Hey everyone! π
When building JED AI (our cloud-native autonomous security platform at https://jedcorp.ink), one of the biggest engineering hurdles wasn't just getting an LLM to chat about securityβit was building a reliable backend bridge to actual command-line utilities.
Standard security workflows require jumping between terminals, managing local dependencies, and manually chaining tools like Nmap, Amass, and SQLMap. To fix this, we built The Kali Armory: a unified, cloud-hosted execution environment integrated directly into our ReAct agent pipeline.
Here is a quick look at how we architected it and why moving terminal tools into a browser-based agent changes the game.
π‘οΈ What is the Kali Armory?
Instead of forcing developers and security researchers to juggle local Kali Linux environments or container setups for every scan, the Kali Armory integrates 33+ core security tools directly into JED AI's backend architecture.
When a user issues a natural language or voice directive (e.g., "Perform a stealth port scan and check headers"), the autonomous agent:
- Parses Intent: Decides which tools are required for the task.
- Chains Execution: Sequentially runs utilities (such as Amass for subdomain enumeration followed by Nmap for port mapping).
-
Streams Telemetry Live: Captures raw
stdoutandstderrstreams, piping them directly to the frontend via Server-Sent Events (SSE).
βοΈ The Technical Challenge: Safety & Process Isolation
Running arbitrary or powerful CLI security tools via an automated backend agent introduces massive risks, particularly command injection and resource starvation.
To keep the system secure and stable, we implemented:
- Strict Parameter Sanitization: User inputs and agent-generated arguments are heavily validated before being passed to subprocess wrappers.
- Isolated Execution Wrappers: Every tool invocation runs within controlled Python subprocess boundaries, capturing outputs safely without exposing the host server.
- Lightweight Telemetry Loop: Long-running scans don't block the web server. Gunicorn manages concurrent worker threads while state is tracked efficiently via SQLite.
π Try It Out
The Kali Armory is fully integrated into the live JED AI platform, which currently supports 1.2k registered users, over 10k executed scans, and 15k+ identified findings.
You can check out the live sandbox and platform here:
- Live Platform: https://jedcorp.ink
- GitHub Repository: https://github.com/jed254silk
How do you handle tool orchestration or process isolation in your own security automation scripts? Let's discuss in the comments below! π
Top comments (0)