manage-python-env
Fail
Audited by Snyk on Feb 16, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.90). The curl|sh install script (https://astral.sh/uv/install.sh) is high-risk because piping a remote .sh to a shell executes unreviewed code from the network, while the GitHub repo URL (https://github.com/user/repo.git) is lower risk in principle but can be unsafe if the repository/user is untrusted or malicious.
Audit Metadata