HuggingFace Model Download

Pass

Audited by Socket on Feb 18, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 18, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/trevors%2Fdot-claude%2Fhuggingface-model-download%2F@fba1b2309347303fd1537b4a83ee24ffaed2cd2e