hugging-science
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from
huggingscience.cothrough thescripts/fetch_catalog.pyutility. \n - Ingestion points: Resource descriptions and metadata are fetched from
huggingscience.co/llms-full.txtand topic-specific markdown files.\n - Boundary markers: The script wraps all fetched content in a clear
UNTRUSTED_BANNERto alert the agent that the data is not instructional.\n - Capability inventory: The skill allows for environment variable modification (
.env), external library installation (uv), and Python execution viatransformersandgradio_client.\n - Sanitization: The
_defangfunction inscripts/fetch_catalog.pyneutralizes potential injection by replacing markdown code fences (```) and filtering frontmatter delimiters (---).\n- [DYNAMIC_EXECUTION]: The documentation for using scientific models (references/using-models.md) acknowledges that many specialized models require thetrust_remote_code=Trueflag in thetransformerslibrary. The skill explicitly instructs the agent to describe the repository and request affirmative user consent before setting this flag, ensuring the user remains in control of executing third-party modeling code.\n- [EXTERNAL_DOWNLOADS]: The skill fetches catalog indices and scientific metadata fromhuggingscience.co. This domain is an official resource provided by the skill's author, and the URLs are validated against a whitelist in the fetching script.
Audit Metadata