wezterm

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core WezTerm management purpose is coherent, and most file/network access fits that purpose, but the skill weakens trust with an unpinned curl|bash auto-tuning script from an unrelated personal GitHub repo. Official WezTerm install guidance via apt.fury.io appears legitimate, and there is no clear credential exfiltration, but the remote script execution plus privileged rescue/tuning commands makes the skill medium-high risk.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Sep 19, 2026, 05:21 PM
Package URL
pkg:socket/skills-sh/dicklesworthstone%2Fagent_flywheel_clawdbot_skills_and_integrations%2Fwezterm%2F@1daa5b84361af6d4bbde36ee20717dea04db52cfce5128c2bc9990d9b78bd883
Security Audit — socket — wezterm