metasploit-skillPlan and execute authorized Metasploit assessments for OpenClaw tasks with repeatable workflows, including target triage, exploit module selection, option tu...
Install via ClawdBot CLI:
clawdbot install zengyuxiu/metasploit-skillGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Mar 22, 2026
Security teams use this skill to conduct controlled Metasploit assessments on web servers, such as exploiting known vulnerabilities like CVE-2023 in HTTP services. It involves target triage, module selection, and generating repeatable .rc scripts to ensure auditability and compliance with scope. This is ideal for verifying patch effectiveness or identifying misconfigurations in production environments.
IT departments leverage this skill to test internal network segments for vulnerabilities, focusing on services like SMB or SSH. The workflow includes building target context, selecting compatible payloads, and executing checks before exploitation to minimize disruption. It helps organizations meet compliance requirements and improve defense-in-depth strategies.
Red teams employ this skill to simulate adversary tactics using Metasploit for authorized attacks, such as gaining initial access via exploit modules and validating sessions. The process emphasizes evidence capture and reporting to provide actionable insights for blue teams. This supports continuous security improvement and incident response readiness.
Researchers use this skill to validate new vulnerabilities in lab environments, applying the check-first approach to confirm exploitability without causing damage. It involves generating resource scripts for reproducibility and documenting findings for disclosure or internal training. This accelerates the development of mitigations and security patches.
Educational institutions integrate this skill into hands-on labs for courses like OSCP or CEH, teaching students to plan and execute Metasploit workflows safely. Students learn module selection, option tuning, and report writing in controlled settings. This builds practical skills for careers in ethical hacking and security analysis.
MSSPs offer subscription-based penetration testing services using this skill to deliver repeatable, auditable assessments for clients. Revenue comes from monthly or annual contracts covering vulnerability scanning, exploit validation, and compliance reporting. This model ensures consistent quality and scalability across multiple organizations.
Cybersecurity firms provide one-off or project-based engagements where experts use this skill for targeted assessments, such as web app or network penetration tests. Revenue is generated through fixed-price or hourly billing for scoping, execution, and report delivery. This model caters to organizations needing tailored security evaluations.
Companies develop and sell integrated security platforms that incorporate this skill as a module for automated exploit testing. Revenue streams include perpetual licenses or SaaS subscriptions, with add-ons for advanced features like workflow automation and reporting. This model targets enterprises seeking to enhance their in-house security tools.
💬 Integration Tip
Integrate this skill with existing security orchestration platforms by automating .rc script generation and logging outputs to central dashboards for real-time monitoring and compliance tracking.
Scored Apr 19, 2026
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Coding style memory that adapts to your preferences, conventions, and patterns for consistent coding.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.