huggingface-hub

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/spaces-docker.md

The content is a comprehensive, largely prudent guide to building and deploying Docker-based Hugging Face Spaces with proper secret handling, non-root usage, and access controls. While no malicious payload is evident, the material highlights sensitive areas (build-time/runtime secrets, authenticated hub interactions) that require careful secret management, access control, and monitoring in real-world use. The overall security posture is moderate due to the inherent secrets handling risk, not due to any malicious intent in the fragments.

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:08 PM
Package URL
pkg:socket/skills-sh/gary149%2Fhuggingface-hub-skill%2Fhuggingface-hub%2F@d5e8f2bd7614a60b4d1c9ad11d850823972e493e