NYC

wezterm

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • COMMAND_EXECUTION (MEDIUM): The skill provides multiple methods for the agent to execute arbitrary commands on the host system, such as 'wezterm cli send-text', 'wezterm cli spawn', and 'wezterm start'. These allow for full control over terminal processes. The severity is adjusted to MEDIUM as this is the primary intended function of the skill.
  • PROMPT_INJECTION (LOW): The skill creates an attack surface for indirect prompt injection. 1. Ingestion points: External data processed by the agent. 2. Boundary markers: No delimiters or warnings are specified for terminal input. 3. Capability inventory: Commands for spawning processes and sending text to shells. 4. Sanitization: The skill does not provide instructions for sanitizing or escaping input before execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 05:45 PM