qt-dev-tools-setup
Warn
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple shell commands for VM management and tool interaction using
uvx,uv run, andvirsh. This includes system-level network configuration viavirshand software installation viasudo apt-getin the virtual environment. - [EXTERNAL_DOWNLOADS]: Uses the
uvxcommand to fetch and execute theqt-ai-dev-toolspackage from external registries. This tool is an unverifiable third-party dependency not associated with a known trusted vendor. - [REMOTE_CODE_EXECUTION]: Provides a
self-updatefeature that downloads and replaces local toolkit source code from a remote source, which can result in the execution of unverified logic.
Audit Metadata