dmux-workflows

Warn

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing 'dmux' from an unverified GitHub repository (github.com/standardagents/dmux), which is not an officially trusted organization or service.
  • [COMMAND_EXECUTION]: The helper script (scripts/orchestrate-worktrees.js) executes shell commands by interpolating variables into a 'launcherCommand' template defined in plan.json. This mechanism allows for the execution of arbitrary commands if the template is modified by an attacker.
  • [PROMPT_INJECTION]: The orchestration workflow is susceptible to indirect prompt injection via the task definitions in plan.json. 1. Ingestion points: The agent reads worker tasks and command templates from a local plan.json file. 2. Boundary markers: There are no delimiters or explicit instructions to ignore embedded commands within the ingested JSON data. 3. Capability inventory: The skill facilitates subprocess execution, tmux management, and file system operations via git worktrees. 4. Sanitization: No sanitization or validation of the launcherCommand template or the worker task strings is mentioned or implemented in the provided documentation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — dmux-workflows