uv-tool-management

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill file is documentation for a user-level tool manager (uv) and contains expected commands and paths for installing and running Python CLI tools. It does not include hardcoded secrets, obfuscated code, or explicit malicious network endpoints. The main security consideration is expected: installing or running code from PyPI or arbitrary git URLs runs third-party code locally and can lead to supply-chain compromise if untrusted sources are used. No direct signs of malware are present in the provided text, but users should treat installs from untrusted repositories cautiously and prefer verified sources.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 07:08 PM
Package URL
pkg:socket/skills-sh/laurigates%2Fclaude-plugins%2Fuv-tool-management%2F@ef0578bdeaffe7bf0137fb09059afd8bec83e9c5