tmux

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign-to-moderately-suspicious: The skill description outlines a legitimate tool for orchestrating tmux sessions and capturing pane output for automation. The primary security concern is data exposure: captured pane outputs can leak sensitive information if shown in credentials or secrets, and the ability to enumerate and control multiple tmux sessions across a socket could enable broad access within the same context. There are no hard-coded secrets, external download patterns, or credential-forwarding behaviors evident in the fragment. To reach a benign classification, ensure explicit access controls, auditing/logging of tmux actions, least-privilege socket scoping, and clear isolation between sessions. Given the potential for pane content leakage and broad session control, the risk should be treated as moderate until mitigations are documented.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:22 PM
Package URL
pkg:socket/skills-sh/insight68%2Fskills%2Ftmux%2F@016cde76ad5ed83bc46f52184820d3eae830ff89
Security Audit — socket — tmux