busybox-on-windows

Fail

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads binary executables from an unverified external source (frippery.org).
  • Evidence: 'Invoke-WebRequest -Uri https://frippery.org/files/busybox/busybox.exe -OutFile busybox.exe'
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and subsequently run an external binary (busybox.exe) to execute UNIX commands on Windows.
  • Evidence: 'Usage: Prefix the UNIX command with busybox.exe, for example: busybox.exe ls -1'
  • [COMMAND_EXECUTION]: The skill uses PowerShell commands to query system hardware information and registry keys, and to perform network downloads.
  • Evidence: 'Get-CimInstance -ClassName Win32_Processor', 'Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"'
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — busybox-on-windows