huggingface-community-evals

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill largely matches its stated purpose and uses standard developer tooling, but it includes an explicit path to execute unreviewed Hugging Face model repository code via --trust-remote-code and forwards HF credentials into third-party evaluation CLIs. This is proportionate for local model evals yet still a meaningful security risk, so it is not benign.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:57 AM
Package URL
pkg:socket/skills-sh/practicalswan%2Fagent-skills%2Fhuggingface-community-evals%2F@b8a32599c16574db8802422b75c1c7fc4d8a816582f22c2564c4eedcd0f44947
Security Audit — socket — huggingface-community-evals