tmux
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is primarily designed to facilitate the execution of shell commands and interactive keystrokes within tmux panes using the
tmux send-keyscommand. - Evidence: Examples provided in
SKILL.mdandtmux/SKILL.mddemonstrate sending arbitrary shell commands and Python code to managed sessions. - [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill captures and processes output from tmux panes without sanitization, which could lead the agent to interpret captured text as instructions.
- Ingestion points: Terminal output is retrieved using
tmux capture-paneinSKILL.mdand within thescripts/wait-for-text.shscript. - Boundary markers: The skill does not implement delimiters or provide explicit instructions to the agent to disregard commands embedded within the captured terminal output.
- Capability inventory: The skill has the capability to both read from (
capture-pane) and write to (send-keys) interactive shell sessions. - Sanitization: No sanitization, filtering, or escaping is applied to the text captured from tmux panes before it is incorporated into the agent's context.
Audit Metadata