dmux-workflows

Warn

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends the global installation of the dmux package (npm install -g dmux) from an unverified third-party source (github.com/standardagents/dmux). This introduces a supply-chain risk as the package's security and integrity are not guaranteed by a trusted vendor.
  • [COMMAND_EXECUTION]: The orchestration helper script scripts/orchestrate-worktrees.js dynamically executes shell commands defined in the launcherCommand field of a plan.json file. This creates a significant attack surface where an agent could be tricked into executing arbitrary or malicious commands if it processes a plan file provided by an untrusted source.
  • [COMMAND_EXECUTION]: The skill manages parallel agent sessions by programmatically creating tmux panes and injecting commands into them. This execution pattern provides an opportunity for indirect injection where attacker-controlled data in a task file could influence the command-line arguments used to launch worker processes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — dmux-workflows