ops-huggingface

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Python scripts to interact with the Hugging Face API. It implements a 'dry-run-first' safety contract where destructive or modifying operations (create-repo, upload, snapshot) require an explicit --execute flag. If the flag is omitted, the skill only generates a receipt confirming what would have happened.
  • [CREDENTIALS_UNSAFE]: The skill manages authentication tokens (HF_TOKEN, HUGGINGFACE_HUB_TOKEN) but includes specific logic in scripts/hf_ops.py to prevent token values from being printed or logged. The whoami and auth_receipt functions verify authentication status and source without leaking the actual secrets.
  • [EXTERNAL_DOWNLOADS]: The skill includes external references to Hugging Face documentation in SKILL.md. These target a well-known service (huggingface.co) for the purpose of retrieving live library documentation and do not involve executable code downloads.
  • [DATA_EXFILTRATION]: While the skill facilitates data uploads to Hugging Face, these are user-directed via the upload command and require the --execute flag. The skill does not attempt to read sensitive system files or exfiltrate data to unauthorized domains.
  • [SAFE]: The metadata and script provenance documentation ('reconstructed from bytecode') is transparently declared and the resulting Python source code is clean, standard CLI code using the established typer and huggingface_hub libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — ops-huggingface