huggingface
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from the Hugging Face Hub, such as dataset rows and repository metadata, which could contain malicious instructions designed to influence the agent.\n
- Ingestion points: Model and dataset repository cards, file trees, and dataset rows retrieved via the Dataset Viewer API.\n
- Boundary markers: Directives like "Inspect before transfer" and the requirement to verify facts against live Hub data serve as boundary markers.\n
- Capability inventory: The agent can execute
hfCLI commands for file operations, repository management, and compute job control.\n - Sanitization: The skill mandates explicit user authorization for all external mutations, visibility changes, and paid resource consumption.\n- [EXTERNAL_DOWNLOADS]: Retrieves models, datasets, and documentation from the Hugging Face Hub.\n
- Evidence: The skill interacts with official domains (
huggingface.co) and refers to thehuggingface_hubpackage, which are trusted and well-known services.\n- [COMMAND_EXECUTION]: Uses the localhfCLI to perform repository and job operations.\n - Evidence: Extensive use of commands like
hf download,hf upload, andhf jobs listto interact with the Hub.
Audit Metadata