hugging-face-cli

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides documentation for executing local shell commands via the hf utility. These commands are standard operations for interacting with the Hugging Face Hub.
  • [SAFE]: No malicious patterns, obfuscation, or data exfiltration vectors were identified. The skill follows secure practices for credential handling by suggesting the use of environment variables (e.g., $HF_TOKEN) rather than hardcoding secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 07:22 PM
Security Audit — agent-trust-hub — hugging-face-cli