История аудитов
uv-package-manager - 4 аудиты
Версия аудита 4
Последняя БезопасноJan 17, 2026, 08:41 AM
Documentation-only skill teaching uv package manager usage. Static findings detected shell pipe patterns and PowerShell commands which are the official installation methods from astral.sh. All detected patterns are standard documentation for legitimate software installation and represent false positives.
Факторы риска
⚙️ Внешние команды (3)
🌐 Доступ к сети (2)
📁 Доступ к файловой системе (2)
Версия аудита 3
БезопасноJan 17, 2026, 08:41 AM
Documentation-only skill teaching uv package manager usage. Static findings detected shell pipe patterns and PowerShell commands which are the official installation methods from astral.sh. All detected patterns are standard documentation for legitimate software installation and represent false positives.
Факторы риска
⚙️ Внешние команды (3)
🌐 Доступ к сети (2)
📁 Доступ к файловой системе (2)
Версия аудита 2
КритичноJan 4, 2026, 04:39 PM
The skill documentation contains download-and-execute patterns (curl | sh and PowerShell remote execution) that pose security risks, along with shell profile modification commands that could be used for persistence.
Критические проблемы (3)
Факторы риска
⚙️ Внешние команды (3)
Обнаруженные паттерны
Версия аудита 1
КритичноJan 4, 2026, 04:39 PM
The skill documentation contains download-and-execute patterns (curl | sh and PowerShell remote execution) that pose security risks, along with shell profile modification commands that could be used for persistence.