uv
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill references official installation scripts for the uv tool from the vendor's official domain.
- Evidence:
curl -LsSf https://astral.sh/uv/install.sh | shandpowershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"inSKILL.md. - Note: These installation methods are documented as the official entry points for the Astral uv project.
- [PRIVILEGE_ESCALATION]: Documents the use of execution policy bypass for the Windows installation script.
- Evidence:
-ExecutionPolicy ByPassin the PowerShell installation example (SKILL.md). - Note: This is standard practice for installing developer tools via PowerShell when the local environment has restricted script execution.
- [COMMAND_EXECUTION]: Provides instructions for standard dependency management and tool execution within virtual environments.
- Evidence:
uv run,uv sync, anduv addcommands inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted configuration files and provides the ability to execute environment-specific code.
- Ingestion points:
pyproject.toml,uv.lock(SKILL.md). - Boundary markers: None.
- Capability inventory:
uv run,uv add,uv sync(SKILL.md). - Sanitization: The skill relies on the standard validation logic of the uv binary.
Audit Metadata