dmux-workflows

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill describes an orchestration workflow that executes shell commands defined in a JSON configuration file. Specifically, it uses a "launcherCommand" parameter (e.g., codex exec ...) that allows the execution of arbitrary commands within parallel tmux panes.
  • [EXTERNAL_DOWNLOADS]: The skill documentation encourages the manual installation of an external orchestration tool, dmux, from a third-party GitHub repository (github.com/standardagents/dmux).
  • [DYNAMIC_EXECUTION]: The skill relies on dynamic script generation and execution patterns, such as creating branch-backed git worktrees and launching worker commands in isolated environments. The core logic for this orchestration is contained in multiple referenced scripts (scripts/orchestrate-worktrees.js, scripts/lib/tmux-worktree-orchestrator.js, scripts/orchestrate-codex-worker.sh) that were not provided for security auditing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:41 AM
Security Audit — agent-trust-hub — dmux-workflows