skills/volcengine/openviking/tmux/Gen Agent Trust Hub

tmux

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary function is to interact with the system via the tmux CLI tool. It executes shell commands to create sessions, send keystrokes, and capture pane output. This is a functional requirement for the skill's stated purpose of providing interactive TTY capabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by scraping output from terminal panes using tmux capture-pane (e.g., in scripts/wait-for-text.sh). If an external process or a downloaded file prints malicious instructions to the terminal, the agent might interpret them as authoritative commands.
  • Ingestion points: Pane output captured in SKILL.md and scripts/wait-for-text.sh.
  • Boundary markers: None explicitly present to distinguish between pane output and system instructions.
  • Capability inventory: Full shell access via tmux send-keys and local script execution.
  • Sanitization: None; the skill performs regex matching but passes full output back to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — tmux