Skip to content
Back to skills

Uv

CSecurity

If the project uses uv, use this skill. Use this skill to create/manage Python projects and environments with `uv`, add/remove dependencies, sync a project from `uv.lock`, and run commands in the project environment.

  • 151 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added June 5, 2026
toolspythonshellbash

Security analysis

C67/100
  • criticalPipes output to a shell interpreter
  • mediumUses curl or wget to download content
  • criticalDownloads and executes remote scripts — classic supply chain attack
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 4 files and shows the line behind each finding

Scanned June 5, 2026

npx -y skills add OpenHands/extensions --skill uv --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Uv?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Uv
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/openhands-uv/badge)](https://www.skillsdirectory.com/skills/openhands-uv)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: uv
description: If the project uses uv, use this skill. Use this skill to create/manage Python projects and environments with `uv`, add/remove dependencies, sync a project from `uv.lock`, and run commands in the project environment.
triggers:
- uv
- uv.lock
---

# uv (Python)

Use `uv` as the default tool for Python dependency + environment management when the repo has `uv.lock`, mentions `uv` in its docs/Makefile, or already uses a `.venv` created by `uv`.

## Quick decision rules

- If the repo has `uv.lock` and `pyproject.toml`: treat it as a uv-managed project.
- If the repo has only `requirements.txt`: you can still use `uv pip` for fast installs.
- Prefer **project commands** (`uv add/remove/sync/run/lock`) over raw `pip` unless the repo explicitly uses `uv pip`.

## Installation (if needed)

Prefer a packaged install method when available. If you use the official installer, review it first (avoid blindly piping into a shell) and follow the latest instructions in the official docs.

```bash
# macOS/Linux (official installer)
curl -LsSf https://astral.sh/uv/install.sh | sh

# Windows (PowerShell, official installer)
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
```

## Common operations

### Initialize a new project

```bash
uv init
# or
uv init my-project
```

### Create / use a virtual environment

```bash
uv venv  # creates .venv

# If you need a specific version, match the project's declared requirement
# (e.g., pyproject.toml / CI config), not an arbitrary latest version.
uv venv --python 3.x

# optional activation (not required for uv commands)
source .venv/bin/activate  # macOS/Linux
# .venv\\Scripts\\activate   # Windows
```

### Add / remove dependencies (updates pyproject.toml and uv.lock)

```bash
uv add requests
uv add 'requests==2.31.0'
uv add -r requirements.txt

uv remove requests
```

### Lock + sync (reproducible installs)

```bash
uv lock   # (re)generate uv.lock
uv sync   # create/update .venv to match uv.lock
```

If you pulled new changes and `uv.lock` changed, run `uv sync`.

### Run commands inside the project environment

```bash
uv run python -m pytest -q
uv run python main.py
uv run ruff check .
```

### Using uv as a fast pip replacement (requirements workflows)

```bash
uv venv
uv pip install -r requirements.txt
uv pip freeze
uv pip list
```

## Notes / pitfalls

- `uv` will usually auto-detect and use `.venv` in the project root.
- In CI/containers you may see `uv pip install --system`, but prefer virtualenvs for local dev.
- If a command mutates deps, prefer `uv add/remove/lock/sync` so `uv.lock` stays correct.

Files in this skill

  • .plugin/plugin.json419 B
  • README.md125 B
  • SKILL.md2.6 KB
  • references/README.md136 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…