managing-huggingface
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes various shell commands to interact with the Hugging Face API and CLI. These commands involve using
curlfor API requests andjqfor processing JSON responses, which are standard operations for this type of integration. - [DATA_EXPOSURE]: The skill reads the Hugging Face token from the standard cache location (
~/.cache/huggingface/token). This is a common and expected practice for tools interacting with the Hugging Face platform. - [EXTERNAL_DOWNLOADS]: The skill makes requests to official Hugging Face domains (
huggingface.co,api-inference.huggingface.co, andapi.endpoints.huggingface.cloud) to retrieve model metadata, dataset information, and manage inference endpoints. These are well-known, trusted services associated with the skill's primary purpose.
Audit Metadata