pentest-metasploit
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the user to use
sudofor managing the PostgreSQL service (sudo systemctl start postgresql), which is a prerequisite for Metasploit's database management features. This is a standard administrative task for setting up the tool's environment. - [EXTERNAL_DOWNLOADS]: The CI/CD template (
assets/ci-config-template.yml) includes a step that fetches an installation script from Aqua Security's public GitHub repository (aquasecurity/tfsec) and executes it usingbash. This is used to incorporate infrastructure-as-code security scanning into a development pipeline using a tool from a well-known security vendor. - [REMOTE_CODE_EXECUTION]: The skill's primary function is to facilitate the use of the Metasploit Framework for vulnerability validation and exploitation. While this involves executing code on remote targets, the skill provides extensive guidance on authorization, scoping, and legal compliance to ensure usage remains within professional and authorized boundaries.
- [SAFE]: The skill includes comprehensive security considerations, emphasizing written authorization, scope adherence, and operational security, which are industry standard practices for penetration testing operations and security research.
Audit Metadata