cmux
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill enables the agent to execute arbitrary shell commands in terminal panes (
cmux send), define startup commands for new workspaces (cmux new-workspace --command), and pipe terminal output to shell processes (cmux pipe-pane). - [PROMPT_INJECTION]: The skill instructions in
SKILL.mdinclude a 'Companion check' that directs the agent to perform directory listings on local skill paths (e.g.,~/.claude/skills/,~/.agent/skills/) to identify installed tools and prompt the user for additional installations. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted data from external sources (terminal screen output and browser accessibility snapshots) without implementing boundary markers or sanitization procedures.
- Ingestion points: Use of
cmux read-screen(found inSKILL.md) andcmux browser snapshot(found inreferences/browser-automation.md) to read content from terminal surfaces and web pages. - Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions to isolate external data from the agent's core logic.
- Capability inventory: High. The agent has access to powerful tools including shell command execution (
cmux send), workspace automation (cmux new-workspace --command), and browser-side JavaScript evaluation (cmux browser eval). - Sanitization: Absent. No logic is provided to filter, escape, or validate content retrieved from terminal outputs or browser snapshots before the agent processes it.
Audit Metadata