hf-download

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill downloads content from HuggingFace (huggingface.co), which is a well-known and trusted repository for machine learning models and datasets.
  • [SAFE]: Credential management instructions follow security best practices, advising the use of environment variables and explicitly prohibiting the logging or plain-text storage of API tokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data, which inherently creates a surface for indirect prompt injection.
  • Ingestion points: Files and folder snapshots downloaded from HuggingFace repositories (e.g., unsloth/gemma-4-12b-it-GGUF).
  • Boundary markers: The provided documentation does not include specific delimiters or instructions for the agent to ignore potentially malicious commands embedded in downloaded files.
  • Capability inventory: The skill environment allows access to Bash and Read tools.
  • Sanitization: There are no descriptions of sanitization or validation processes for the downloaded content prior to its use by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 12:56 PM
Security Audit — agent-trust-hub — hf-download