Cmux

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed cmux control helper, but users should supervise actions that type into terminal panes or close workspaces.

Install this only if you want the agent to manage your cmux session. Keep it pointed at the intended socket, target explicit workspaces and surfaces, and require confirmation before sending terminal input, key presses, or closing workspaces.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports sending arbitrary text and key presses to terminal surfaces, which can directly trigger shell command execution in whatever terminal session is attached. Because the documentation presents this as a routine capability without safety boundaries, confirmation requirements, or warnings, an agent could use the skill to run destructive commands, exfiltrate data, or interfere with active user sessions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal