powertoys-module-verification

Warn

Audited by Socket on Jun 27, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/pt-nonelevated.ps1

Likely a benign test/utility for integrity-level dependent process visibility using one-shot Scheduled Tasks. No direct indicators of malware (exfiltration, persistence, keylogging, or network activity) are present in this fragment. However, the capture function generates and executes a cmd.exe-run .cmd wrapper that embeds caller-controlled $Arguments without robust cmd escaping, creating a meaningful command/shell injection risk if inputs are untrusted. $OutFile is also used for deletion and redirection, which can enable user-permission file overwrite/targeting. Use only with trusted, sanitized inputs.

Confidence: 72%Severity: 55%
Audit Metadata
Analyzed At
Jun 27, 2026, 07:59 AM
Package URL
pkg:socket/skills-sh/microsoft%2FPowerToys%2Fpowertoys-module-verification%2F@b602461d183b65bfc08a65b005eb19ba07018aebea59cc2fcc83dc7a78acccd7
Security Audit — socket — powertoys-module-verification