Tmux Temp

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The skill provides an AI agent with the capability to manage interactive tmux sessions and scrape their output, which is a high-risk capability that can be used to execute commands outside of standard monitored shell environments. While the scripts (scripts/find-sessions.sh and scripts/wait-for-text.sh) are well-authored and lack evidence of malicious intent, the SKILL.md documentation explicitly instructs the agent on how to orchestrate other agents (e.g., Codex) using flags like --yolo or --full-auto to bypass interactive safety confirmations. This combination of persistent background shell access and instructions to bypass sub-tool safety checks constitutes a high-risk capability set.