huggingface-docs

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a static documentation collection. It does not contain executable code or instructions that bypass safety guidelines.
  • [COMMAND_EXECUTION]: Files such as huggingface.js.md and inference-providers.md contain documentation snippets showing how to use package managers like pip, npm, and pnpm, as well as curl for API requests. These are standard instructional examples for the Hugging Face ecosystem.
  • [EXTERNAL_DOWNLOADS]: The documentation references official Hugging Face domains and repositories for package installation and model access. These references target well-known and trusted services.
  • [DATA_EXPOSURE]: While the documentation mentions the use of HF_TOKEN for authentication, no actual credentials or secrets are present within the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 12:51 PM
Security Audit — agent-trust-hub — huggingface-docs