hugging-face

Pass

Audited by Socket on Apr 17, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Apr 17, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fhugging-face%2F@2f7ebba04b4a34f6040327c09ba5268b80801713