uv-mcp

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill describes tools like repair_environment, add_dependency, and build_project which perform system-level operations to manage virtual environments and packages. These are standard and expected capabilities for a project management skill.
  • [EXTERNAL_DOWNLOADS]: The skill mentions capabilities for installing the uv binary and various Python interpreters. These operations involve downloading artifacts from external sources, which is the primary purpose of the described tools.
  • [PROMPT_INJECTION]: The instructions focus purely on operational guidance for the uv-mcp server. No patterns attempting to bypass safety filters or override agent behavior were identified.
  • [DATA_EXFILTRATION]: There are no patterns indicating the unauthorized access or external transmission of sensitive information such as credentials or environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 05:58 AM
Security Audit — agent-trust-hub — uv-mcp