uv-package-manager

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides official installation instructions that fetch and execute scripts from the developer's domain (astral.sh). These include curl -LsSf https://astral.sh/uv/install.sh | sh for Unix-like systems and a PowerShell equivalent for Windows. These are documented neutrally as standard installation procedures for the well-known 'uv' utility.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents workflows for adding dependencies from various sources, including Git repositories (uv add git+...) and local paths. This represents a standard capability surface where an agent following these instructions might ingest third-party code.
  • Ingestion points: Commands like uv add and uv sync in SKILL.md.
  • Boundary markers: Not explicitly defined in the instructional text.
  • Capability inventory: The skill facilitates environment creation, package installation, and script execution via uv run.
  • Sanitization: Relies on the underlying 'uv' tool's own resolution and security logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:01 AM
Security Audit — agent-trust-hub — uv-package-manager