hugging-face-cli

Pass

Audited by Socket on Apr 1, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Apr 1, 2026, 03:43 AM
Package URL
pkg:socket/skills-sh/bcastelino%2Fagent-skills-kit%2Fhugging-face-cli%2F@71459ef32ca106085601c9643cf62cec5199c135
Security Audit — socket — hugging-face-cli