huggingface-local-models

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill guides the agent to fetch and process data from Hugging Face Hub repositories to determine configuration parameters. This represents a surface where external content could potentially influence the agent's execution of commands.
  • Evidence: references/hub-discovery.md describes extracting snippets and file information from huggingface.co URLs and APIs.
  • External Resource Acquisition: The skill facilitates downloading and compiling software from established community sources and acquiring model weights.
  • Evidence: SKILL.md provides steps to clone the llama.cpp repository and download model files via the Hugging Face CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 11:17 PM