Audit History
uv-package-manager - 4 audits
Audit version 4
Latest SafeJan 17, 2026, 08:41 AM
Documentation-only skill teaching uv package manager usage. Static findings detected shell pipe patterns and PowerShell commands which are the official installation methods from astral.sh. All detected patterns are standard documentation for legitimate software installation and represent false positives.
Risk Factors
⚙️ External commands (3)
🌐 Network access (2)
📁 Filesystem access (2)
Audit version 3
SafeJan 17, 2026, 08:41 AM
Documentation-only skill teaching uv package manager usage. Static findings detected shell pipe patterns and PowerShell commands which are the official installation methods from astral.sh. All detected patterns are standard documentation for legitimate software installation and represent false positives.
Risk Factors
⚙️ External commands (3)
🌐 Network access (2)
📁 Filesystem access (2)
Audit version 2
CriticalJan 4, 2026, 04:39 PM
The skill documentation contains download-and-execute patterns (curl | sh and PowerShell remote execution) that pose security risks, along with shell profile modification commands that could be used for persistence.
Critical Issues (3)
Risk Factors
⚙️ External commands (3)
Detected Patterns
Audit version 1
CriticalJan 4, 2026, 04:39 PM
The skill documentation contains download-and-execute patterns (curl | sh and PowerShell remote execution) that pose security risks, along with shell profile modification commands that could be used for persistence.