tmux

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is primarily designed to facilitate the execution of shell commands and interactive keystrokes within tmux panes using the tmux send-keys command.
  • Evidence: Examples provided in SKILL.md and tmux/SKILL.md demonstrate sending arbitrary shell commands and Python code to managed sessions.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill captures and processes output from tmux panes without sanitization, which could lead the agent to interpret captured text as instructions.
  • Ingestion points: Terminal output is retrieved using tmux capture-pane in SKILL.md and within the scripts/wait-for-text.sh script.
  • Boundary markers: The skill does not implement delimiters or provide explicit instructions to the agent to disregard commands embedded within the captured terminal output.
  • Capability inventory: The skill has the capability to both read from (capture-pane) and write to (send-keys) interactive shell sessions.
  • Sanitization: No sanitization, filtering, or escaping is applied to the text captured from tmux panes before it is incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:03 PM
Security Audit — agent-trust-hub — tmux