uv

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation guide for the legitimate 'uv' Python tool. It provides standard usage patterns for package and environment management.
  • [COMMAND_EXECUTION]: The skill describes how to use various uv commands, such as uv run, uv add, and uvx. The instructions include explicit security warnings regarding the use of uvx, noting that running tools by package name from PyPI can be unsafe and advising the agent to only run well-known tools.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation at https://docs.astral.sh/uv/llms.txt. This is a standard reference to the vendor's own documentation and does not constitute a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:05 PM
Security Audit — agent-trust-hub — uv