tmux-agent

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] Overall, the code fragment is benign and self-consistent with its stated purpose of tmux-based orchestration for Claude instances. It does not introduce external dependencies, credential handling, or data exfiltration; data reads are restricted to local pane state and outputs, and actions are tmux-API driven within the user’s session. LLM verification: This skill's capabilities are consistent with its stated purpose (tmux orchestration) but they are inherently powerful: it can read pane outputs and execute arbitrary commands in other panes. There are no external downloads or third-party network calls, so supply-chain compromise signals are absent. However, the skill provides mechanisms that, if misused or incorrectly escaped, could lead to command injection, unintended execution, or exposure of secrets visible in terminal sessions. Treat this

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 03:28 PM
Package URL
pkg:socket/skills-sh/ssiumha%2Fdots%2Ftmux-agent%2F@d1aec7aec78430b9f4f5ab89b0abd23cbad408ae