hf-cli

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose aligns with Hugging Face account and Hub administration, and most capabilities are coherent for an official CLI skill. However, the footprint is broad for an agent skill: pipe-to-shell installers, optional raw-GitHub installer, third-party extension installs, transitive skill installation, token handling, file upload/sync, and powerful destructive admin actions. This looks like a legitimate but high-impact skill whose risk comes from supply-chain trust and expansive remote-action scope, not clear malicious intent.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Aug 15, 2026, 03:44 AM
Package URL
pkg:socket/skills-sh/waybarrios%2Fopencode-power-pack%2Fhf-cli%2F@3f6d9b41e435a441912cd579ff281c262889cf747fa3e9071fdd06a83afe2725
Security Audit — socket — hf-cli