wezterm

Fail

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions include a one-liner that downloads a remote shell script from GitHub and pipes it directly into bash for execution.
  • Evidence: curl -fsSL https://raw.githubusercontent.com/Dicklesworthstone/misc_coding_agent_tips_and_scripts/main/wezterm-mux-tune.sh | bash found in SKILL.md and references/PERFORMANCE-TUNING.md.
  • Risk: This execution pattern allows the remote source to execute arbitrary commands on the local system without verification or version pinning.
  • [PRIVILEGE_ESCALATION]: The skill directs the user to perform actions that weaken system security and require root access.
  • Evidence: sudo sysctl -w kernel.yama.ptrace_scope=0 (SKILL.md). Disabling ptrace_scope removes a key security layer that prevents processes from attaching to and inspecting other running processes.
  • Software Installation: Instructs the use of sudo apt-get install to install software like reptyr and wezterm (references/PERSISTENT-SESSIONS.md).
  • [PERSISTENCE]: The skill provides configuration for maintaining persistent access and background processes across user sessions.
  • Evidence: Creation of a systemd user service (wezterm-mux-server.service) and the use of sudo loginctl enable-linger $USER to ensure the user's processes continue running after logout (references/PERSISTENT-SESSIONS.md).
  • [EXTERNAL_DOWNLOADS]: The skill downloads external resources and configures third-party package repositories.
  • Evidence: Fetches a GPG key from https://apt.fury.io/wez/gpg.key to configure an external APT repository for WezTerm (references/PERSISTENT-SESSIONS.md).
  • [COMMAND_EXECUTION]: The skill relies on the wezterm cli to programmatically interact with the terminal environment, including injecting text into active panes.
  • Evidence: Extensive documentation of wezterm cli send-text, wezterm cli spawn, and wezterm cli split-pane used to control session behavior (references/COMMANDS.md).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to manage environments where multiple AI agents produce high-volume output, creating a vulnerability surface for indirect injection.
  • Ingestion points: Processes continuous output streams from multiple agents such as Claude Code and Codex (SKILL.md).
  • Boundary markers: There are no specified delimiters or boundary markers to isolate agent output from the management context.
  • Capability inventory: The skill has full terminal control capabilities, including the ability to split panes and inject text/commands via CLI.
  • Sanitization: No sanitization or filtering of ingested agent output is implemented.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/Dicklesworthstone/misc_coding_agent_tips_and_scripts/main/wezterm-mux-tune.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 19, 2026, 05:21 PM
Security Audit — agent-trust-hub — wezterm