dmux-workflows
Warn
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing 'dmux' from an unverified GitHub repository (github.com/standardagents/dmux), which is not an officially trusted organization or service.
- [COMMAND_EXECUTION]: The helper script (scripts/orchestrate-worktrees.js) executes shell commands by interpolating variables into a 'launcherCommand' template defined in plan.json. This mechanism allows for the execution of arbitrary commands if the template is modified by an attacker.
- [PROMPT_INJECTION]: The orchestration workflow is susceptible to indirect prompt injection via the task definitions in plan.json. 1. Ingestion points: The agent reads worker tasks and command templates from a local plan.json file. 2. Boundary markers: There are no delimiters or explicit instructions to ignore embedded commands within the ingested JSON data. 3. Capability inventory: The skill facilitates subprocess execution, tmux management, and file system operations via git worktrees. 4. Sanitization: No sanitization or validation of the launcherCommand template or the worker task strings is mentioned or implemented in the provided documentation.
Audit Metadata