busybox-on-windows
Fail
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
Invoke-WebRequestto download executable files (busybox.exe,busybox64.exe, etc.) fromhttps://frippery.org/files/busybox/. This domain is not a recognized trusted vendor or well-known service according to defined safety parameters. - [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute the downloaded binary to perform system operations (e.g.,
busybox.exe --list). Running untrusted binaries downloaded at runtime is a high-risk activity that can lead to arbitrary code execution on the host system.
Recommendations
- AI detected serious security threats
Audit Metadata