skills/manaflow-ai/cmux/cmux-cloud-vm/Gen Agent Trust Hub

cmux-cloud-vm

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill integrates with the cmux CLI to allow agents to perform remote system administration tasks, including running shell commands, managing workspaces, and controlling interactive terminal sessions on cloud VMs.\n- [PRIVILEGE_ESCALATION]: Use of the cmux vpn up command requires sudo access on the host system to configure WireGuard interfaces for secure communication with the cloud VM network.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from remote VM environments, creating a potential vector for indirect prompt injection.\n
  • Ingestion points: Data is ingested through cmux vm terminal read, cmux vm exec output, and repository files synced from the local environment to the VM.\n
  • Boundary markers: The instructions do not define specific delimiters to isolate untrusted remote output from the agent's control logic.\n
  • Capability inventory: The skill possesses powerful capabilities including remote shell execution, file modification, and exposing VM ports via HTTPS domains.\n
  • Sanitization: There is no evidence of specific sanitization routines for external data processed by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:40 PM
Security Audit — agent-trust-hub — cmux-cloud-vm