Atlas / MCP servers / gh05tcrew / Metasploit

MetasploitSAFE

mcp/gh05tcrew/metasploit

MCP Server for Metasploit

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 5r · 6w · 1d
Transport
stdio
License
Apache-2.0
Stars
733
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for Metasploit Framework integration.

https://github.com/user-attachments/assets/39b19fb5-8397-4ccd-b896-d1797ec185e1

Description

This MCP server provides a bridge between large language models like Claude and the Metasploit Framework penetration testing platform. It allows AI assistants to dynamically access and control Metasploit functionality through standardized tools, enabling a natural language interface to complex security testing workflows.

Features

Module Information

  • list_exploits: Search and list available Metasploit exploit modules
  • list_payloads: Search and list available Metasploit payload modules with optional platform and architecture filtering

Exploitation Workflow

  • run_exploit: Configure and execute an exploit against a target with options to run checks first
  • run_auxiliary_module: Run any Metasploit auxiliary module with custom options
  • run_post_module: Execute post-exploitation modules against existing sessions

Payload Generation

  • generate_payload: Generate payload files using Metasploit RPC (saves files locally)

Session Management

  • list_active_sessions: Show current Metasploit sessions with detailed information
  • send_session_command: Run a command in an active shell or Meterpreter session
  • terminate_session: Forcefully end an active session

Handler Management

  • list_listeners: Show all active handlers and background jobs
  • start_listener: Create a new multi/handler to receive connections
  • stop_job: Terminate any running job or handler

Prerequisites

  • Metasploit Framework installed and msfrpcd running
  • Python 3.10 or higher
  • Required Python packages (see requirements.txt)

Installation

  1. Clone this repository
  2. Install dependencies:
pip install -r requirements.txt
  1. Configure environment variables (optional):
MSF_PASSWORD=yourpassword
MSF_SERV
Read from source at commit 58dcae53f10bOBSERVED · 2026-09-28
02

Exposed tools (12)

5 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
generate_payloadread
list_active_sessionsreadList active Metasploit sessions with their details.
list_exploitsread
list_listenersreadList all active Metasploit jobs, categorizing exploit/multi/handler jobs.
list_payloadsread
run_auxiliary_modulewrite
run_exploitwrite
run_post_modulewrite
send_session_commandwrite
start_listenerwrite
stop_jobwrite
terminate_sessiondestructive
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
terminate_session
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastapi, uvicorn, pymetasploit3, mcp, fastmcp
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 58dcae53f10bfull audit observations/trust-audit/mcp-server/gh05tcrew__metasploit.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2858dcae53f10bSAFEB89first audit
05

Questions

What is the Metasploit MCP server?

MCP Server for Metasploit

What tools does Metasploit expose?

12 in total: 5 read-only, 6 that write, and 1 that can delete or overwrite (terminate_session). Every one is listed on this page with its risk.

Is Metasploit safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Metasploit need?

It reads MSF_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Metasploit run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (58dcae53f10b), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement