huggingface-community-evals
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill largely matches its stated purpose and uses standard developer tooling, but it includes an explicit path to execute unreviewed Hugging Face model repository code via --trust-remote-code and forwards HF credentials into third-party evaluation CLIs. This is proportionate for local model evals yet still a meaningful security risk, so it is not benign.
Confidence: 89%Severity: 58%
Audit Metadata