huggingface-docs
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a static documentation collection. It does not contain executable code or instructions that bypass safety guidelines.
- [COMMAND_EXECUTION]: Files such as
huggingface.js.mdandinference-providers.mdcontain documentation snippets showing how to use package managers likepip,npm, andpnpm, as well ascurlfor API requests. These are standard instructional examples for the Hugging Face ecosystem. - [EXTERNAL_DOWNLOADS]: The documentation references official Hugging Face domains and repositories for package installation and model access. These references target well-known and trusted services.
- [DATA_EXPOSURE]: While the documentation mentions the use of
HF_TOKENfor authentication, no actual credentials or secrets are present within the skill files.
Audit Metadata