hugging-science

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent with its stated scientific-ML discovery purpose and uses mostly official Hugging Face surfaces, so there is no strong evidence of malware or credential harvesting. However, it asks the agent to read local `.env` secrets and, more importantly, normalizes `trust_remote_code=True` and programmatic Space usage, which create meaningful execution-trust and credential/data-forwarding risk beyond simple catalog browsing.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
May 1, 2026, 06:08 PM
Package URL
pkg:socket/skills-sh/K-Dense-AI%2Fscientific-agent-skills%2Fhugging-science%2F@c27f55bfe7fd7a786e0e5fec235f259956ec26f9