kali-tools-on-ubuntu-safe-path
Warn
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform high-privilege system modifications, including adding repository configuration files to
/etc/apt/, managing system services viasystemctl, and usingsetcapto modify binary capabilities. - [COMMAND_EXECUTION]: Establishes persistence on the host system by configuring a Docker container with the
--restart unless-stoppedflag, ensuring the containerized environment remains active across system reboots. - [EXTERNAL_DOWNLOADS]: Fetches a large Docker image (
kalilinux/kali-rolling) and numerous software packages from external repositories. While these target official Kali Linux and Docker Hub sources, they involve the mass ingestion of external code. - [REMOTE_CODE_EXECUTION]: The skill's primary objective is the installation and execution of the
kali-linux-everythingmeta-package, which introduces thousands of executable binaries into the environment, creating a vast attack surface and potential for remote code execution via these tools.
Audit Metadata