busybox-on-windows

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill provides a coherent Windows-focused BusyBox usage guide that relies on downloading an external binary and executing it locally. While the intended functionality (Unix-like tool availability on Windows) is reasonable, the use of an unverifiable external binary from a non-official domain introduces notable supply-chain risk. There is no evidence of credential harvesting, data exfiltration, or destructive actions, but the download-execute pattern from an unverified source elevates risk. Treat as suspicious due to unverifiable binary distribution; mitigate by offering verified hashes, official registry distribution, or signing, and clearly document trust boundaries.

Confidence: 98%Severity: 65%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:14 AM
Package URL
pkg:socket/skills-sh/claudiodearaujo%2Fizacenter%2Fbusybox-on-windows%2F@d1591726a2fec0b3008e15da72f90466f62d946f