Metasploit Framework

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: internally coherent as a Metasploit skill and not obviously a credential-harvesting lure, but it equips an AI agent with explicit offensive security capabilities and real-world exploit workflows. The Rapid7 installer appears official, so the main risk is not supply-chain malware but the high-risk offensive scope and ability to compromise systems, harvest credentials, and maintain access.

Confidence: 93%Severity: 88%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:20 AM
Package URL
pkg:socket/skills-sh/googyosoo%2Fantigravity-skills%2Fmetasploit-framework%2F@bec98ac8b7107263817633beb86c4c906422d771
Security Audit — socket — Metasploit Framework