Back to skill

Security audit

Zellij Terminal Workspace

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Zellij helper, but it recommends unattended coding agents with approval bypass and can expose full terminal pane output, so it needs careful review before use.

Install only if you intend to let agents control Zellij sessions. Avoid the documented `--yolo` and `--full-auto` patterns unless you are in a disposable, isolated workspace with restricted credentials and you will review all changes. Treat pane output as sensitive because helper scripts may print terminal contents into logs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:82
Finding

Unsafe Recommendation to Run Coding Agents Without Approval Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says the skill remotely controls zellij sessions by sending keystrokes and scraping pane output. The supplied code does not send keystrokes, scrape pane contents, or interact with panes for CLI control. Instead, it lists existing zellij sessions from a data directory, prompts for confirmation, and deletes all of them. Session deletion is a materially different and destructive capability that is not represented in the declared purpose, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description emphasizes active remote control of zellij sessions for interactive CLI use, specifically sending keystrokes and scraping pane output. The supplied code does none of that. It invokes zellij ... list-sessions, parses the returned JSON with jq, optionally filters by substring, and prints session summaries. Its actual purpose is session discovery/listing across zellij data directories, not controlling sessions or interacting with pane contents. That is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The examples explicitly launch coding agents with approval-bypass flags such as --yolo for unattended execution, but they do not include a warning about the risks of autonomous command execution or repository modification. In this skill's context, which is specifically about orchestrating multiple agent sessions in parallel, that omission increases the chance a user will copy-paste unsafe patterns that can make broad changes, run commands, or damage worktrees without review.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/cleanup-sessions.sh (reported line 12)May include surrounding context.

sh
Options:
  -D, --data-dir    zellij data directory (uses CLAWDBOT_ZELLIJ_DATA_DIR if not set)
  -y, --yes         skip confirmation prompt
  -h, --help        show this help
USAGE
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script captures pane output from a remote-controlled zellij session and, on timeout, prints the full pane contents to stderr. Pane output can contain secrets, tokens, credentials, command history, or other sensitive terminal data, so emitting it without redaction or an explicit warning can leak confidential information into logs or calling processes. In this skill context, the risk is elevated because the whole purpose of the skill is to scrape interactive CLI panes, which commonly display sensitive material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.