tmux-session-manager
Fail
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's
sendworkflow (found inSKILL.md,SKILL.en.md, andSKILL.es.md) allows users to provide instructions that are directly interpolated into a shell command string executed over SSH. This pattern is highly vulnerable to command injection, as malicious input could escape the single quotes to execute arbitrary shell commands on the remote Lightsail instance. - [COMMAND_EXECUTION]: The skill relies extensively on executing shell commands via SSH on a remote host to manage tmux sessions and synchronize Git pull requests. These commands involve directory navigation and script invocation with multiple arguments.
- [REMOTE_CODE_EXECUTION]: The skill executes remote shell scripts (
cc-session.shandsync-prs.sh) located on a Lightsail instance. The source code for these scripts is not provided within the skill package, rendering their behavior unverifiable and posing a risk if the remote environment is untrusted or compromised. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection by processing untrusted data from remote environments.
- Ingestion points: Remote tmux session output and logs captured via the
captureandstatuscommands (e.g., inSKILL.en.md). - Boundary markers: Absent. The instructions do not specify delimiters or provide warnings to ignore embedded instructions in the captured content.
- Capability inventory: SSH command execution, session management (kill/create), and instruction delivery (
send-keys). - Sanitization: None. The skill instructs the agent to summarize and report the captured output directly to the user without prior validation or escaping.
Recommendations
- AI detected serious security threats
Audit Metadata