python-uv-acceleration

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). While github.com/astral-sh/uv and the astral.sh domain appear to be the official project sources, the skill instructs executing remote install scripts (install.sh / install.ps1) and using arbitrary package indexes — running unverified remote scripts and using non-official indexes are meaningful supply‑chain risks and could be used to distribute malware if the host or repo were compromised or spoofed.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 16, 2026, 01:06 AM