tmux-workflows

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses tmux send-keys to dispatch shell commands to new panes. The instructions mitigate injection risks by using the literal flag and requiring the agent to state exact commands and wait for operator approval before execution.- [INDIRECT_PROMPT_INJECTION]: The skill reads external terminal output, which is an untrusted data source.
  • Ingestion points: tmux capture-pane is used in SKILL.md to read output from development server panes.
  • Boundary markers: The skill explicitly warns the agent to treat every captured line as untrusted data, although it does not provide technical markers to isolate this data within the prompt.
  • Capability inventory: The agent has the ability to execute shell commands via tmux send-keys and manage panes.
  • Sanitization: The skill instructs the agent to validate any commands found in captured output against the operator's original request before execution.- [SAFE]: The skill implements strong security best practices by forbidding the agent from interacting with authentication prompts (SSH, sudo, MFA) or handling private keys and passwords, requiring direct operator input for these secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:20 PM
Security Audit — agent-trust-hub — tmux-workflows