zellij-workspace-ops
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalyreferences/agent-sessions.md
LOWAnomalyLOW
references/agent-sessions.md
No direct evidence of malware (exfiltration/backdoor/reverse shell) is present in the provided content. However, the described workflow includes a sensitive control-plane mechanism that can rewrite what Zellij restarts (executed via `sh -c` and overwriting `session-layout.kdl`) and it previously suffered from incorrect substring-based matching that poisoned pane commands. Additionally, the agent launch examples use explicitly described “dangerously-*” permission/sandbox/approval bypass flags, increasing the impact of any agent-side compromise. Treat correctness of command rewriting/matching and the necessity of bypass flags as primary security review items.
Confidence: 62%Severity: 58%
Audit Metadata