hugging-face-evaluation
Warn
Audited by Socket on Apr 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core behavior is mostly aligned with its stated Hugging Face evaluation purpose, and the main services referenced are official/documented. However, it combines mutable uv-based execution, credential forwarding to remote jobs and a third-party API, and optional remote-code model execution, creating a medium security risk that is broader than a simple model-card editing skill.
Confidence: 89%Severity: 61%
Audit Metadata