busybox-on-windows

Fail

Audited by Socket on Apr 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities are mostly aligned, but it instructs direct download and execution of a third-party Windows binary from mutable URLs without checksum verification. Provenance is partially verifiable and no credential theft or exfiltration is evident, so this is better classified as supply-chain risk than malware.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 15, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/cleodin%2Fantigravity-awesome-skills%2Fbusybox-on-windows%2F@d1591726a2fec0b3008e15da72f90466f62d946f
Security Audit — socket — busybox-on-windows