huggingface-lora-space-builder

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs necessary dependencies from official Hugging Face sources and other well-known repositories associated with the specific models being deployed. All downloads are contextually appropriate and target reputable sources.
  • [DYNAMIC_EXECUTION]: The skill generates and deploys Python code to Hugging Face Spaces and supports custom UI components via JavaScript and HTML. These activities are transparently managed and require user review before publication.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external model descriptions from the Hugging Face Hub. The associated risks are mitigated by the skill's workflow, which mandates manual approval of all generated files before they are shared or executed.
  • [SAFE]: No malicious patterns, such as prompt injection, data exfiltration, or persistence mechanisms, were found. The skill follows secure conventions for deployment in a cloud-based inference environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:52 AM
Security Audit — agent-trust-hub — huggingface-lora-space-builder