
set PAYLOAD windows/meterpreter/reverse_https # staged
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-036 Critical
Metasploit framework
set PAYLOAD windows/meterpreter_reverse_https # stageless
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-037 Critical
Metasploit framework
meterpreter > run post/windows/manage/migrate
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-038 Critical
Metasploit framework
meterpreter > run post/multi/recon/local_exploit_suggester
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-039 Critical
Metasploit framework
meterpreter > getsystem -t 1 # Named Pipe Impersonation
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-040 Critical
Metasploit framework
meterpreter > getsystem -t 2 # Named Pipe Impersonation (Admin Drop)
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-041 Critical
Metasploit framework
meterpreter > getsystem -t 3 # Token Duplication
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-042 Critical
Metasploit framework
meterpreter > background
The skill explicitly depends on and teaches Metasploit or Meterpreter workflows. The cited line is part of exploit, payload, post-exploitation, or framework setup guidance.
RISK-043 Critical
Cobalt Strike keywords
- **Cobalt Strike**: Export sessions to Cobalt Strike beacons
The skill discusses exporting sessions to Cobalt Strike beacons. That is a direct handoff to C2-style offensive infrastructure.
RISK-044 Critical
[HEURISTIC] DANGEROUS COMBINATION: Code execution + Network + Credential access
This combination is common in credential stealers and RATs
The reviewed content includes code execution, network capability, and credential-access guidance. The heuristic is supported by the surrounding Metasploit workflow.
RISK-045 Critical
Phishing Payload Delivery Workflow
SKILL.md includes a phishing campaign delivery pattern that generates a malicious document and configures a reverse HTTPS Meterpreter listener.
The section is explicitly titled phishing campaign delivery and contains payload and listener setup steps. This is clear social-engineering and payload-delivery guidance.
RISK-046 Critical
Credential Theft and Persistence Guidance
SKILL.md lists post-exploitation modules for password hash extraction, credential collection, local exploit discovery, and persistence.
The cited lines directly name hashdump, credential collector, local exploit suggester, and persistence modules. These are concrete post-compromise capabilities.
RISK-047 High
C2 keywords
- **Exfiltration**: T1041 (Exfiltration Over C2 Channel)
The skill maps Metasploit activity to exfiltration over C2 channels. In this offensive workflow, that context supports high-risk post-compromise activity.
RISK-048 High
System reconnaissance
meterpreter > getuid
The cited line appears in post-exploitation or operational-security guidance. It supports host discovery, identity checks, stealth, or cleanup after compromise.
RISK-049 High
System reconnaissance
meterpreter > getuid
The cited line appears in post-exploitation or operational-security guidance. It supports host discovery, identity checks, stealth, or cleanup after compromise.
RISK-050 High
System reconnaissance
- **Attribution Prevention**: Avoid personal infrastructure or identifiable indicators
The cited line appears in post-exploitation or operational-security guidance. It supports host discovery, identity checks, stealth, or cleanup after compromise.
RISK-051 High
System reconnaissance
- **Session Management**: Close sessions cleanly to avoid detection alerts
The cited line appears in post-exploitation or operational-security guidance. It supports host discovery, identity checks, stealth, or cleanup after compromise.
RISK-052 High
Network scanning tools
tools: [postgresql, nmap]
The skill includes Nmap and proxychains workflows for enumeration and pivoted scanning. These are real network reconnaissance capabilities.
RISK-053 High
Network scanning tools
msf6 > db_import /path/to/nmap-scan.xml
The skill includes Nmap and proxychains workflows for enumeration and pivoted scanning. These are real network reconnaissance capabilities.
RISK-054 High
Network scanning tools
proxychains nmap -sT -Pn <internal-target>
The skill includes Nmap and proxychains workflows for enumeration and pivoted scanning. These are real network reconnaissance capabilities.
RISK-055 High
Network scanning tools
- **Nmap Integration**: Import reconnaissance data with `db_import`
The skill includes Nmap and proxychains workflows for enumeration and pivoted scanning. These are real network reconnaissance capabilities.
RISK-056 High
Defense Evasion and Stealth Advice
SKILL.md advises attribution prevention, encrypted payload traffic, artifact cleanup, and techniques to avoid detection alerts during offensive operations.
The operational-security section and troubleshooting steps discuss evasion, encrypted callbacks, cleanup, and detection avoidance. The context is an offensive Metasploit workflow.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    Critical
    Operational exploit and payload instructions are presented as executable workflows.
    Limit marketplace publication to vetted offensive-security channels, or replace exploit execution steps with defensive validation planning and reporting-only guidance.
  2. FIX-002
    Critical
    The skill includes credential collection, persistence, phishing delivery, pivoting, and evasion workflows.
    Remove or gate these sections behind strict authorization controls, lab-only constraints, and explicit refusal guidance for unauthorized targets.
  3. FIX-003
    High
    The CI template uses a curl-to-bash installer pattern.
    Replace remote shell piping with a pinned release, checksum verification, or a trusted package manager install path.
  4. FIX-004
    Low
    Reference templates trigger many static alerts because vulnerable examples are embedded inline.
    Label examples clearly as non-executable documentation and keep dangerous snippets minimal, sanitized, and separated from operational instructions.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (9)
Critical
Metasploit framework
- https://docs.metasploit.com/
Force-confirmed blocker/critical static finding; AI dismissal overridden.
Critical
Metasploit framework
- https://www.offsec.com/metasploit-unleashed/
Force-confirmed blocker/critical static finding; AI dismissal overridden.
Critical
Metasploit framework
Organizations can detect Metasploit activity by:
Force-confirmed blocker/critical static finding; AI dismissal overridden.
Critical
Metasploit framework
- **Network IDS**: Signature-based detection of default Metasploit payloads
Force-confirmed blocker/critical static finding; AI dismissal overridden.
Critical
Metasploit framework
- **Endpoint Detection**: Behavioral analysis of meterpreter process injection
Force-confirmed blocker/critical static finding; AI dismissal overridden.
Critical
Metasploit framework
- [Metasploit Documentation](https://docs.metasploit.com/)
Force-confirmed blocker/critical static finding; AI dismissal overridden.
Critical
Metasploit framework
- [Metasploit Unleashed](https://www.offsec.com/metasploit-unleashed/)
Force-confirmed blocker/critical static finding; AI dismissal overridden.
High
C2 keywords
- **T1041**: Exfiltration Over C2 Channel
Force-confirmed blocker/high static finding; AI dismissal overridden.
High
Malware type keywords
[ ] 10. Remove malicious artifacts (malware, backdoors, webshells)
Force-confirmed blocker/high static finding; AI dismissal overridden.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable