busybox-on-windows
Fail
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads binary executables from an unverified external source (frippery.org).
- Evidence: 'Invoke-WebRequest -Uri https://frippery.org/files/busybox/busybox.exe -OutFile busybox.exe'
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download and subsequently run an external binary (busybox.exe) to execute UNIX commands on Windows.
- Evidence: 'Usage: Prefix the UNIX command with busybox.exe, for example: busybox.exe ls -1'
- [COMMAND_EXECUTION]: The skill uses PowerShell commands to query system hardware information and registry keys, and to perform network downloads.
- Evidence: 'Get-CimInstance -ClassName Win32_Processor', 'Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"'
Recommendations
- AI detected serious security threats
Audit Metadata