dmux-workflows
Warn
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends the global installation of the
dmuxpackage (npm install -g dmux) from an unverified third-party source (github.com/standardagents/dmux). This introduces a supply-chain risk as the package's security and integrity are not guaranteed by a trusted vendor. - [COMMAND_EXECUTION]: The orchestration helper script
scripts/orchestrate-worktrees.jsdynamically executes shell commands defined in thelauncherCommandfield of aplan.jsonfile. This creates a significant attack surface where an agent could be tricked into executing arbitrary or malicious commands if it processes a plan file provided by an untrusted source. - [COMMAND_EXECUTION]: The skill manages parallel agent sessions by programmatically creating tmux panes and injecting commands into them. This execution pattern provides an opportunity for indirect injection where attacker-controlled data in a task file could influence the command-line arguments used to launch worker processes.
Audit Metadata