huggingface-papers

Pass

Audited by ZeroLeaks on Apr 15, 2026

Risk Level: LOW
Scan Summary

The skill receives a WARNING verdict driven by a transparency concern: an obfuscated or encoded execution path weakens the ability to fully review what the skill does before loading, which limits pre-use confidence. On the positive side, instruction/data boundaries stay reasonably clear, and no strong prompt-injection vectors were identified in the scan. However, behavior analysis was not run, so there is no direct evidence on whether loading the skill materially changes downstream agent behavior compared to baseline—this gap, combined with the reviewability issue, keeps confidence low and means the clean-pass bar is not met.

Score
86/100
Verdict
WARNING
Confidence
low
Findings
1
Section Analysis (3)
TransparencyWARNING
74/100

The skill has 1 transparency concern that weaken pre-use reviewability, mainly around obfuscated or encoded execution path.

Prompt InjectionPASS
92/100

The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.

Agent BehaviorSkipped

Behavior analysis was not run.

Findings (1)
HIGH

Obfuscated or encoded execution path

Coverage DetailsClick to expand
Discovered Files
1
Omitted Files
0
Analyzed Bytes
9.1 KB
Sections Completed
2
Sections Skipped
1
Behavior Probes
0/0
Audit Metadata
Score
86/100
Verdict
WARNING
Confidence
low
Sections
2/3 completed
Findings
1
Mode
risk
Files Scanned
1
Duration
105.1s
Analyzed
Apr 15, 2026, 11:05 PM
Security Audit — zeroleaks — huggingface-papers