Running every piece of code with the same level of privilege is the root of many problems.
Returning too much information about error to the user is usually a bad idea.
Now that WSL2 has a real full Linux Kernel using Kali Linux in WSL2 is a nice option to have.
When you experiment with security, it is useful to have a safe environment isolated from your production machines.
Always limit what a user can send to your API for better security