tmux-workflows
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
tmux send-keysto dispatch shell commands to new panes. The instructions mitigate injection risks by using the literal flag and requiring the agent to state exact commands and wait for operator approval before execution.- [INDIRECT_PROMPT_INJECTION]: The skill reads external terminal output, which is an untrusted data source. - Ingestion points:
tmux capture-paneis used inSKILL.mdto read output from development server panes. - Boundary markers: The skill explicitly warns the agent to treat every captured line as untrusted data, although it does not provide technical markers to isolate this data within the prompt.
- Capability inventory: The agent has the ability to execute shell commands via
tmux send-keysand manage panes. - Sanitization: The skill instructs the agent to validate any commands found in captured output against the operator's original request before execution.- [SAFE]: The skill implements strong security best practices by forbidding the agent from interacting with authentication prompts (SSH, sudo, MFA) or handling private keys and passwords, requiring direct operator input for these secrets.
Audit Metadata