huggingface

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Token Security: The skill explicitly enforces the use of environment variables for authentication (HF_TOKEN) and includes a linter script (scripts/verify.sh) to detect and block hardcoded token literals in the codebase.
  • [SAFE]: Trusted Dependencies: External packages such as huggingface_hub and transformers are officially maintained by Hugging Face, a well-known and trusted provider. Installation commands point to standard package registries.
  • [SAFE]: Secure Infrastructure: Routing is directed to official Hugging Face endpoints (router.huggingface.co), and the skill accurately differentiates between local execution and hosted inference to minimize unnecessary infrastructure exposure.
  • [SAFE]: Static Analysis Tooling: The provided verify.sh script is a read-only bash linter that checks for common configuration errors and anti-patterns without performing network requests or executing untrusted external payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — huggingface