huggingface-local-models
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill guides the agent to fetch and process data from Hugging Face Hub repositories to determine configuration parameters. This represents a surface where external content could potentially influence the agent's execution of commands.
- Evidence:
references/hub-discovery.mddescribes extracting snippets and file information fromhuggingface.coURLs and APIs. - External Resource Acquisition: The skill facilitates downloading and compiling software from established community sources and acquiring model weights.
- Evidence:
SKILL.mdprovides steps to clone thellama.cpprepository and download model files via the Hugging Face CLI.
Audit Metadata