---
name: security-lab-boundaries
description: Where the line sits on the CAI/pentest security lab — what to help with vs refuse
metadata: 
  node_type: memory
  type: feedback
  originSessionId: 09013e0f-2e94-4156-8686-e27053e7e466
---

On 2026-07-04 Ahmed built out a security-testing lab (see [[cai-security-tooling]]) and,
over a Telegram thread, escalated from legit pentest interest toward surveillance/attack
asks. The boundary held and should stay consistent across sessions:

**Help with (authorized):** installing/using pentest tools, testing HIS OWN devices &
networks, learning on Juice Shop, USB/remote-access demos on machines he owns, consented
work (client with signed authorization), transparent parental controls / MDM-with-disclosure.

**Refuse (declined these):**
- USB implant/backdoor to compromise a "random PC" (unauthorized access). Recurred 2026-07-04
  as "a flash drive with a small CPU I can live in, SSH into, plug into a device, and run Kali
  tools to figure out what it is and how to get to it" — same ask, hardware-drop-box framing.
  Tell: if the pitch is "figure out what a device is and how to get in," it's not his device.
- WiFi/Bluetooth deauth against networks/devices not his (DoS; also VPS has no radio).
- Covert phone monitoring / stalkerware — pulling someone's WhatsApp/Snap/IG/TikTok messages,
  photos, calls, location, search history. This is the biggest one: it's spyware against a
  *person*, illegal (Saudi Anti-Cyber Crime Law), and harmful. Hard no regardless of whose phone.

**Why:** Authorization to operate the agent ≠ authorization to attack third parties or surveil
people. **How to apply:** Stay warm and keep him on the legit track (his own gear / consented
targets), name the specific law/harm briefly, offer the legal alternative, don't moralize at length.
