managing-huggingface

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various shell commands to interact with the Hugging Face API and CLI. These commands involve using curl for API requests and jq for processing JSON responses, which are standard operations for this type of integration.
  • [DATA_EXPOSURE]: The skill reads the Hugging Face token from the standard cache location (~/.cache/huggingface/token). This is a common and expected practice for tools interacting with the Hugging Face platform.
  • [EXTERNAL_DOWNLOADS]: The skill makes requests to official Hugging Face domains (huggingface.co, api-inference.huggingface.co, and api.endpoints.huggingface.cloud) to retrieve model metadata, dataset information, and manage inference endpoints. These are well-known, trusted services associated with the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 11:26 AM
Security Audit — agent-trust-hub — managing-huggingface