tmux

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities are broadly aligned with its stated purpose, and its data flow appears local and coherent. The main risk is not hidden exfiltration but high-impact autonomy: it launches multiple background Devin subagents with `--permission-mode dangerous`, effectively multiplying a powerful agent’s ability to act without granular approval. Official installer trust is only a low/medium supply-chain concern because the remote script appears same-org and documented.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 23, 2026, 11:18 PM
Package URL
pkg:socket/skills-sh/harivansh-afk%2Ftmux-subagents%2Ftmux%2F@7cdc6849c060e8205c1ebc20e3932cc87875eb68