huggingface
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Token Security: The skill explicitly enforces the use of environment variables for authentication (
HF_TOKEN) and includes a linter script (scripts/verify.sh) to detect and block hardcoded token literals in the codebase. - [SAFE]: Trusted Dependencies: External packages such as
huggingface_hubandtransformersare officially maintained by Hugging Face, a well-known and trusted provider. Installation commands point to standard package registries. - [SAFE]: Secure Infrastructure: Routing is directed to official Hugging Face endpoints (
router.huggingface.co), and the skill accurately differentiates between local execution and hosted inference to minimize unnecessary infrastructure exposure. - [SAFE]: Static Analysis Tooling: The provided
verify.shscript is a read-only bash linter that checks for common configuration errors and anti-patterns without performing network requests or executing untrusted external payloads.
Audit Metadata