Metasploit Framework

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches an installation wrapper from Rapid7's official GitHub repository.
  • [COMMAND_EXECUTION]: Executes system commands for installation, service management, and framework interaction via msfconsole and msfvenom.
  • [PRIVILEGE_ESCALATION]: Utilizes administrative privileges via sudo for initial setup and database initialization. Documents commands for privilege escalation on target systems using the Meterpreter 'getsystem' function.
  • [DATA_EXFILTRATION]: Describes tool capabilities for harvesting credentials, keylogging, and downloading files from target systems during security assessments.
  • [PERSISTENCE]: Includes procedures for utilizing persistence modules to maintain access on compromised systems as part of post-exploitation activities.
  • [DYNAMIC_EXECUTION]: Guides the user through generating and executing dynamic payloads and exploits tailored for various target platforms and architectures.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill instructions involve the agent processing output from Metasploit modules, scan results, and interactive sessions.
  • Boundary markers: None identified.
  • Capability inventory: Includes comprehensive file system access, network operations, and shell command execution capabilities.
  • Sanitization: None identified; the skill assumes an environment suitable for penetration testing operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — Metasploit Framework