huggingface-jobs

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • Secure Credential Management: The skill provides extensive documentation on the safe handling of Hugging Face tokens. It emphasizes the use of the $HF_TOKEN placeholder, which is automatically and securely replaced by the execution environment, effectively preventing the accidental exposure of sensitive credentials in code or logs.
  • Trusted External Resource Integration: The skill references scripts and Docker images hosted on Hugging Face and GitHub. These references target well-known and verified organizations, ensuring that the remote content used for job execution originates from reputable sources.
  • Scoped Execution Environment: The primary function of the skill is to facilitate the remote execution of Python workloads (such as data processing and model inference) on managed cloud infrastructure. This behavior is the intended purpose of the skill and is implemented through documented integration with platform-provided tools.
  • Comprehensive Security Guidance: The included references (e.g., token_usage.md and troubleshooting.md) offer clear instructions on avoiding common security pitfalls, such as hardcoding secrets or using insecure environment variable patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:44 PM
Security Audit — agent-trust-hub — huggingface-jobs