cursor-council

clawhub:cursor-council

View source
C
69/100

First Seen

Feb 18, 2026

Last Scanned

Feb 22, 2026

Findings

11

Score

69/100

HIGH 1
MEDIUM 2
LOW 8

Findings (11)

HIGH
Zero-width character obfuscation
L108

Detects zero-width characters used to hide content

FIX

Remove hidden directives embedded in markdown, HTML comments, or encoded text. All agent-facing text should be explicit and visible in the skill definition.

FP?

Likely FP if the match is a standard markdown formatting pattern or HTML comment used for documentation rather than concealing directives.

MEDIUM
Terminal multiplexer command injection
L100

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

MEDIUM
Terminal multiplexer command injection
L101

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L73

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L77

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L78

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L79

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L192

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L195

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L196

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.

LOW
Terminal multiplexer command injection
L197

Detects tmux/screen send-keys used to inject commands into terminal sessions

tmux send-keys 
FIX

Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.

FP?

Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.