busybox-on-windows

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This document is a Windows-focused usage guide that instructs the user to download and run a BusyBox binary from a third-party host. The document itself contains no embedded malicious code or hard-coded credentials, but it explicitly recommends a download-and-execute flow without any integrity or provenance verification. That pattern constitutes a moderate supply-chain risk: a compromised or malicious remote binary can perform arbitrary malicious actions once executed. Recommend adding pinned versions, cryptographic verification (hashes and signatures), guidance to prefer official/signed distributions or building from source, avoiding silent automated downloads, and treating the downloaded binary as untrusted until verified.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 08:44 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fbusybox-on-windows%2F@9b2bdb0c9ff13c3b0bf3552d0c7546c7998bc013