uv-package-manager
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides official installation instructions that fetch and execute scripts from the developer's domain (astral.sh). These include
curl -LsSf https://astral.sh/uv/install.sh | shfor Unix-like systems and a PowerShell equivalent for Windows. These are documented neutrally as standard installation procedures for the well-known 'uv' utility. - [INDIRECT_PROMPT_INJECTION]: The skill documents workflows for adding dependencies from various sources, including Git repositories (
uv add git+...) and local paths. This represents a standard capability surface where an agent following these instructions might ingest third-party code. - Ingestion points: Commands like
uv addanduv syncinSKILL.md. - Boundary markers: Not explicitly defined in the instructional text.
- Capability inventory: The skill facilitates environment creation, package installation, and script execution via
uv run. - Sanitization: Relies on the underlying 'uv' tool's own resolution and security logic.
Audit Metadata