huggingface-llm-trainer
Audited by Socket on Aug 18, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: The skill is largely coherent and uses official Hugging Face/Astral tooling, so it does not look malicious. However, it meaningfully increases operational risk by instructing autonomous cloud job submission and by encouraging execution of remote, unpinned scripts inside job containers while forwarding HF credentials.
No direct indicators of embedded malware are present in this fragment (it performs model merge → GGUF conversion/quantization → upload). However, the script deliberately creates high-impact supply-chain and remote-code-execution risk by (1) using trust_remote_code=True when loading remote Hugging Face model/tokenizer code and (2) cloning an unpinned llama.cpp repository at runtime, installing its Python requirements via pip, and executing its conversion/quantization tooling. Treat this as a security alert for supply-chain integrity: pin exact revisions, minimize/disable trust_remote_code where possible, and control/validate the environment-provided model identifiers and OUTPUT_REPO.