wezterm
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core WezTerm management purpose is coherent, and most file/network access fits that purpose, but the skill weakens trust with an unpinned curl|bash auto-tuning script from an unrelated personal GitHub repo. Official WezTerm install guidance via apt.fury.io appears legitimate, and there is no clear credential exfiltration, but the remote script execution plus privileged rescue/tuning commands makes the skill medium-high risk.
Confidence: 90%Severity: 78%
Audit Metadata