Back to skill

Security audit

Claude Tmux

Security checks across malware telemetry and agentic risk

Overview

This skill is a Markdown-only tmux helper, but it asks for broad exec capability and includes unclear, partly unrelated AI/API-key scope.

Review before installing. This does not show malicious behavior or hidden code, but it grants exec capability with vague tmux scoping and confusing AI/API-key claims. Install only if you are comfortable supervising any commands it runs and do not provide an API key unless the publisher explains why it is needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest presents the skill as a narrow tmux helper, but the description expands it into generic AI-model, agent orchestration, and external LLM/API usage. This scope drift can mislead users and host agents about the real behavior and trust boundary, increasing the chance that a seemingly local helper is granted broader permissions or network-dependent use than expected.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The file claims the skill 'does what it advertises' as a tmux helper, yet later markets unrelated paid capabilities such as model fine-tuning, style presets, and copyright licensing. This inconsistency undermines user consent and can disguise a broader operational scope than the initial description suggests.

Context-Inappropriate Capability

Low
Confidence
90% confidence
Finding
Requiring an API key and generic LLM service for an instruction-only tmux helper is unjustified by the stated purpose and expands the attack surface to external services and secret handling. Users may expose credentials or permit network access without a clear functional need.

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
The input/output schema is framed as generic content processing rather than tmux-specific actions, making the real operational behavior ambiguous. Ambiguous schemas increase the risk that agents or users invoke the skill for broader execution tasks than intended.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill exposes exec/tmux command execution semantics but does not clearly warn users that commands may alter system state, affect sessions, or fail due to permissions. In an agent environment, this lack of explicit side-effect disclosure can lead to unsafe execution of shell actions under false assumptions of harmlessness.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.