Agent skill

Metasploit

by Encod3d-Sec in Encod3d-Sec/TORCH

Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup…

MITAuto-check passedSecurity

Install Metasploit

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill metasploit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH metasploit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/metasploit .claude/skills/metasploit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
metasploit
GitHub stars
329
Token cost
~1k tokens
SKILL.md length
461 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup…

  • Driving an exploit/reverse-shell through msf
  • SKILL.md covers Pre-attack wiki query…, Setup / DB, Recon via msf and Search / select / verify, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Penetration testing

What it does

Metasploit is an agent skill from Encod3d-Sec/TORCH. Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup for Windows/EDR), sessions + localexploitsuggester + post modules, and autoroute/portfwd/socks pivoting. Points to the metasploit cheatsheet for syntax. Use for "metasploit", "msfconsole", "msfvenom", "meterpreter", "multi/handler", or driving an exploit/reverse-shell through msf.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing. It works with Metasploit and Nmap. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Driving an exploit/reverse-shell through msf
  • Tasks that involve Penetration testing

Example prompts

  • “metasploit”
  • “msfconsole”
  • “msfvenom”
  • “/metasploit”

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Metasploit loads about 1k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 461 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 461 words, ~1,017 tokens.

Download SKILL.mdSave it as .claude/skills/metasploit/SKILL.md (or your agent's skills folder).
name
metasploit
description
Drive msfconsole across the workflow - DB-backed recon (db_nmap, auxiliary scanners), version->exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shell_reverse_tcp backup for Windows/EDR), sessions + local_exploit_suggester + post modules, and autoroute/portfwd/socks pivoting. Points to the metasploit cheatsheet for syntax. Use for "metasploit", "msfconsole", "msfvenom", "meterpreter", "multi/handler", or driving an exploit/reverse-shell through msf.

Metasploit: framework driver

Drive msfconsole for recon, exploit, reverse shells, and post-ex. Syntax lives in [[metasploit]]; this skill is the workflow that strings it together.

Pre-attack wiki query (MANDATORY)

Before firing any exploit module, query the fingerprinted tech/CVE: read [[metasploit]] directly for syntax, then Skill(arsenal) for the matching module/payload/technique. Never fire a module from memory when a targeted lookup would confirm the right one/target index.

Setup / DB

msfconsole -q in a named tmux tab, never a blind background job, the operator needs to see sessions land live. workspace -a <eng> scopes loot to the engagement, db_status confirms the Postgres backend is up before anything else. Cheatsheet: Setup + Database sections.

Recon via msf

db_nmap writes straight to hosts/services; layer auxiliary/scanner/* (smb/http/ssh version + vuln checks) on top for anything plain nmap scripts miss. This complements the ctf-box Phase-1 basics, it does not replace them, run both.

Search / select / verify

search <app> <ver> or search cve:<id>, use, info to read the module's CVE refs and target list, check before run/exploit whenever the module supports it, a non-destructive exploitability test beats a blind fire. Cheatsheet: Search and Selection + Options and Running.

Reverse shells

multi/handler catches. Payload choice: meterpreter first (linux/x64/meterpreter/reverse_tcp / windows/x64/meterpreter/reverse_tcp), fall back to plain shell_reverse_tcp when meterpreter is blocked or unstable, routine on hardened Windows/EDR. Delivery via msfvenom (ELF/EXE/ASPX/PHP, cheatsheet's MSFVenom section has every format). Egress-test the LPORT (80/443/53 before 4444). Background the handler correctly: set ExitOnSession false; run -j so it keeps catching new sessions. On the VM, scripts/vm-handler.sh <eng> <lhost> [payload] automates the LPORT choice: it reads the VM's listeners and picks the first FREE egress-friendly port (80/443/53/8000/8080), so the handler never fails to bind on a taken port nor silently picks a filtered high port; it launches in the engagement's msf tmux window and prints the LPORT to build the payload with.

Show full SKILL.md (159 more words)Show less

Sessions / post-ex

sessions -i to interact, run post/multi/recon/local_exploit_suggester is the privesc reflex on every fresh session, then targeted post/* modules, getsystem, and post/multi/manage/shell_to_meterpreter to upgrade a plain shell. Cheatsheet: Sessions and Jobs

  • Post-Exploitation Modules.

Pivoting

autoroute/portfwd/socks through a session to reach internal-only ports before hand-rolling SSH -L. Full syntax and proxychains setup: [[pivoting]].

Verify target (false-root)

Before trusting any shell or privesc claim: getuid + sysinfo/hostname must match the actual target. A uid=0 that doesn't match the target is the false-root trap, the session died back to the attacker box. Same guardrail Skill(delegate) enforces on manual exploit runs.

Interlock + anti-drift

The fiddly msfvenom-compile -> handler-catch -> escalation-run sequence is a prime Skill(delegate) hand-off: fully specified, mechanical, cheap-model-shaped. DRIVE msf for every load-bearing exploit/shell request so the operator watches sessions land; don't abandon msf for raw scripts once a foothold lands.

Client-data boundary

Sessions, loot, and creds stay in the msf DB workspace + targets/<eng>/; never paste a real host/cred/hashdump into wiki/ or session/*.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/metasploit of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Metasploit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Metasploit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Metasploit this skillEncod3d-Sec/TORCH329—~1kAutomated safety check: PassMIT
Exploiting Ms17 010 Eternalblue Vulnerabilitymukul975/Anthropic-Cybersecurity-Skills34k—~963Automated safety check: PassApache-2.0
Add Community Skillsamugit83/redamon3k—~775Automated safety check: PassMIT
NmapBrownFineSecurity/iothackbot8591 repos~3.8kAutomated safety check: NotesMIT
Nmap ReconCommonHuman-Lab/nyxstrike157—~639Automated safety check: PassCustom licence
Operate Network Reconcyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • Exploiting Ms17 010 Eternalblue Vulnerability

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's…

    34k GitHub stars~963 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    3k GitHub stars~775 tokensUpdated today
    SecurityAuto-check passed
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    859 GitHub starsUsed in 1 repo~3.8k tokens
    SecurityAuto-check: notes
  • Nmap Recon

    CommonHuman-Lab/nyxstrike

    Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools

    157 GitHub stars~639 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Operate Network Recon

    cyberful/cyberful

    Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

    135 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recon Nmap

    AgentSecOps/SecOpsAgentKit

    Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

    220 GitHub starsUsed in 1 repo~4.6k tokens
    SecurityAuto-check: notes

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Metasploit

What does Metasploit do?

Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup…. Metasploit is an agent skill from Encod3d-Sec/TORCH. Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup for Windows/EDR), sessions + localexploitsuggester + post modules, and autoroute/portfwd/socks pivoting.

When should I use Metasploit?

Metasploit fits situations like: driving an exploit/reverse-shell through msf; tasks that involve Penetration testing.

How do I install Metasploit in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill metasploit -a claude-code`. Or copy the skill folder (skills/workflow/metasploit in Encod3d-Sec/TORCH) into .claude/skills/metasploit in your project. Claude Code loads it when a task matches its description.

How do I install Metasploit in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill metasploit -a codex`. Or copy the skill folder (skills/workflow/metasploit in Encod3d-Sec/TORCH) into .agents/skills/metasploit in your project. Codex loads it when a task matches its description.

Can I use Metasploit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill metasploit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/metasploit, .gemini/skills/metasploit, .github/skills/metasploit and .opencode/skills/metasploit in your project.

What does Metasploit need to run?

SKILL.md names no scripts, command-line tools or credentials: Metasploit is instructions for the agent only.

Does Metasploit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Metasploit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Metasploit use?

Metasploit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Metasploit use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Metasploit?

Skills that share tags, products or a category with Metasploit: Exploiting Ms17 010 Eternalblue Vulnerability (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Add Community Skill (samugit83/redamon, 3k stars), Nmap (BrownFineSecurity/iothackbot, 859 stars) and Nmap Recon (CommonHuman-Lab/nyxstrike, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Metasploit?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.