Skip to content

OpenSpec setup, unofficial/Rapid7 disclaimers, and CI/release hardening - #17

Merged
setuidloot merged 5 commits into
mainfrom
claude/mcp-functionality-comparison-c63ab3
Jul 31, 2026
Merged

setuidloot merged 5 commits into
mainfrom
claude/mcp-functionality-comparison-c63ab3

Conversation

@setuidloot

@setuidloot setuidloot commented Jul 31, 2026 •

Copy link
Copy Markdown
Owner

Summary

Groundwork for the first public PyPI release of this fork (metasploit-mcp), managed via a newly-initialized OpenSpec workflow, plus remediation of all open Dependabot alerts.

1. OpenSpec initialization + change proposals (chore(openspec))

  • Initializes OpenSpec (spec-driven) with the /opsx:* command + skill integration under .claude/.
  • Adds two managed changes under openspec/changes/:

2. Unofficial status + Rapid7 disclaimers + owner rename (docs)

  • PyPI description and README lead with "unofficial"; explicit no affiliation / no support from Rapid7 notice (README + NOTICE); "Metasploit" acknowledged as a Rapid7 trademark.
  • Full credit to GH05TCREW as original author; this fork contributes additional features + the PyPI release.
  • Owner references cbdmaul → setuidloot (repo renamed) across pyproject.toml, README.md, server.json, MCP registry namespace; author set to setuidloot <michael@mccord.ai>.

3. CI quality gates + SBOM release integration (ci)

  • generate_sbom.py --check (drift detection); CI jobs for packaging build + twine check, black --check (blocking) with advisory mypy, and SBOM freshness; release verifies + attaches sbom.json. Docs + tests.

4. Security — Dependabot remediation (fix(security), fix(deps))

  • Critical — CVE-2026-5463 / GHSA-qpc3-8vqg-8g6w (pymetasploit3, no upstream fix): console command injection via newline characters in module options (e.g. RHOSTS). Mitigated in code: _reject_unsafe_option_chars() rejects newline / carriage-return / NUL in option names and values on both the RPC (_set_module_options) and console (_execute_module_console) paths, before any value is interpolated into a set command. Added unit + async tests.
  • 3× High (mcp): bumped mcp >=1.6.0 → >=1.28.1 (resolves to 1.29.0), clearing GHSA-vj7q-gjh5-988w, GHSA-jpw9-pfvf-9f58, GHSA-hvrp-rf83-w775.

Verification

  • Full test suite: 385 passed, 39 skipped (includes 9 new injection-guard tests + 6 SBOM tests).
  • black --check src tests, poetry build, twine check, generate_sbom.py --check all pass locally.

Notes / follow-ups

  • mypy is intentionally advisory for now (pre-existing backlog); flipping to blocking is tracked in the change's tasks.
  • PyPI Trusted Publisher must be registered under setuidloot/MetasploitMCP (workflow release.yml, env pypi) before first publish.
  • The 3 mcp alerts will auto-close once this merges to main. The critical pymetasploit3 alert has no upstream fix, so it will remain "open" in Dependabot despite the code mitigation — it should be dismissed as "risk mitigated in code / no fix available" after merge.

🤖 Generated with Claude Code

setuidloot and others added 5 commits July 31, 2026 12:20
Initialize OpenSpec (spec-driven schema) with the /opsx:* command and skill
integration, and add two managed changes:

- official-parity-and-mcp-modernization: reach feature parity with the official
  Rapid7 MCP (DB intel tools, module check, async results, safety gate) and
  adopt current MCP-spec features (annotations, structured output, elicitation,
  resources, FastMCP 3.x evaluation). Planning only — not yet implemented.
- release-and-ci-hardening: CI quality gates + SBOM release integration.
  Implemented in the following commits.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…dloot owner

- Prefix the PyPI description and README with "unofficial" and add a clear
  "not affiliated with / supported by Rapid7" notice (README + NOTICE).
- Credit GH05TCREW as the original author; frame this fork's contribution as
  additional features plus the PyPI release.
- Update owner/repository references from cbdmaul to setuidloot (repo renamed)
  across pyproject, README, server.json, and the MCP registry namespace; set
  author/maintainer to setuidloot <michael@mccord.ai>.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Close the release-pipeline gaps identified against the release-and-ci-hardening
OpenSpec change:

- generate_sbom.py: add a `--check` mode (fails if sbom.json has drifted from
  poetry.lock) and make status messages robust to an out-of-tree output path.
- CI (ci.yml): new jobs alongside the test matrix — packaging build + twine
  check, `black --check` (blocking) with advisory `mypy`, and SBOM freshness.
- Release (release.yml): verify SBOM freshness (fail-fast), upload it as a
  separate `sbom` artifact (kept out of dist/ so PyPI publish is unaffected),
  and attach sbom.json to the GitHub Release.
- Add `make sbom-check`; document the gates in RELEASING.md and CONTRIBUTING.md.
- Add tests for the SBOM generator and its --check mode.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
pymetasploit3 <=1.0.6 (GHSA-qpc3-8vqg-8g6w, no upstream fix) is vulnerable to
console command injection: newline characters in module options such as RHOSTS
terminate the intended `set <key> <value>` command and execute attacker-supplied
console commands. Our console execution path (`_execute_module_console`) built
`set` commands the same way and shared the exposure.

Add `_reject_unsafe_option_chars()` and apply it in both `_set_module_options`
(RPC path) and `_execute_module_console` (console path, incl. payload options),
rejecting newline / carriage-return / NUL in option names and values before any
value is interpolated into a console command. Add unit + async tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Raises the mcp floor from >=1.6.0 to >=1.28.1 (resolves to 1.29.0), clearing
three high-severity Dependabot alerts:
- GHSA-vj7q-gjh5-988w (WebSocket transport Host/Origin validation)
- GHSA-jpw9-pfvf-9f58 (HTTP transports serve requests without verifying principal)
- GHSA-hvrp-rf83-w775 (task handlers accessible across clients)

Re-locks dependencies, regenerates sbom.json, and records the security fixes
and release-prep changes under an Unreleased CHANGELOG section.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@setuidloot
setuidloot merged commit 129a83f into main Jul 31, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant