busybox-on-windows
Fail
Audited by Socket on Apr 15, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill's purpose and capabilities are mostly aligned, but it instructs direct download and execution of a third-party Windows binary from mutable URLs without checksum verification. Provenance is partially verifiable and no credential theft or exfiltration is evident, so this is better classified as supply-chain risk than malware.
Confidence: 87%Severity: 62%
Audit Metadata