msf-oneshot
Audited by Socket on Apr 22, 2026
2 alerts found:
SecurityMalwareThis skill is not a normal productivity or integration skill; it is an offensive exploitation playbook for AI agents. The install provenance for Metasploit itself is mostly consistent with Rapid7, so supply-chain risk is not the main issue. The main risk is capability scope: remote exploitation, reverse shells, credential dumping, privilege escalation, and file transfer are fundamentally high-risk and enable harmful real-world actions. Overall this is a high-risk offensive security skill and should be treated as suspicious/dangerous for general agent deployment.
This JSON fragment is an adversarial capability template that operationalizes intrusion: it provides actionable Metasploit one-liner/module guidance for SMB exploitation, reverse-shell payload generation, and database-to-OS command execution via supplied credentials and network parameters. Even without runtime code, it materially facilitates unauthorized compromise, so it represents an extremely high security/malware misuse risk.