hugging-face-evaluation-manager

Warn

Audited by Snyk on Mar 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill's CLI and scripts (e.g., scripts/evaluation_manager.py using ModelCard.load to read public model README content from huggingface.co and get_aa_model_data/import-aa which calls the Artificial Analysis API) fetch and parse untrusted, user-generated third-party data and then use those parsed values to construct model-index YAML and optionally create pushes/PRs, so that external content directly influences actions the tool will perform.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 28, 2026, 08:18 PM
Issues
1
Security Audit — snyk — hugging-face-evaluation-manager