huggingface-tool-builder

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides baseline and reference scripts for interacting with Hugging Face's official API and CLI tools. All network operations are directed at official huggingface.co domains. Authentication is handled correctly through the HF_TOKEN environment variable, avoiding hardcoded secrets. The shell and Python scripts include input validation (e.g., checking if limits are numeric) and use standard utilities like curl and jq for data processing. References to external tools like the hf CLI are for official Hugging Face utilities. No malicious patterns such as obfuscation, persistence, or data exfiltration were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:22 PM
Security Audit — agent-trust-hub — huggingface-tool-builder