Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/suzu-testing/metasploit-cursor-harness/memcache-pentestnpx skills add Suzu-Testing/metasploit-cursor-harness --skill memcache-pentestgit clone --depth 1 https://github.com/Suzu-Testing/metasploit-cursor-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/suzu-testing/metasploit-cursor-harness/memcache-pentest)<a href="https://agentmods.dev/skills/suzu-testing/metasploit-cursor-harness/memcache-pentest"><img src="https://agentmods.dev/badge/skills/suzu-testing/metasploit-cursor-harness/memcache-pentest.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00035 | $0.01869 |
| Opus 5 | $0.00017 | $0.00934 |
| Sonnet 5 | $0.00007 | $0.00374 |
| Haiku 4.5 | $0.00003 | $0.00187 |
Grade A, and why
memcache-pentest scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Runs shell commandslowCapability
Expected in a hook, worth knowing in a rule or an instructions file.
return (os.system, ('id',)) How it starts
The opening of the file, as written. The whole thing — 244 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Memcache Pentest
Prerequisites
- Target is in scope (
scope/scope-master.txt, engagement ROE). - Web targets with exposed cache: load
web-app-pentest. - Do not run amplification attacks.
auxiliary/dos/*modules are forbidden by ROE.
Ports and detection
| Port | Service |
|---|---|
| 11211/tcp | Memcached |
| 11211/udp | Memcached (amplification vector, document only) |
Service fingerprint
MSF MCP (preferred):
msf_run_auxiliary_module(
module_name="auxiliary/scanner/memcached/memcached_amp",
engagement_id="<id>",
options={"RHOSTS": "<target>", "RPORT": 11211}
)
CLI fallback:
nmap -n -sV --script memcached-info -p 11211 <target>
echo "version" | nc -vn -w 1 <target> 11211
echo "stats" | nc -vn -w 1 <target> 11211
Workflow
Task Progress:
- [ ] Version and stats enumeration
- [ ] SASL auth testing
- [ ] Slab and key discovery (TCP and UDP)
- [ ] Cached data extraction
- [ ] Deserialization chain assessment
- [ ] Document findings
Stats and version enumeration
MSF MCP (preferred):
msf_run_auxiliary_module(
module_name="auxiliary/gather/memcached_extractor",
engagement_id="<id>",
options={"RHOSTS": "<target>", "RPORT": 11211}
)
CLI fallback:
echo "version" | nc -vn -w 1 <target> 11211
echo "stats" | nc -vn -w 1 <target> 11211
echo "stats slabs" | nc -vn -w 1 <target> 11211
echo "stats items" | nc -vn -w 1 <target> 11211
memcstat --servers=<target>
SASL auth testing
MSF: No direct module; use CLI.
CLI fallback:
# Check if SASL required
echo "stats" | nc -vn <target> 11211
# CLIENT ERROR: auth required
echo -e "stats\r\n" | nc -vn <target> 11211
# Brute SASL credentials (when enabled)
# Using memcached-tool or custom script with SASL PLAIN
python3 -c "
import socket, base64
s = socket.create_connection(('<target>', 11211))
s.send(b'sasl plain\r\n')
# Send base64 null-separated auth string
auth = base64.b64encode(b'\\x00user\\x00pass').decode()
s.send(f'{len(auth)}\\r\\n{auth}\\r\\n'.encode())
print(s.recv(4096))
"
# libmemcached with SASL
memcstat --servers=<target> --username=user --password=pass
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 244 lines · 35 tokens per session scan A 0778cc141b1b
memcache-pentest is a skill published in the GitHub repository Suzu-Testing/metasploit-cursor-harness (3 stars, last pushed 12d ago), licensed MIT. It adds 35 tokens to every session and 1,869 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (runs shell commands). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
pinecone
Managed vector DB for production RAG and search.
redis-inspect
Inspect Redis cache keys, values, and TTLs for debugging. Supports both main cache and system cache. Use for debugging cache issues, checking cached values, and monitoring cache state. Read-only by default.
redis-js
Work with the Upstash Redis JavaScript/TypeScript SDK for serverless Redis operations. Use for caching, session storage, rate limiting, leaderboards, full-text search (querying, filtering, aggregating with @upstash/redis search extension), and all Redis data structures. Supports automatic serialization/deserialization…
using-redis-token-buckets
Use when adding a bucket-like rate limit backed by Redis: a per-caller budget with burst capacity and continuous refill, a refund path for requests that did no work, or a limit whose Retry-After must be a real wait rather than a window edge. posthog/tokenbucket.py provides an atomic Lua token bucket (consume, refund…
byted-milvus
Manages Milvus on Volcano Engine (Volcengine): provision/inspect/scale/delete clusters and run collection + CRUD/search operations via bundled CLIs. Use when the user mentions Milvus + Volcengine/Volcano Engine or asks to operate Milvus there.
vector-db
Vector database expert for embeddings, similarity search, RAG patterns, and indexing strategies.