Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/suzu-testing/metasploit-cursor-harness/agents-mdgit clone --depth 1 https://github.com/Suzu-Testing/metasploit-cursor-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/suzu-testing/metasploit-cursor-harness/agents-md)<a href="https://agentmods.dev/instructions/suzu-testing/metasploit-cursor-harness/agents-md"><img src="https://agentmods.dev/badge/instructions/suzu-testing/metasploit-cursor-harness/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.02469 | $0.02469 |
| Opus 5 | $0.01234 | $0.01234 |
| Sonnet 5 | $0.00494 | $0.00494 |
| Haiku 4.5 | $0.00247 | $0.00247 |
Grade A, and why
metasploit-cursor-harness AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 156 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Metasploit Cursor Harness - Agent Context
Project Intent
This is an agentic penetration testing harness that bridges Cursor AI agents with the Metasploit Framework via MCP (Model Context Protocol). It provides structured, scope-enforced access to Metasploit RPC for reconnaissance, exploitation, session management, and post-exploitation.
Architecture
- MCP Server (
msf_harness/mcp/): Python FastMCP server exposing 54 tools over stdio - RPC Backend:
msfrpcdon 127.0.0.1:55553 via MessagePack RPC (WSL/Kali or native Linux) - Policy Layer (
msf_harness/mcp/policy/roe.py): Server-side CIDR/domain validation, module blocking, session limits, CIDR width caps, and check-before-exploit enforcement - Hooks (
.cursor/hooks/): PowerShell gates for scope enforcement, risk scoring, duplicate detection (world-state), and audit logging - Skills (
.cursor/skills/): 57 workflow playbooks for recon, exploitation, post-exploitation, and domain-specific testing - Subagents (
.cursor/agents/): Specialized agents for orchestration, recon, exploit chains, post-exploitation, and review
Prerequisites
- Python 3.10+ with
pip install -e ".[mcp]" - Metasploit Framework installed (WSL/Kali or native Linux)
- Start RPC:
./scripts/start-msfrpcd.sh(Linux) or.\scripts\start-msfrpcd.ps1(Windows/WSL) - Set
MSF_USERandMSF_PASSWORDin.env(copy from.env.example)
MCP Tools (54 total)
Read-Only Tools (no engagement_id required)
| Tool | Purpose |
|---|---|
msf_status |
Check RPC connectivity and version |
msf_search_modules |
Search Metasploit module database |
msf_module_info |
Get detailed module information |
msf_module_options |
Get only configurable options for a module |
msf_list_modules |
List modules by type with optional filter |
msf_running_stats |
Get running module statistics (waiting/running/results) |
msf_host_info |
Query discovered hosts |
msf_service_info |
Query discovered services |
msf_vulnerability_info |
Query vulnerability records |
msf_note_info |
Query notes/annotations |
msf_credential_info |
Query harvested credentials |
msf_loot_info |
Query collected loot |
msf_list_active_sessions |
List current sessions |
msf_session_info |
Get detailed info for a single session |
msf_list_listeners |
List active handlers/jobs |
msf_job_info |
Get details about a specific running job |
msf_list_payloads |
Search available payloads |
msf_compatible_payloads |
List payloads compatible with a module |
msf_get_lab_network |
Get lab target configuration |
msf_list_workspaces |
List database workspaces |
msf_db_status |
Check database connectivity and driver info |
msf_console_list |
List active RPC console instances |
msf_route_list |
List active routes for pivoting |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 156 lines · 2,469 tokens per session scan A 1013be999b20
metasploit-cursor-harness AGENTS.md is an instructions file published in the GitHub repository Suzu-Testing/metasploit-cursor-harness (3 stars, last pushed 11d ago), licensed MIT. It adds 2,469 tokens to every session, about $0.0123 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other instructions, from other repositories
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).