Suzu-Testing/metasploit-cursor-harness

Agentic penetration testing harness bridging Cursor AI agents with Metasploit Framework via MCP

3Stars on the repository
67Mods indexed here, across every type
9d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

ai-llm-pentest

01

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides AI and LLM application security testing including prompt injection, system prompt extraction, tool/function abuse, MCP server testing, and data exfiltration via LLM features. Use for chatbots, agents, and AI-integrated apps.

not rated 3 9d ago F 55 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides binary exploitation including stack overflow, ROP, format strings, heap basics, pwntools, and GDB analysis. Use when engagement ROE explicitly authorizes custom exploit development beyond Metasploit modules.

not rated 3 9d ago A 49 tokens original MIT

blockchain-pentest

03

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides blockchain and smart contract security testing with reentrancy, flash loan, and access control analysis using Slither and EVM tooling. Use when auditing Solidity contracts, DeFi protocols, EVM dApps, or Web3 signing workflows in engagement scope.

not rated 3 9d ago A 57 tokens original MIT

cloud-pentest

04

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides cloud penetration testing for AWS, Azure, and GCP enumeration, credential abuse, metadata SSRF, storage misconfigurations, IAM privilege escalation, and cloud lateral movement from web or internal footholds.

not rated 3 9d ago B 46 tokens original MIT

cmdi-pentest

05

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides OS command injection testing with shell metacharacter probes, blind exfiltration, filter bypass, and OS-specific syntax. Use when inputs reach shell commands such as ping, nslookup, file conversion, or when shell metacharacters alter application behavior.

not rated 3 9d ago A 57 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides container and DevOps penetration testing for Docker escape, Kubernetes abuse, CI/CD pipeline secrets, package manager poisoning, and secrets enumeration from footholds or exposed services.

not rated 3 9d ago B 40 tokens original MIT

database-pentest

07

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides database penetration testing for MSSQL, MySQL, PostgreSQL, MongoDB, Redis, and Elasticsearch. Use when database ports are open, SQL injection yields DB access, or linked-server abuse is suspected.

not rated 3 9d ago A 47 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides insecure deserialization testing with format identification, language-specific gadget chains, and ysoserial/phpggc tooling. Use when Java, .NET, PHP, Python, or Ruby serialized objects appear in cookies, headers, APIs, or base64-encoded parameters including ViewState.

not rated 3 9d ago A 62 tokens original MIT

dns-pentest

09

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides DNS name resolution service penetration testing. Use when port 53 is discovered during scanning or when DNS is identified on a target.

not rated 3 9d ago A 31 tokens original MIT

forensics-pentest

10

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides digital forensics methodology for disk images, memory dumps, pcaps, and artifact analysis. Use when analyzing evidence to support incident response, malware triage, or pentest finding validation.

not rated 3 9d ago A 44 tokens original MIT

ftp-pentest

11

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides FTP file transfer service penetration testing. Use when port 21 is discovered during scanning or when FTP is identified on a target.

not rated 3 9d ago B 31 tokens original MIT

graphql-pentest

12

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides GraphQL injection and authorization testing with introspection, field enumeration, batch attacks, and nested query abuse. Use when GraphQL endpoints, introspection, or query syntax are discovered.

not rated 3 9d ago A 42 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides network and service penetration testing after port discovery. Provides port-to-skill routing, per-service quick reference, and general enumeration methodology for services with and without dedicated harness skills.

not rated 3 9d ago A 42 tokens original MIT

hardware-pentest

14

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides hardware and physical access penetration testing with UART/JTAG/SPI analysis, firmware extraction, and logic analyzer techniques. Use when engagement ROE includes firmware extraction, debug interface access, or physical device compromise.

not rated 3 9d ago A 46 tokens original MIT

idor-pentest

15

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Insecure Direct Object Reference testing with ID manipulation, parameter pollution, and horizontal/vertical privilege escalation techniques. Use when predictable IDs in URLs, sequential numbers, UUIDs, or authorization bypass indicators appear.

not rated 3 9d ago A 46 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides initial access techniques including external attack surface mapping, credential abuse, phishing delivery chains, and client-side payload planning. Use during external engagement phases before exploitation.

not rated 3 9d ago A 37 tokens original MIT

internal-ad-pentest

17

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Active Directory and internal network penetration testing for AD enumeration, Kerberos abuse, relay attacks, ADCS exploitation, lateral movement, domain dominance, and MSSQL attacks in domain environments.

not rated 3 9d ago A 43 tokens original MIT

jwt-pentest

18

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides JSON Web Token attack testing with algorithm confusion, signature bypass, header injection, and secret brute force techniques. Use when Bearer tokens, Authorization headers with eyJ prefix, or JWT cookies are observed during web or API testing.

not rated 3 9d ago A 51 tokens original MIT

ldap-pentest

19

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides LDAP directory service penetration testing. Use when port 389 or 636 is discovered during scanning or when LDAP/Active Directory is identified.

not rated 3 9d ago A 33 tokens original MIT

lfi-pentest

20

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides local and remote file inclusion testing with traversal payloads, PHP wrappers, log poisoning, and LFI-to-RCE chains. Use when parameters like page, file, include, or path accept filenames or traversal sequences.

not rated 3 9d ago A 50 tokens original MIT

linux-pentest

21

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Linux penetration testing for privesc, persistence, container host escape, SUID/capabilities abuse, cron, kernel exploits, and post-ex on Linux sessions.

not rated 3 9d ago B 39 tokens original MIT

macos-pentest

22

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides macOS penetration testing when ROE includes macOS endpoints. Covers privesc, TCC bypass, keychain abuse, sandbox escape, launch daemon abuse, dylib hijacking, and XPC/Mach service abuse on Intel and Apple Silicon.

not rated 3 9d ago A 57 tokens original MIT

memcache-pentest

23

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Memcached in-memory cache penetration testing. Use when port 11211 is discovered during scanning or when Memcached is identified on a target.

not rated 3 9d ago A 35 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Central reference for pentest methodology, cross-cutting cheatsheets, reverse shells, file transfer, hash cracking, network discovery, and common tool syntax. Use during recon, threat modeling, post-exploit, and reporting when any domain skill needs quick operational references.

not rated 3 9d ago A 58 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: