hf-cli
Warn
Audited by Socket on Aug 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose aligns with Hugging Face account and Hub administration, and most capabilities are coherent for an official CLI skill. However, the footprint is broad for an agent skill: pipe-to-shell installers, optional raw-GitHub installer, third-party extension installs, transitive skill installation, token handling, file upload/sync, and powerful destructive admin actions. This looks like a legitimate but high-impact skill whose risk comes from supply-chain trust and expansive remote-action scope, not clear malicious intent.
Confidence: 89%Severity: 74%
Audit Metadata