hugging-science
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is largely coherent with its stated scientific-ML discovery purpose and uses mostly official Hugging Face surfaces, so there is no strong evidence of malware or credential harvesting. However, it asks the agent to read local `.env` secrets and, more importantly, normalizes `trust_remote_code=True` and programmatic Space usage, which create meaningful execution-trust and credential/data-forwarding risk beyond simple catalog browsing.
Confidence: 87%Severity: 64%
Audit Metadata