hugging-science

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from huggingscience.co through the scripts/fetch_catalog.py utility. \n
  • Ingestion points: Resource descriptions and metadata are fetched from huggingscience.co/llms-full.txt and topic-specific markdown files.\n
  • Boundary markers: The script wraps all fetched content in a clear UNTRUSTED_BANNER to alert the agent that the data is not instructional.\n
  • Capability inventory: The skill allows for environment variable modification (.env), external library installation (uv), and Python execution via transformers and gradio_client.\n
  • Sanitization: The _defang function in scripts/fetch_catalog.py neutralizes potential injection by replacing markdown code fences (```) and filtering frontmatter delimiters (---).\n- [DYNAMIC_EXECUTION]: The documentation for using scientific models (references/using-models.md) acknowledges that many specialized models require the trust_remote_code=True flag in the transformers library. The skill explicitly instructs the agent to describe the repository and request affirmative user consent before setting this flag, ensuring the user remains in control of executing third-party modeling code.\n- [EXTERNAL_DOWNLOADS]: The skill fetches catalog indices and scientific metadata from huggingscience.co. This domain is an official resource provided by the skill's author, and the URLs are validated against a whitelist in the fetching script.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — hugging-science