workmux
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and usage examples for the
workmuxCLI. It instructs the agent on how to interact with the tool to manage isolated development environments. - [COMMAND_EXECUTION]: The skill describes various shell commands (e.g.,
workmux add,workmux list,tmux list-sessions). These are legitimate uses of development tools for managing git worktrees and terminal multiplexing. No malicious command injection or high-risk patterns were found. - [PROMPT_INJECTION]: While the skill uses instructional language like 'Do NOT explore' or 'you are a dispatcher', these are functional directions for task orchestration rather than attempts to bypass safety filters or override the system prompt.
- [DATA_EXPOSURE]: The configuration section mentions copying
.envfiles into worktrees. This is documented as a standard feature of the tool for managing isolated environments and does not constitute a secret leak or unauthorized access.
Audit Metadata