hugging-face-jobs

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/generate-responses.py

This is primarily a dataset-to-model generation and upload utility. The strongest security concern is the explicit trust_remote_code=True when loading the vLLM model, which can enable arbitrary code execution from the selected Hugging Face model repository. Additionally, generated responses are uploaded to a user-controlled Hub dataset without filtering, so sensitive information present in the input dataset could be propagated into the output dataset. No clear indicators of overt embedded malware are present in this snippet; risk is dominated by supply-chain trust and data-handling implications.

Confidence: 72%Severity: 64%
Audit Metadata
Analyzed At
Apr 1, 2026, 03:43 AM
Package URL
pkg:socket/skills-sh/bcastelino%2Fagent-skills-kit%2Fhugging-face-jobs%2F@bb8df683175118803b038ddd49e3449cb2e87dfe
Security Audit — socket — hugging-face-jobs