hugging-face-jobs

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Hugging Face Hub datasets which may contain untrusted instructions. \n * Ingestion points: Data is loaded via datasets.load_dataset in cot-self-instruct.py, generate-responses.py, and finepdfs-stats.py. \n * Boundary markers: Scripts use apply_chat_template for delimiter formatting, but do not explicitly filter for malicious instructions. \n * Capability inventory: The skill enables remote code execution via hf_jobs and write access to Hub repositories via push_to_hub. \n * Sanitization: No explicit sanitization or validation of input dataset content is performed. \n- [DYNAMIC_EXECUTION]: The primary purpose of this skill is to generate and execute Python code remotely on managed Hugging Face Jobs infrastructure using the hf_jobs tool. \n- [EXTERNAL_DOWNLOADS]: The skill references and downloads scripts from official Hugging Face Hub infrastructure and GitHub repositories. These resources are from a recognized trusted organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 07:41 PM
Security Audit — agent-trust-hub — hugging-face-jobs