aeon-huggingface-trending

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches trending metadata for models, datasets, and spaces from Hugging Face's official public API (huggingface.co).
  • [EXTERNAL_DOWNLOADS]: The setup instructions reference installation from the author's repository on GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the Hugging Face API, which could potentially contain malicious instructions embedded in model names or descriptions.
  • Ingestion points: Data retrieved from Hugging Face's model, dataset, and spaces APIs.
  • Boundary markers: None specified in the provided instructions.
  • Capability inventory: Uses curl to perform network requests.
  • Sanitization: No specific sanitization or filtering for adversarial prompt content is described in the logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:44 AM
Security Audit — agent-trust-hub — aeon-huggingface-trending