Red-Teaming the Agentic Red-Team
The first comprehensive security evaluation of widely-used agentic systems built for offensive security work. We show these tools contain design flaws that let adversaries exfiltrate API keys, establish persistent footholds, and fully compromise the operator's machine — even when the agent runs inside a sandboxed container. We present a full cyber kill chain from LLM manipulation through sandbox escape, then propose a secure architecture and design principles to fix these vulnerabilities at the foundational level.