hugging-face-paper-publisher
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The stated purpose, requested HF write token, and Hugging Face/arXiv workflow are broadly coherent, and the dependency path appears to use normal Python tooling. However, the core script that would receive the token and perform network writes is missing from the provided content, so credential handling and endpoint integrity cannot be verified. Risk is medium due to incomplete visibility plus unpinned runtime dependency installation, not because of clear malicious behavior.
Confidence: 88%Severity: 52%
Audit Metadata