uv-expert

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This documentation/skill is primarily informational about the 'uv' tool and its workflows. It does not contain embedded malicious code, nor does it request credentials. The main security concern is supply-chain: the recommended curl|sh and PowerShell piped-install commands are high-risk download-and-execute patterns because they fetch remote scripts and execute them without integrity verification. Additional moderate risks come from recommending unpinned pip installs, using a third-party GitHub Action in CI (transitive trust), and installing the package during Docker builds without pinned hashes. Recommend replacing curl|sh/iex examples with guidance to inspect downloaded scripts, provide checksum/signature verification, pin versions or use commit SHAs for actions, and use hash-pinned installs in container builds and CI to reduce supply-chain risk.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 12:11 AM
Package URL
pkg:socket/skills-sh/straydragon%2Fmy-claude-skills%2Fuv-expert%2F@7b129f70e964464f95e0a79167ec454d084b818a