NYC

hf-mcp

Pass

Audited by Socket on Feb 12, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 12, 2026, 08:29 PM
Package URL
pkg:socket/skills-sh/huggingface%2Fskills%2Fhf-mcp%2F@0dfccf04cfff8fc2215180c25af09e234e1ecb4c