dmux-workflows
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation recommends downloading and installing the
dmuxtool from a third-party GitHub repository (github.com/standardagents/dmux). - [COMMAND_EXECUTION]: The skill utilizes a local script
scripts/orchestrate-worktrees.jsthat executes shell commands within tmux panes. These commands are derived from aplan.jsonfile, allowing for arbitrary command execution based on the configuration. - [INDIRECT_PROMPT_INJECTION]: The orchestration workflow involves reading task instructions from a configuration file (
plan.json) and passing them to sub-agents. This creates a surface for indirect prompt injection if the plan is generated from untrusted external data. - Ingestion points: The
workersarray andlauncherCommandfield inplan.jsonserve as data entry points. - Boundary markers: None identified in the provided documentation or examples.
- Capability inventory: The system can spawn tmux sessions, execute shell commands via the launcher, manage git worktrees, and perform file writes for task management.
- Sanitization: No evidence of input validation or sanitization for the task strings or command templates was found.
- [DYNAMIC_EXECUTION]: The helper script uses template-based string interpolation (e.g.,
{worktree_path},{task_file}) to dynamically construct and execute commands at runtime based on the orchestration plan.
Audit Metadata