tmux
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's primary function is to interact with the system via the
tmuxCLI tool. It executes shell commands to create sessions, send keystrokes, and capture pane output. This is a functional requirement for the skill's stated purpose of providing interactive TTY capabilities. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by scraping output from terminal panes using
tmux capture-pane(e.g., inscripts/wait-for-text.sh). If an external process or a downloaded file prints malicious instructions to the terminal, the agent might interpret them as authoritative commands. - Ingestion points: Pane output captured in
SKILL.mdandscripts/wait-for-text.sh. - Boundary markers: None explicitly present to distinguish between pane output and system instructions.
- Capability inventory: Full shell access via
tmux send-keysand local script execution. - Sanitization: None; the skill performs regex matching but passes full output back to the agent context.
Audit Metadata