busybox-on-windows

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use PowerShell's Invoke-WebRequest to download executable files from https://frippery.org/files/busybox/.
  • [REMOTE_CODE_EXECUTION]: Following the download, the skill provides instructions to run the downloaded binary (busybox.exe) with various arguments. Downloading and executing arbitrary binaries from unverified third-party domains is a significant security risk, as the content of the executable cannot be verified by the system.
  • [COMMAND_EXECUTION]: The skill utilizes PowerShell to query system information (CPU and OS version) and execute the downloaded binary, demonstrating capabilities that could be abused if the downloaded source were malicious.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — busybox-on-windows