aeon-huggingface-trending
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches trending metadata for models, datasets, and spaces from Hugging Face's official public API (huggingface.co).
- [EXTERNAL_DOWNLOADS]: The setup instructions reference installation from the author's repository on GitHub.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the Hugging Face API, which could potentially contain malicious instructions embedded in model names or descriptions.
- Ingestion points: Data retrieved from Hugging Face's model, dataset, and spaces APIs.
- Boundary markers: None specified in the provided instructions.
- Capability inventory: Uses
curlto perform network requests. - Sanitization: No specific sanitization or filtering for adversarial prompt content is described in the logic.
Audit Metadata