From 318b54ccfce1b985a1484d6896da0b3348229061 Mon Sep 17 00:00:00 2001 From: Ahmed Allam Date: Wed, 22 Jul 2026 11:30:39 +0000 Subject: [PATCH] sandbox: multi-stage build + drop ZAP/uv, dedupe ast-grep (~2.7GB) --- containers/Dockerfile | 48 ++++++++++++++++-------- strix/agents/prompts/system_prompt.jinja | 3 +- 2 files changed, 33 insertions(+), 18 deletions(-) diff --git a/containers/Dockerfile b/containers/Dockerfile index e6977d76..ed3a58d4 100644 --- a/containers/Dockerfile +++ b/containers/Dockerfile @@ -1,3 +1,26 @@ +# --------------------------------------------------------------------------- +# Builder stage: compile the Go tools here so the Go toolchain (~225MB) and the +# module/build caches never reach the runtime image. The resulting binaries are +# statically linked and copied into the final stage. +# --------------------------------------------------------------------------- +FROM kalilinux/kali-rolling:latest AS gobuilder + +RUN apt-get update && \ + apt-get install -y kali-archive-keyring && \ + apt-get update && \ + apt-get install -y --no-install-recommends golang-go git ca-certificates + +ENV GOBIN=/out/bin +RUN mkdir -p /out/bin && \ + go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest && \ + go install -v github.com/projectdiscovery/katana/cmd/katana@latest && \ + go install -v github.com/projectdiscovery/cvemap/cmd/vulnx@latest && \ + go install -v github.com/jaeles-project/gospider@latest && \ + go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest + +# --------------------------------------------------------------------------- +# Runtime stage +# --------------------------------------------------------------------------- FROM kalilinux/kali-rolling:latest LABEL description="AI Agent Penetration Testing Environment with Comprehensive Automated Tools" @@ -17,12 +40,11 @@ RUN mkdir -p /home/pentester/tools /app/certs && \ RUN apt-get update && \ apt-get install -y --no-install-recommends \ - wget curl git vim nano unzip tar \ + wget curl git nano unzip tar \ apt-transport-https ca-certificates gnupg lsb-release \ - build-essential software-properties-common \ - gcc libc6-dev pkg-config libpcap-dev libssl-dev \ - python3 python3-pip python3-dev python3-venv python3-setuptools \ - golang-go \ + software-properties-common \ + gcc libc6-dev \ + python3 python3-pip python3-venv python3-setuptools \ net-tools dnsutils whois \ file xxd \ jq parallel ripgrep grep \ @@ -61,17 +83,11 @@ USER root RUN cp /app/certs/ca.crt /usr/local/share/ca-certificates/ca.crt && \ update-ca-certificates -RUN curl -LsSf https://astral.sh/uv/install.sh | env UV_INSTALL_DIR=/usr/local/bin sh - USER pentester WORKDIR /tmp -RUN go install -v github.com/projectdiscovery/httpx/cmd/httpx@latest && \ - go install -v github.com/projectdiscovery/katana/cmd/katana@latest && \ - go install -v github.com/projectdiscovery/cvemap/cmd/vulnx@latest && \ - go install -v github.com/jaeles-project/gospider@latest && \ - go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest && \ - go clean -cache -modcache +# Go tools are built in the gobuilder stage; copy the static binaries only. +COPY --from=gobuilder --chown=pentester:pentester /out/bin/ /home/pentester/go/bin/ RUN nuclei -update-templates @@ -89,7 +105,9 @@ RUN npm install -g retire@latest && \ npm install -g @ast-grep/cli@latest && \ npm install -g tree-sitter-cli@latest && \ npm install -g agent-browser@0.26.0 && \ - npm cache clean --force + npm cache clean --force && \ + # ast-grep ships two identical binaries (`ast-grep` and `sg`); dedupe (~52MB) + ln -sf ast-grep /home/pentester/.npm-global/lib/node_modules/@ast-grep/cli/sg ENV AGENT_BROWSER_EXECUTABLE_PATH=/usr/bin/chromium ENV AGENT_BROWSER_USER_AGENT="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" @@ -148,8 +166,6 @@ RUN set -eux; \ install -m 0755 /tmp/gitleaks /usr/local/bin/gitleaks; \ rm -f /tmp/gitleaks /tmp/gitleaks.tgz -RUN apt-get update && apt-get install -y zaproxy - RUN curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin RUN apt-get install -y wapiti diff --git a/strix/agents/prompts/system_prompt.jinja b/strix/agents/prompts/system_prompt.jinja index 8ae6632b..fe82bc06 100644 --- a/strix/agents/prompts/system_prompt.jinja +++ b/strix/agents/prompts/system_prompt.jinja @@ -196,7 +196,7 @@ EFFICIENCY TACTICS: - For Caido proxy automation inside Python, explicitly import from `caido_api`: `from caido_api import list_requests, view_request, repeat_request, list_sitemap, view_sitemap_entry, scope_rules` -- Prefer established fuzzers/scanners where applicable: ffuf, sqlmap, zaproxy, nuclei, wapiti, arjun, httpx, katana, semgrep, bandit, trufflehog, nmap. Use scripts mainly to coordinate or validate around them, not to replace them without reason +- Prefer established fuzzers/scanners where applicable: ffuf, sqlmap, nuclei, wapiti, arjun, httpx, katana, semgrep, bandit, trufflehog, nmap. Use scripts mainly to coordinate or validate around them, not to replace them without reason - For trial-heavy vectors (SQLi, XSS, XXE, SSRF, RCE, auth/JWT, deserialization), DO NOT iterate payloads manually in the browser. Always spray payloads via Python scripts through `exec_command` or terminal tools. - When using established fuzzers/scanners, use the proxy for inspection where helpful - Generate/adapt large payload corpora: combine encodings (URL, unicode, base64), comment styles, wrappers, time-based/differential probes. Expand with wordlists/templates @@ -412,7 +412,6 @@ VULNERABILITY ASSESSMENT: - nuclei - Vulnerability scanner with templates - sqlmap - SQL injection detection/exploitation - trivy - Container/dependency vulnerability scanner -- zaproxy - OWASP ZAP web app scanner - wapiti - Web vulnerability scanner WEB FUZZING & DISCOVERY: