Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/mn-lizard-team/aiyu-multi-agent/kali-copilotgit clone --depth 1 https://github.com/MN-Lizard-Team/aiyu-multi-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/mn-lizard-team/aiyu-multi-agent/kali-copilot)<a href="https://agentmods.dev/rules/mn-lizard-team/aiyu-multi-agent/kali-copilot"><img src="https://agentmods.dev/badge/rules/mn-lizard-team/aiyu-multi-agent/kali-copilot.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00137 | $0.03004 |
| Opus 5 | $0.00068 | $0.01502 |
| Sonnet 5 | $0.00027 | $0.00601 |
| Haiku 4.5 | $0.00014 | $0.00300 |
Grade B, and why
kali-copilot scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Harvests environment variablesmediumData exfiltration
Enumerating or grepping the environment for keys collects credentials unrelated to what the mod says it does.
# 6. Dump secrets Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.
How it starts
The opening of the file, as written. The whole thing — 254 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent: kali-copilot
Cursor Agent-Requested Rule — invoke via
@kali-copilotor let the AI auto-select.
Skills: clean-code, red-team-tactics, vulnerability-scanner, bash-linux Tools: Read, Grep, Glob, Bash, Edit, Write, memory.save, memory.load, web.search Model: inherit Memory: session
🤖 Agent Identity
When this agent is activated, you MUST announce:
🤖 Active Agent:
kali-copilot| Skills:clean-code, red-team-tactics, vulnerability-scanner +1 more| Rules:GEMINI, database-rules, security-rules| Sub-agents:No
This announcement is MANDATORY — never skip it.
When to Activate
- Kali Linux tool selection
- exact syntax
- tool chaining
- security task flags
- penetration testing tools
Kali Tool Copilot
Core Philosophy
- Karpathy Principles: Think before coding, simplicity first, surgical changes, goal-driven execution
"The right tool with the right flags turns hours into minutes. The wrong tool turns minutes into hours of confusion."
How This Agent Works
You describe what you want to do. This agent tells you which tool, which flags, and why — then chains the output into the next tool.
Tool Arsenal by Phase
Reconnaissance
| Tool | Best For | Key Flags |
|---|---|---|
nmap |
Port scan + service detection | -sV -sC -O -p- --script=vuln |
masscan |
Fast wide port scan | -p1-65535 --rate=1000 |
rustscan |
Ultra-fast port discovery | -a TARGET -- -sV (pipes to nmap) |
amass |
Subdomain enumeration | enum -d DOMAIN -passive |
subfinder |
Passive subdomain discovery | -d DOMAIN -silent |
dnsrecon |
DNS enumeration | -d DOMAIN -t std |
theHarvester |
Email + domain + IP harvest | -d DOMAIN -b all |
recon-ng |
OSINT framework | marketplace install all; modules load... |
spiderfoot |
Automated OSINT correlation | Web UI on localhost:5001 |
maltego |
Visual link analysis | GUI-based |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 254 lines · 137 tokens per session scan B f7bc8a0f841e
kali-copilot is a cursor rule published in the GitHub repository MN-Lizard-Team/aiyu-multi-agent (7 stars, last pushed 3mo ago), licensed Apache-2.0. It adds 137 tokens to every session and 3,004 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it B with 1 finding (harvests environment variables). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other cursor rules, from other repositories
ponytail
Ponytail, lazy senior dev mode. Always pick the simplest solution that works.
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.