huggingface-js

Pass

Audited by Socket on Mar 29, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Mar 29, 2026, 07:55 AM
Package URL
pkg:socket/skills-sh/mgd34msu%2Fgoodvibes-gemini%2Fhuggingface-js%2F@5d0fff6e8e6139e47c74f1f3da64dcbb43fccefe