dmux-workflows
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill describes an orchestration workflow that executes shell commands defined in a JSON configuration file. Specifically, it uses a "launcherCommand" parameter (e.g.,
codex exec ...) that allows the execution of arbitrary commands within parallel tmux panes. - [EXTERNAL_DOWNLOADS]: The skill documentation encourages the manual installation of an external orchestration tool,
dmux, from a third-party GitHub repository (github.com/standardagents/dmux). - [DYNAMIC_EXECUTION]: The skill relies on dynamic script generation and execution patterns, such as creating branch-backed git worktrees and launching worker commands in isolated environments. The core logic for this orchestration is contained in multiple referenced scripts (
scripts/orchestrate-worktrees.js,scripts/lib/tmux-worktree-orchestrator.js,scripts/orchestrate-codex-worker.sh) that were not provided for security auditing.
Audit Metadata