Claude Code Task
PassAudited by VirusTotal on Mar 30, 2026.
Findings (1)
The skill automates coding agents (like Claude Code) using tmux and git worktrees, specifically instructing the agent to use the `--dangerously-skip-permissions` flag in SKILL.md. While the instructions mandate a 'plan-first' approach and user approval before execution, the bypass of sub-agent security prompts combined with broad shell access via tmux represents a high-risk configuration. No evidence of intentional malice or data exfiltration was found, but the execution environment is inherently risky.
