Back to skill

Security audit

Tmux

Security checks across malware telemetry and agentic risk

Overview

This tmux skill is a clear terminal-control helper, but users should treat pane capture, session cleanup, and autonomous agent examples as potentially impactful.

Install this only if you are comfortable letting an agent control tmux. Use a private socket, avoid targeting panes that may contain secrets, review any repository changes made by autonomous agents, and verify session names before running kill-session or kill-server.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Because this is a markdown file, missing-warning findings apply when the description omits warnings about behaviors that could affect user data or system integrity. The examples encourage running agents in project directories with autonomous flags and mention parallel fixes, but they do not explicitly warn that these commands can modify repository files or perform impactful actions automatically.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The markdown includes `kill-session` and `kill-server` examples that can abruptly end active interactive processes, but the section does not warn that this may discard in-progress terminal state or stop running jobs. For markdown files, destructive or system-affecting behaviors should be disclosed so users understand the impact before using them.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.