hugging-face

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its purpose, and the CLI install path appears to be an official npm-distributed Membrane tool rather than a hidden payload. However, the skill is not a direct Hugging Face integration: it requires a separate Membrane account, stores/refreshes credentials server-side, and routes requests through Membrane’s proxy. That intermediary credential and data flow is clearly disclosed but meaningfully expands trust and creates medium security risk, especially given generic proxy access and destructive account-management actions.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhugging-face%2F@d7bc9aff50e8d06d0d5baa954b811b9542581c8e
Security Audit — socket — hugging-face