kali-tools-on-ubuntu-safe-path

Warn

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform high-privilege system modifications, including adding repository configuration files to /etc/apt/, managing system services via systemctl, and using setcap to modify binary capabilities.
  • [COMMAND_EXECUTION]: Establishes persistence on the host system by configuring a Docker container with the --restart unless-stopped flag, ensuring the containerized environment remains active across system reboots.
  • [EXTERNAL_DOWNLOADS]: Fetches a large Docker image (kalilinux/kali-rolling) and numerous software packages from external repositories. While these target official Kali Linux and Docker Hub sources, they involve the mass ingestion of external code.
  • [REMOTE_CODE_EXECUTION]: The skill's primary objective is the installation and execution of the kali-linux-everything meta-package, which introduces thousands of executable binaries into the environment, creating a vast attack surface and potential for remote code execution via these tools.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 19, 2026, 07:46 PM
Security Audit — agent-trust-hub — kali-tools-on-ubuntu-safe-path