tmux-session-manager

Fail

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's send workflow (found in SKILL.md, SKILL.en.md, and SKILL.es.md) allows users to provide instructions that are directly interpolated into a shell command string executed over SSH. This pattern is highly vulnerable to command injection, as malicious input could escape the single quotes to execute arbitrary shell commands on the remote Lightsail instance.
  • [COMMAND_EXECUTION]: The skill relies extensively on executing shell commands via SSH on a remote host to manage tmux sessions and synchronize Git pull requests. These commands involve directory navigation and script invocation with multiple arguments.
  • [REMOTE_CODE_EXECUTION]: The skill executes remote shell scripts (cc-session.sh and sync-prs.sh) located on a Lightsail instance. The source code for these scripts is not provided within the skill package, rendering their behavior unverifiable and posing a risk if the remote environment is untrusted or compromised.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection by processing untrusted data from remote environments.
  • Ingestion points: Remote tmux session output and logs captured via the capture and status commands (e.g., in SKILL.en.md).
  • Boundary markers: Absent. The instructions do not specify delimiters or provide warnings to ignore embedded instructions in the captured content.
  • Capability inventory: SSH command execution, session management (kill/create), and instruction delivery (send-keys).
  • Sanitization: None. The skill instructs the agent to summarize and report the captured output directly to the user without prior validation or escaping.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — tmux-session-manager