huggingface-hub
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents an installation method using a shell script downloaded from the official Hugging Face domain (hf.co). This is a standard deployment pattern for this service's command-line interface.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates interaction with external, community-provided content such as dataset descriptions, pull request comments, and model metadata. While this represents a potential surface for indirect prompt injection if the agent processes malicious text from the Hugging Face Hub, the skill itself does not implement unsafe data handling or automated execution of that content.
Audit Metadata