dmux-workflows

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation recommends downloading and installing the dmux tool from a third-party GitHub repository (github.com/standardagents/dmux).
  • [COMMAND_EXECUTION]: The skill utilizes a local script scripts/orchestrate-worktrees.js that executes shell commands within tmux panes. These commands are derived from a plan.json file, allowing for arbitrary command execution based on the configuration.
  • [INDIRECT_PROMPT_INJECTION]: The orchestration workflow involves reading task instructions from a configuration file (plan.json) and passing them to sub-agents. This creates a surface for indirect prompt injection if the plan is generated from untrusted external data.
  • Ingestion points: The workers array and launcherCommand field in plan.json serve as data entry points.
  • Boundary markers: None identified in the provided documentation or examples.
  • Capability inventory: The system can spawn tmux sessions, execute shell commands via the launcher, manage git worktrees, and perform file writes for task management.
  • Sanitization: No evidence of input validation or sanitization for the task strings or command templates was found.
  • [DYNAMIC_EXECUTION]: The helper script uses template-based string interpolation (e.g., {worktree_path}, {task_file}) to dynamically construct and execute commands at runtime based on the orchestration plan.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — dmux-workflows