Back to skill

Security audit

Claude Code Orchestrator (tmux-first)

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Claude Code tmux-orchestration purpose, but it gives long-running local or SSH coding agents broad unchecked authority by default.

Install only if you intentionally want Claude Code tasks run in detached tmux sessions and understand that the default mode bypasses normal permission prompts. Prefer disposable or low-privilege workspaces, avoid SSH mode unless hosts and paths are trusted, do not pass untrusted labels/workdirs/prompt files, and review generated reports and diffs before relying on the result.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-tmux-task.sh:193
Finding

Shell Command Injection Through an Unquoted Working Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-tmux-task.sh:100
Finding

Remote Command Injection Through Unsafe SSH Command Construction

Content
View full analysis
/dev/null 2>&1; then ssh -o BatchMode=yes "$SSH_HOST" "tmux -S '$SOCKET' kill-session -t '$SESSION'" fi ``` From `scripts/monitor-tmux-task.sh`: ```bash if $ATTACH; then if [[ "$TARGET" == "ssh" ]]; then exec ssh "$SSH_HOST" "tmux -S '$SOCKET' attach -t '$SESSION'" else exec tmux -S "$SOCKET" attach -t "$SESSION" fi else if [[ "$TARGET" == "ssh" ]]; then ssh "$SSH_HOST" "tmux -S '$SOCKET' capture-pane -p -J -t '$SESSION':0.0 -S -'$LINES'" ``` From `scripts/status-tmux-task.sh`: ```bash session_alive=false if [[ "$TARGET" == "ssh" ]]; then ssh -o BatchMode=yes "$SSH_HOST" "tmux -S '$SOCKET' has-session -t '$SESSION'" 2>/dev/null && session_alive=true else tmux -S "$SOCKET" has-session -t "$SESSION" 2>/dev/null && session_alive=true fi # 2. Check if report exists report_exists=false if [[ "$TARGET" == "ssh" ]]; then ssh -o BatchMode=yes "$SSH_HOST" "test -f '$REPORT_JSON'" 2>/dev/null && report_exists=true ``` ### Technical Analysis Values including `LABEL`, `NAMESPACE`, `SESSION`, `SOCKET`, and line-count parameters are incorporated into textual commands passed to SSH. Although some values are surrounded by single quotes in those strings, the scripts do not reject embedded single quotes. A crafted value can therefore terminate the intended quoting context and introduce new remote-shell syntax. The `SES ...[truncated 1496 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/start-tmux-task.sh:192
Finding

Claude Code Is Launched With Permission Enforcement Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/start-tmux-task.sh:55
Finding

Predictable Shared Temporary Files Permit Symlink and File-Substitution Attacks

Content
View full analysis
"$PROMPT_TMP" < "$REPORT_JSON" cat > "$REPORT_MD" <
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description emphasizes triggering Claude Code development tasks in tmux, stable startup, observability, SSH monitoring, and completion callback behavior. This script does none of that. It does not start tmux sessions, launch Claude Code, run coding work, or notify OpenClaw. Instead, it reads task listings from another script, filters for tasks with completion reports and done-like statuses, compares report mtimes against a local state file, emits a summary of completed-but-undelivered tasks, and can update delivery state to mark tasks as delivered. That is a materially different purpose: post-hoc reconciliation/delivery tracking rather than task execution and monitoring.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description emphasizes launching Claude Code work in tmux, ensuring stable startup, allowing SSH monitoring, and notifying OpenClaw upon completion. The supplied code chunk is a reporting utility (summarize-tasks.sh) that calls list-tasks.sh --json, parses statuses with jq, and prints a chat-friendly summary of existing tasks in a namespace. It provides progress visibility in a limited sense, but it neither launches tasks nor handles completion callbacks. Its primary purpose is observational summarization, which is only a supporting/monitoring component of the broader declared skill, not an accurate match for the stated trigger-and-run behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about orchestrating Claude Code development work in observable tmux sessions, including startup stability, monitoring, and completion notification. The supplied code does none of that. It only validates an input string and invokes an OpenClaw gateway 'wake' command with that text and a mode, with a fallback for older CLI versions. This is a materially different primary purpose and omits the core described behaviors, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs launching Claude with --dangerously-skip-permissions, which disables normal permission safeguards for an agent performing coding tasks in a local workspace. In this context, the agent may read, modify, execute, or exfiltrate data through shell-accessible resources with reduced friction, making accidental or malicious prompt-driven actions substantially more dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script combines remote session control, shell execution, and optional SSH operation with Claude permission checks disabled, but does not present any user-facing warning or confirmation at launch. That is dangerous because a user may believe they are only starting an observable coding session, while the script actually enables an autonomous agent to act with broad authority on local or remote systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script starts Claude with --dangerously-skip-permissions, explicitly disabling permission safeguards while also placing the agent in a real project directory with network proxy settings and shell access. In this skill’s context, that gives the model broad autonomous ability to read, modify, and execute within the repository beyond what a tmux orchestration helper strictly requires, increasing the chance of unintended destructive actions or prompt-driven abuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill clearly directs shell-based task orchestration through multiple bash scripts, but it declares no explicit tool scope or permission boundaries. That creates an authorization gap where a broadly triggered skill may invoke powerful local shell actions without transparent constraint, increasing the chance of unintended or unsafe execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The trigger condition is broad enough that the skill may activate for many coding-related requests without clear exclusions for sensitive environments, privileged repositories, or untrusted prompts. Because this skill also orchestrates shell commands, tmux sessions, and potentially SSH-monitored workflows, overbroad invocation increases the risk of inappropriate use in high-trust contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script executes shell code taken directly from arguments via command substitution: lint_out="$($LINT_CMD 2>&1)" and build_out="$($BUILD_CMD 2>&1)". Because these values are treated as full shell commands rather than fixed executables plus validated arguments, any caller able to influence --lint-cmd or --build-cmd can run arbitrary commands with the script's privileges; in this skill context, that is especially dangerous because the skill is explicitly designed to trigger development tasks automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script emits user-facing status text and a required follow-up reply pattern entirely in Chinese, including the suggested command phrase the user should send. This imposes a specific language on users without offering a choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

When TARGET=ssh, the script silently copies the prompt/reference file to the remote host and later instructs copying report artifacts back to another host. Even if operationally useful, this can expose sensitive task content, repository details, or generated reports across systems without clear user disclosure or destination validation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The generated prompt text is entirely in Chinese and instructs the downstream agent in that language, with no indication that the user selected Chinese or that the skill is intentionally limited to a Chinese-speaking context. This constitutes a language/locale policy issue because it imposes a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user-visible strings are hard-coded in Chinese, so the skill's output enforces a specific language regardless of user preference. Under the policy, fixed locale behavior should either offer opt-in/choice or be clearly documented as a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script creates JSON and Markdown report files under /tmp and later writes content to them, but there is no prior warning in the usage text or comments that running the skill will create local report artifacts. For a code-file audit, file writes can warrant disclosure when no user-facing warning or description is present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This script writes persistent local state to a JSON file under the skill's state directory, and later rewrites that file when marking tasks as delivered. Although the behavior is visible in code comments, there is no runtime disclosure, confirmation, or user-facing notice that invoking the script will create or modify local state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The comments state that output is designed to be posted to chat, and later the script prints the namespace and task labels/statuses. This discloses operational metadata to a chat audience, but the file provides no explicit user-facing warning, confirmation, or caution that task names and status details will be shared externally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.