hugging-science

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches scientific catalog data from the huggingscience.co domain and retrieves datasets/models from the Hugging Face Hub. These operations are consistent with the skill's primary purpose.
  • [COMMAND_EXECUTION]: Utilizes a bundled Python script scripts/fetch_catalog.py to fetch and parse structured markdown data from the catalog service.
  • [CREDENTIALS_UNSAFE]: Promotes secure secret management by instructing the agent to load the Hugging Face API token from a .env file, adhering to standard security practices.
  • [REMOTE_CODE_EXECUTION]: Provides transparent documentation regarding the use of trust_remote_code=True for specific scientific models with custom architectures, ensuring users are informed before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 09:23 PM
Security Audit — agent-trust-hub — hugging-science