busybox-on-windows

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download binary executables from an external domain using PowerShell.
  • Evidence: Invoke-WebRequest -Uri https://frippery.org/files/busybox/busybox.exe -OutFile busybox.exe and variations for 64-bit/ARM architectures.
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to download an executable file from the internet and then execute it locally to perform various system commands.
  • Evidence: The usage section states, Prefix the UNIX command with busybox.exe, for example: busybox.exe ls -1 after providing download instructions.
  • [COMMAND_EXECUTION]: The skill utilizes PowerShell to perform system discovery and manage file downloads.
  • Evidence: Get-CimInstance -ClassName Win32_Processor and Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion" are used to extract hardware and OS metadata.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — busybox-on-windows