park-workspace
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script uses
subprocess.runto interact with local system utilities such ascmux,ps,lsof, andgit. These interactions are required for the skill to identify workspaces and manage process lifecycles. - [DYNAMIC_EXECUTION]: The
unparkfeature usesos.execvpto resume Claude sessions by executing a shell command constructed from stored metadata. The risk of command injection is mitigated through the use ofshlex.quoteand strict UUID validation for session identifiers. - [PERSISTENCE]: The skill maintains state through a ledger of parked workspaces stored in
~/.claude/parked/. It also recommends a symlink in~/.local/bin/to ensure the tool is available across shell sessions. - [INDIRECT_PROMPT_INJECTION]: The skill reads terminal screen content to identify unsent drafts, representing an indirect injection surface. Ingestion points: Terminal screen buffers are read via
cmux read-screeninpark.py. Boundary markers: It identifies input boundaries using terminal box-drawing characters and specific prompt glyphs. Capability inventory: The skill has the ability to terminate processes and execute shell commands. Sanitization: The script uses strict regular expressions for identifiers andshlex.quotefor all command-line arguments. - [DATA_EXPOSURE]: The skill stores workspace information including directories and session IDs. It enforces
0700directory permissions and0600file permissions to ensure that session data is only accessible to the current user.
Audit Metadata