hugging-face-jobs

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is designed for the legitimate purpose of running managed compute jobs. It includes extensive documentation on the secure handling of Hugging Face authentication tokens, explicitly warning against hardcoding credentials and detailing the use of encrypted secrets.
  • [COMMAND_EXECUTION]: The skill utilizes the hf_jobs MCP tool to run Python scripts and Docker-based workloads on remote infrastructure. The instructions guide the agent to pass script contents as strings or URLs to the tool, which is the intended primary functionality.
  • [EXTERNAL_DOWNLOADS]: The skill references scripts and datasets from well-known technology services, specifically huggingface.co and github.com/huggingface. These references are documented neutrally and are part of the standard workflow for the targeted infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 04:30 PM
Security Audit — agent-trust-hub — hugging-face-jobs