exploiting-smb-vulnerabilities-with-metasploit
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a structured guide for authorized penetration testing. It focuses on the SMB protocol and uses well-known security frameworks such as Metasploit, Impacket, and Nmap.
- [COMMAND_EXECUTION]: The skill provides command-line examples for common security tools (nmap, msfconsole, crackmapexec). These are intended to be executed by a human operator in a controlled testing environment (e.g., Kali Linux).
- [CREDENTIALS_UNSAFE]: The instructions demonstrate techniques for credential harvesting (hashdump) and Pass-the-Hash attacks. These are core components of network security testing and are documented here for authorized demonstration of risk, not for malicious exfiltration. No actual sensitive credentials or API keys are hardcoded in the skill.
- [PROMPT_INJECTION]: No attempts to override agent behavior or safety guidelines were detected. The instructions include explicit 'Do not use' sections and emphasize the requirement for written authorization and defined scope.
Audit Metadata