hf-download

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates downloading assets from HuggingFace (huggingface.co), which is a well-known and trusted service for machine learning models and datasets.
  • [CREDENTIALS_SAFE]: The documentation and acceptance criteria emphasize secure handling of the HUGGING_FACE_TOKEN, instructing users to use environment variables and explicitly forbidding the logging or plain-text storage of credentials.
  • [SAFE]: The skill relies on the huggingface_hub library, which is maintained by a trusted organization (HuggingFace) and is standard for this use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 08:07 PM
Security Audit — agent-trust-hub — hf-download