CtrlK
BlogDocsLog inGet started
Tessl Logo

metasploit-framework

This skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads with msfvenom", "perform post-exploitation", "use auxiliary modules for scanning", or "develop custom exploits". It provides comprehensive guidance for leveraging the Metasploit Framework in security assessments.

64

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/metasploit-framework/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable — nearly everything is a concrete, executable command arranged in a sensible phased workflow with a troubleshooting section. Its weaknesses are token efficiency (significant duplication between the phase walkthroughs and the Quick Reference tables, plus prerequisite padding) and the absence of any progressive disclosure: a 470-line monolith that should split its command reference and module catalogs into references/ files.

Suggestions

De-duplicate the Meterpreter and msfconsole command lists: keep the inline phase walkthroughs as task-flows and let the Quick Reference tables be the single source for command syntax, or vice versa, cutting roughly 60-80 lines.

Split the bulk reference material into one-level-deep bundle files (e.g., references/command-reference.md, references/module-catalog.md, references/msfvenom-recipes.md) and keep SKILL.md as a concise overview with clearly signaled links.

Tighten the Prerequisites section by removing the 'Required Knowledge' bullets (e.g., 'Basic programming concepts') that restate knowledge Claude already has, keeping only the authorization/scope requirements that gate legitimate use.

DimensionReasoningScore

Conciseness

The command listings are dense and informative, but there is substantial duplication — Phase 6's Meterpreter commands reappear almost wholesale in the 'Meterpreter Essential Commands' table, and Phases 1/4 console commands repeat the Quick Reference table. The 'Required Knowledge' list ('Network and system fundamentals', 'Basic programming concepts') is padding that assumes no competence, fitting the 'mostly efficient but could be tightened' anchor rather than the lean 5 or the padded 2.

3 / 5

Actionability

Fully executable, copy-paste-ready commands throughout: realistic msfconsole session transcripts, msfvenom one-liners with concrete payload/format/encoder arguments, and meterpreter commands, covering the common exploitation, scanning, and payload-generation cases. Nothing is pseudocode or vague.

5 / 5

Workflow Clarity

A clear ten-phase sequence (console basics → module types → search → configure → payload selection → meterpreter → auxiliary → post → msfvenom → handlers) with validation checkpoints ('check' before 'exploit', 'show options again to verify') and a Troubleshooting table that supplies error-recovery loops. It misses 5 because there is no explicit 'only proceed when check succeeds' gate or structured checklist around the risky exploitation steps.

4 / 5

Progressive Disclosure

The body is a single ~470-line file with no bundle files at all; a command reference, a module catalog, and msfvenom recipe collections are inlined where they belong in references/ files. Section headers and tables keep it above the 'minimal structure' anchor, but content that should be separate is inline, which is the 3 anchor.

3 / 5

Total

15

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit and well-phrased trigger list covering the tool's main surfaces (exploitation, payload generation, scanning, post-exploitation, custom exploits). Its main weakness is that the capability statement leans on generic 'comprehensive guidance for leveraging' phrasing instead of concretely stating what the skill provides.

DimensionReasoningScore

Specificity

Names the Metasploit domain and multiple concrete actions ('exploit vulnerabilities with msfconsole', 'create payloads with msfvenom', 'perform post-exploitation', 'use auxiliary modules for scanning', 'develop custom exploits'), giving broad coverage. It falls short of 5 because the capability statement itself is generic — 'provides comprehensive guidance for leveraging the Metasploit Framework' is padded buzzword phrasing rather than a crisp statement of what the skill does.

4 / 5

Completeness

Both halves are present: an explicit 'This skill should be used when...' clause with six concrete trigger phrases, plus a 'what' statement. It sits at 4 rather than 5 because the 'what' ('comprehensive guidance for leveraging the Metasploit Framework in security assessments') is vague, whereas the 'when' is fully explicit.

4 / 5

Trigger Term Quality

Quoted trigger phrases are natural things a user would say and include the tool-specific terms 'Metasploit', 'msfconsole', and 'msfvenom'. Not 5 because common synonyms such as 'meterpreter', 'reverse shell', 'listener/handler', or 'generate a payload' are absent.

4 / 5

Distinctiveness Conflict Risk

Clear niche anchored by highly tool-specific triggers (msfconsole, msfvenom, Metasploit) that no other skill would claim; only the generic 'penetration testing' / 'security assessments' phrasing creates minor overlap with broader security skills.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.