Should you click Run anyway?

The warnings in plain words, four questions to answer before you click, and a checksum check we ran so you can copy it.

An envelope closed with a wax seal
Photo by mk. s on Unsplashdithered by Cyborb

“Windows protected your PC” means Microsoft Defender SmartScreen does not recognize the app yet: the file has no track record, and often no code signature. It is a warning about the unknown, not a malware verdict. Clicking Run anyway is reasonable only when you know who made the file, downloaded it from their official site, and checked that it matches a checksum they publish.

This guide explains that warning and its Mac and Linux cousins, gives you four questions to answer before you click, and shows a checksum check with real output. Our worked example is Cyborb, a desktop AI agent from Orbioom. It is our product, and its Windows and Linux builds are unsigned betas.

The short version
  • The warning appears when SmartScreen has no reputation for a file. Unsigned apps always start there, and brand-new signed apps can too.
  • Click Run anyway only if four things hold: an official source, a warning the developer told you to expect, a matching checksum, and a developer you trust with your files.
  • A checksum is a file’s fingerprint. In our test, adding one character to a file changed its fingerprint completely.
  • On a Mac, apps Apple has not checked open through System Settings, Privacy & Security, Open Anyway. On Linux, an AppImage shows no warning at all, so the checks are yours.
  • Walk away from malware warnings, mismatched checksums, cracked software and anyone rushing you.

What does “Windows protected your PC” mean?

It means SmartScreen looked up the file’s reputation and found too little to vouch for it. Microsoft says SmartScreen weighs two signals: whether the file is signed by a known publisher, and whether this exact file has been downloaded by many people without trouble.

A code signature is the developer’s verified name, stamped on the file so that any later change breaks it. According to Microsoft’s documentation for developers:

  • Unsigned files get the “Windows protected your PC” screen. You have to choose More info, then Run anyway, and a workplace policy can remove that option.

  • Signed but new files still get a warning, but it shows the verified publisher’s name.

  • Reputation takes time. Microsoft says there is no exact threshold, and it can take several weeks and hundreds of clean installs.

  • Unsigned apps start over with every update, because reputation cannot carry across versions without a signature.

  • Extended Validation certificates no longer skip the warning. That shortcut was removed in 2024.

SmartScreen also warns when a file matches its list of programs reported as unsafe. That is a different situation: delete the file.

Windows 11 has a stricter layer called Smart App Control. It blocks unsigned apps unless they already have a good reputation, and Microsoft says there is no way to make an exception for a single app. The only way through is to turn Smart App Control off, which recent Windows updates let you undo later without reinstalling Windows.

The warnings you may see, compared

Each system handles unknown apps differently. Checked on September 28, 2026, against each vendor’s documentation.

What you seeWhereWhat it meansCan you continue?Source
“Windows protected your PC”Windows SmartScreenNo reputation yet, usually an unsigned fileYes: More info, then Run anyway, unless a policy blocks itMicrosoft
An unrecognized app warning showing a publisher nameWindows SmartScreenSigned, but the file is newYes, after checking the publisher is who you expectMicrosoft
A Smart App Control blockWindows 11Unsigned or untrusted appNo exception for one app; only by turning the feature offMicrosoft
Apple cannot check the app for malicious softwaremacOS GatekeeperApple has not checked this appYes: System Settings, Privacy & Security, Open AnywayApple
An app with malware was blocked and moved to the TrashmacOSKnown malwareNoApple
No warning; the file will not start until you allow itLinux AppImageNothing checked itYes, by making it executableAppImage

Is it safe to click Run anyway?

It is safe enough when all four statements below are true. If any is false, or you are not sure, stop. An app you run can do anything your account can do, including reading your documents, browser data and API keys.

Before you click Run anyway0 of 4

Microsoft gives developers the same advice from the other side: tell early users they may see a SmartScreen prompt, and that they should continue only after checking the publisher and the download source.

How do I verify a download’s checksum?

Compute the file’s checksum on your computer and compare it with the value the developer publishes. If every character matches, you have exactly the file the developer listed.

We ran this on a Mac with a small stand-in file, since this guide downloads no real installers. Many developers publish a .sha256 file next to the download, and -c checks your file against it:

Text
$ shasum -a 256 demo-installer.bin
b0bbd8640efc4b6806a2c9c53c63bd24215857e77c1125a06bb125d8ab49ba5d  demo-installer.bin

$ shasum -a 256 -c demo-installer.bin.sha256
demo-installer.bin: OK

$ printf "x" >> demo-installer.bin

$ shasum -a 256 -c demo-installer.bin.sha256
demo-installer.bin: FAILED
shasum: WARNING: 1 computed checksum did NOT match

$ shasum -a 256 demo-installer.bin
14bad11823bec9f936e335b791d56c63ac82e1a3799e2818a8157324440cc97a  demo-installer.bin

Adding a single letter to the end of the file changed the whole fingerprint. That is what makes a checksum useful: a corrupted, swapped or tampered file cannot quietly match.

On Linux, the same commands are sha256sum file and sha256sum -c file.sha256. On Windows, PowerShell’s Get-FileHash does the job. These lines follow Microsoft’s documentation; we did not run them on a Windows machine for this guide:

Text
Get-FileHash .\Downloads\app-setup.exe -Algorithm SHA256
(Get-FileHash .\Downloads\app-setup.exe).Hash -eq "PASTE-THE-PUBLISHED-VALUE"

The second line prints True or False. Microsoft’s own example compares a download against a published hash exactly this way.

What about a Mac: “Apple cannot check this app”?

That message comes from Gatekeeper, and it means Apple has not notarized the app. Notarization is Apple’s check of a developer’s software for known malicious content before release.

Apple’s own steps to open such an app, if you are sure of its source:

  1. Try to open the app once

    The warning appears and the app does not open. That is expected.

  2. Open Privacy & Security

    Go to System Settings, choose Privacy & Security, and scroll down.

  3. Click Open Anyway

    Confirm when the warning appears again. Apple saves the app as an exception, so it opens normally from then on.

Two other prompts look similar but mean different things. An app that is signed and notarized still asks once whether you want to open something downloaded from the internet; that is routine. An app that macOS moves to the Trash because it contains malware should stay there.

Linux: how do I run an AppImage safely?

Make the file executable, then run it. Linux shows no reputation warning for an AppImage, so every check in this guide is up to you.

Terminal
chmod +x my.AppImage
./my.AppImage

In a file manager, the same switch is a checkbox in the file’s properties, called “Allow executing file as program” in Files and “Is executable” in Dolphin. If you see an error saying AppImages require FUSE, install libfuse2 (named libfuse2t64 on Ubuntu 24.04), or run the file with --appimage-extract-and-run.

AppImages can carry a GPG signature, but running one does not check it. The AppImage project points to a separate validate tool for that, so for most people a checksum is the practical check.

Cyborb’s Windows and Linux builds are unsigned betas

Cyborb, our product, ships three desktop builds. The macOS build for Apple Silicon is signed and notarized by Apple. The Windows x64 and Linux x64 AppImage builds are unsigned betas, and our download page says so. Checked on September 28, 2026:

  • Windows: the page says SmartScreen may show “Windows protected your PC” on first run, and to choose More info, then Run anyway. It publishes each release’s file size and SHA-512 checksum at updates.cyborb.ai/latest.yml.

  • Linux: the page says to make the AppImage executable with chmod +x before opening it. The same kind of entry for the AppImage is in updates.cyborb.ai/latest-linux.yml.

Those checksums are SHA-512 values written in base64, a compact text encoding, rather than the more common hexadecimal. On Linux or a Mac, these lines compare your download with the published value. We tested them on a stand-in file, since we did not download the real installer:

Terminal
cd ~/Downloads
curl -fsSL https://updates.cyborb.ai/latest-linux.yml -o latest-linux.yml
expected=$(grep -m1 "sha512:" latest-linux.yml | awk '{print $2}')
actual=$(openssl dgst -sha512 -binary Cyborb-*.AppImage | openssl base64 -A)
[ "$expected" = "$actual" ] && echo "Checksum OK" || echo "MISMATCH: do not run this file"

Our stand-in printed Checksum OK, and after we added one character to it, MISMATCH: do not run this file. On Windows, these PowerShell lines do the same comparison with the value from latest.yml; as above, we could not run them on Windows:

Text
$expected = "PASTE-THE-sha512-VALUE-FROM-latest.yml"
$hex = [BitConverter]::ToString([Convert]::FromBase64String($expected)) -replace "-", ""
(Get-FileHash .\Downloads\Cyborb-*.exe -Algorithm SHA512).Hash -eq $hex

A quicker, weaker check is the file size: right-click the installer, choose Properties, and compare the size in bytes with the size line in the file. Because the checksum lives on the same domain as the download, it guards against a corrupted or swapped file, not against someone who controls cyborb.ai. A code signature closes that gap; the macOS build has one, and the Windows and Linux builds do not yet.

When to walk away

Reasonable to continue
  • You typed the developer’s address or came from their docs
  • The developer’s page warns you about this exact prompt
  • The checksum matches, character for character
  • You would trust this developer with your files anyway
Walk away
  • SmartScreen, Microsoft Defender or macOS says the file is malicious
  • The checksum does not match, even after a fresh download
  • The file came from an ad, a mirror, an email or a direct message
  • It is cracked software, or the installer asks you to turn off your antivirus
  • Someone is rushing you, or a page asks you to paste a command

The last two are classic scam patterns. Our guide to AI scams covers the pressure tactics, and our guide to curl | bash covers pasted commands.

FAQ

Is “Windows protected your PC” a virus warning?

No. It means SmartScreen has no reputation for the file yet, which is normal for unsigned or brand-new apps. It becomes a real warning sign when the source is doubtful or the checksum does not match.

How do I get past “Windows protected your PC”?

Click More info, check the publisher and file name, then click Run anyway. Do it only after the checks above. If there is no Run anyway button, a workplace policy or Smart App Control is blocking the app.

Does a signed app mean it is safe?

No. A signature proves who published the file and that nobody changed it afterwards. Apple’s notarization adds a scan for known malware. Neither proves the app behaves well, so the source still matters.

Should I turn off SmartScreen or Smart App Control to install one app?

We would not. They protect every later download too. If you do turn Smart App Control off, Microsoft says recent updates let you turn it back on without reinstalling Windows.

Is it safe to let an AI agent install apps for me?

Only with approvals switched on for installs, so you see every download before it runs. Our guide to letting an AI agent control your computer explains the settings that matter.

Key takeaways
  • “Windows protected your PC” means no reputation yet, not malware found.
  • Continue only with an official source, an expected warning, a matching checksum and a trusted developer.
  • Checksums catch swapped or corrupted files; signatures also prove who published them.
  • On a Mac, use Open Anyway only for apps whose source you are sure of.
  • On Linux, nothing warns you, so check the checksum before chmod +x.

Next, read how to check an install script before you run it, or get comfortable with the basics in the terminal for beginners.

Sources
  1. SmartScreen reputation for Windows app developers, Microsoft Learn, 2026
  2. Code signing options for Windows app developers, Microsoft Learn, August 2026
  3. Microsoft Defender SmartScreen overview, Microsoft Learn, April 2026
  4. What is Smart App Control?, Microsoft Support
  5. Get-FileHash, Microsoft Learn
  6. Safely open apps on your Mac, Apple Support, May 2026
  7. Gatekeeper and runtime protection in macOS, Apple Platform Security
  8. AppImage quickstart, AppImage documentation
  9. Errors related to FUSE, AppImage documentation
  10. Signing AppImages, AppImage documentation
  11. Download Cyborb, Orbioom, accessed September 2026
cyborb.ai

Stop reading about it. Build it.

Describe what you want in plain words. Cyborb plans the work, writes and runs the code, makes the assets, and puts the result online.

Download Cyborb

Free to start. No card required.