Back to skill

Security audit

Claude终端复用工具

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only tmux helper has no hidden scripts, but it requests broad command/write authority with vague, inconsistent instructions that need review before installation.

Review this skill carefully before installing. It appears to be a low-code Markdown helper rather than malware, but only use it for tmux tasks, verify any command before it runs, avoid giving it API keys unless the provider and use are clear, and require confirmation before closing or changing active sessions/windows.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill markets itself as 'instruction-only' and 'does what it advertises,' yet it declares exec and write capabilities and includes command/API execution setup steps. This mismatch can mislead users and invoking agents about the true trust boundary, increasing the chance that the skill is granted execution privileges without appropriate scrutiny.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The file gives contradictory statements about synchronization support: the FAQ says tmux synchronization is unsupported, while a later comparison table claims synchronization functionality. Contradictory capability claims can cause operators or agents to make unsafe assumptions about what actions the skill may attempt or automate.

Vague Triggers

High
Confidence
91% confidence
Finding
The invocation description is overly broad and extends to generic project management, planning, tracking, and team collaboration rather than tmux-specific tasks. In an agent ecosystem, broad triggers can cause the skill to be selected in unrelated contexts, unintentionally granting exec/write-capable behavior where a non-executing skill would have been safer.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill describes tmux management features but does not clearly warn that commands may create, rename, kill, or otherwise modify sessions and windows. Without an explicit warning and confirmation model, users may trigger destructive terminal state changes or lose active work unintentionally.

Static analysis

No suspicious patterns detected.