hf-cli

Pass

Audited by Socket on May 7, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
May 7, 2026, 02:21 PM
Package URL
pkg:socket/skills-sh/huggingface%2Fskills%2Fhf-cli%2F@c8920fd4af68b30c13d07af607ed8d666c32c423