T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:82- Finding
Unsafe Recommendation to Run Coding Agents Without Approval Controls
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Zellij helper, but it recommends unattended coding agents with approval bypass and can expose full terminal pane output, so it needs careful review before use.
Install only if you intend to let agents control Zellij sessions. Avoid the documented `--yolo` and `--full-auto` patterns unless you are in a disposable, isolated workspace with restricted credentials and you will review all changes. Treat pane output as sensitive because helper scripts may print terminal contents into logs.
SKILL.md:82Unsafe Recommendation to Run Coding Agents Without Approval Controls
The declared description says the skill remotely controls zellij sessions by sending keystrokes and scraping pane output. The supplied code does not send keystrokes, scrape pane contents, or interact with panes for CLI control. Instead, it lists existing zellij sessions from a data directory, prompts for confirmation, and deletes all of them. Session deletion is a materially different and destructive capability that is not represented in the declared purpose, so this is a clear mismatch.
The declared description emphasizes active remote control of zellij sessions for interactive CLI use, specifically sending keystrokes and scraping pane output. The supplied code does none of that. It invokes zellij ... list-sessions, parses the returned JSON with jq, optionally filters by substring, and prints session summaries. Its actual purpose is session discovery/listing across zellij data directories, not controlling sessions or interacting with pane contents. That is a material description-behavior mismatch.
The examples explicitly launch coding agents with approval-bypass flags such as --yolo for unattended execution, but they do not include a warning about the risks of autonomous command execution or repository modification. In this skill's context, which is specifically about orchestrating multiple agent sessions in parallel, that omission increases the chance a user will copy-paste unsafe patterns that can make broad changes, run commands, or damage worktrees without review.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Options:
-D, --data-dir zellij data directory (uses CLAWDBOT_ZELLIJ_DATA_DIR if not set)
-y, --yes skip confirmation prompt
-h, --help show this help
USAGE
}
The script captures pane output from a remote-controlled zellij session and, on timeout, prints the full pane contents to stderr. Pane output can contain secrets, tokens, credentials, command history, or other sensitive terminal data, so emitting it without redaction or an explicit warning can leak confidential information into logs or calling processes. In this skill context, the risk is elevated because the whole purpose of the skill is to scrape interactive CLI panes, which commonly display sensitive material.
No suspicious patterns detected.