hf-upload

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is broadly coherent with its stated purpose: it provides HuggingFace upload primitives and related dataset-management helpers with backoff. The use of official huggingface_hub and environment-based credentials is appropriate, but there are mild security considerations around credential exposure in logs and error messages, and potential data volumes during uploads. Overall, the design is benign and proportionate to its goal, with moderate security risk primarily around credential handling visibility and logging.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 07:00 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fhf-upload%2F@e15d6b83038d145f8ce88bfc025ac1c9af030953