NYC

hugging-face-cli

Pass

Audited by Socket on Feb 16, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 16, 2026, 04:09 AM
Package URL
pkg:socket/skills-sh/smithery%2Fai%2Fhugging-face-cli%2F@4589f11b8bad415ad4d81bb96452f5d6843a0e320e325b3ec8b3ec9087e8b681