huggingface-hub

Pass

Audited by Socket on Jun 23, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Jun 23, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/AlexAI-MCP%2Fhermes-CCC%2Fhuggingface-hub%2F@17bbc29be37f886abf8de3a57cdfabcb18fc180ffc7207fa4cb6068d85734241
Security Audit — socket — huggingface-hub