AGENT LAB: SKILLS

hugging-face-tool-builder

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill description and its examples are coherent and consistent with the declared purpose: building reusable scripts that interact with the Hugging Face API or `hf` CLI. I found no indications of malicious behavior, unknown network endpoints, obfuscated code, or credential exfiltration. The primary security considerations are standard operational hygiene: protect HF_TOKEN from being logged or committed, validate inputs before writing files, and avoid piping credentials to untrusted third parties. Overall the artifact appears benign.

Confidence: 85%Severity: 15%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/huggingface%2Fskills%2Fhugging-face-tool-builder%2F@6015a4182c147bafff8c1eb01a136abf935bdd2d