metasploit

Fail

Audited by Socket on Sep 5, 2026

3 alerts found:

Malwarex2Security
MalwareHIGH
references/post-exploitation.md

This fragment is a highly malicious, offensive post-exploitation runbook for Metasploit. It explicitly instructs credential dumping/secret extraction (Windows SAM/LSA/NTDS and Linux /etc/shadow), privilege escalation, persistence (scheduled task/registry/cron), internal pivoting and scanning (route/autoroute, SOCKS), surveillance (keylogging and screenshot/screen streaming), and data theft via file search/download/upload. There are strong malicious intent indicators and no obfuscation.

Confidence: 92%Severity: 98%
MalwareHIGH
references/msfvenom.md

This artifact is not a benign software module; it is highly actionable offensive documentation for generating reverse-shell/meterpreter payloads (including cross-platform and web-style formats) and starting a handler to receive connections. While it contains no intrinsic runtime behavior, its inclusion in a software package would represent a serious supply-chain risk due to direct weaponization guidance and enablement of malware-like operations.

Confidence: 80%Severity: 85%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: internally consistent as a Metasploit reference, but it is an offensive security skill that enables exploitation, session control, credential dumping, and remote host manipulation. Install trust is mostly official/low concern; the primary risk is the AI agent being given high-impact exploit and post-exploitation capability.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fmetasploit%2F@1128ed8e6ba4eeca1c32bd4f00e47ad4ade1131cc7557edfd5302dd2dd8e81a5
Security Audit — socket — metasploit