First Seen
Feb 18, 2026
Last Scanned
Feb 22, 2026
Findings
11
Score
69/100
Findings (11)
Detects zero-width characters used to hide content
Remove hidden directives embedded in markdown, HTML comments, or encoded text. All agent-facing text should be explicit and visible in the skill definition.
Likely FP if the match is a standard markdown formatting pattern or HTML comment used for documentation rather than concealing directives.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.
Detects tmux/screen send-keys used to inject commands into terminal sessions
tmux send-keys Avoid sending unsanitized user input to tmux/screen sessions via send-keys. Use a controlled command dispatch mechanism instead of injecting commands into terminal multiplexers.
Likely FP if the match is in documentation describing tmux/screen workflow automation for the user themselves, not controlled by an external agent.