hf-cli
Hugging Face Hub CLI (`hf`) for downloading, uploading, and managing models, datasets, spaces, buckets, repos, papers, jobs, and more on the Hugging Face Hub. Use when: handling authentication; managing local cache; managing Hugging Face Buckets; running or scheduling jobs on Hugging Face infrast...
Install this skill
or
0/100
Security score
The hf-cli skill was audited on Oct 1, 2026 and we found 10 security issues across 4 threat categories, including 2 critical. Review the findings below before installing.
Categories Tested
Security Issues
critical line 6
Piping content to bash shell
SourceSKILL.md
| 4 | --- |
| 5 | |
| 6 | Install: `curl -LsSf https://hf.co/cli/install.sh | bash -s`. |
| 7 | |
| 8 | The Hugging Face Hub CLI tool `hf` is available. IMPORTANT: The `hf` command replaces the deprecated `huggingface-cli` command. |
high line 6
Curl to non-GitHub URL
SourceSKILL.md
| 4 | --- |
| 5 | |
| 6 | Install: `curl -LsSf https://hf.co/cli/install.sh | bash -s`. |
| 7 | |
| 8 | The Hugging Face Hub CLI tool `hf` is available. IMPORTANT: The `hf` command replaces the deprecated `huggingface-cli` command. |
medium line 208
Webhook reference
SourceSKILL.md
| 206 | ### `hf webhooks` — Manage webhooks on the Hub. |
| 207 | |
| 208 | - `hf webhooks create --watch TEXT` — Create a new webhook. `[--url TEXT --job-id TEXT --domain [repo|discussions] --secret TEXT --format [auto|human|agent|json|quiet]]` |
| 209 | - `hf webhooks delete WEBHOOK_ID` — Delete a webhook permanently. `[--yes --format [auto|human|agent|json|quiet]]` |
| 210 | - `hf webhooks disable WEBHOOK_ID` — Disable an active webhook. `[--format [auto|human|agent|json|quiet]]` |
medium line 209
Webhook reference
SourceSKILL.md
| 207 | |
| 208 | - `hf webhooks create --watch TEXT` — Create a new webhook. `[--url TEXT --job-id TEXT --domain [repo|discussions] --secret TEXT --format [auto|human|agent|json|quiet]]` |
| 209 | - `hf webhooks delete WEBHOOK_ID` — Delete a webhook permanently. `[--yes --format [auto|human|agent|json|quiet]]` |
| 210 | - `hf webhooks disable WEBHOOK_ID` — Disable an active webhook. `[--format [auto|human|agent|json|quiet]]` |
| 211 | - `hf webhooks enable WEBHOOK_ID` — Enable a disabled webhook. `[--format [auto|human|agent|json|quiet]]` |
medium line 210
Webhook reference
SourceSKILL.md
| 208 | - `hf webhooks create --watch TEXT` — Create a new webhook. `[--url TEXT --job-id TEXT --domain [repo|discussions] --secret TEXT --format [auto|human|agent|json|quiet]]` |
| 209 | - `hf webhooks delete WEBHOOK_ID` — Delete a webhook permanently. `[--yes --format [auto|human|agent|json|quiet]]` |
| 210 | - `hf webhooks disable WEBHOOK_ID` — Disable an active webhook. `[--format [auto|human|agent|json|quiet]]` |
| 211 | - `hf webhooks enable WEBHOOK_ID` — Enable a disabled webhook. `[--format [auto|human|agent|json|quiet]]` |
| 212 | - `hf webhooks info WEBHOOK_ID` — Show full details for a single webhook. `[--format [auto|human|agent|json|quiet]]` |
medium line 211
Webhook reference
SourceSKILL.md
| 209 | - `hf webhooks delete WEBHOOK_ID` — Delete a webhook permanently. `[--yes --format [auto|human|agent|json|quiet]]` |
| 210 | - `hf webhooks disable WEBHOOK_ID` — Disable an active webhook. `[--format [auto|human|agent|json|quiet]]` |
| 211 | - `hf webhooks enable WEBHOOK_ID` — Enable a disabled webhook. `[--format [auto|human|agent|json|quiet]]` |
| 212 | - `hf webhooks info WEBHOOK_ID` — Show full details for a single webhook. `[--format [auto|human|agent|json|quiet]]` |
| 213 | - `hf webhooks list` — List all webhooks for the current user. `[--format [auto|human|agent|json|quiet]]` |
medium line 212
Webhook reference
SourceSKILL.md
| 210 | - `hf webhooks disable WEBHOOK_ID` — Disable an active webhook. `[--format [auto|human|agent|json|quiet]]` |
| 211 | - `hf webhooks enable WEBHOOK_ID` — Enable a disabled webhook. `[--format [auto|human|agent|json|quiet]]` |
| 212 | - `hf webhooks info WEBHOOK_ID` — Show full details for a single webhook. `[--format [auto|human|agent|json|quiet]]` |
| 213 | - `hf webhooks list` — List all webhooks for the current user. `[--format [auto|human|agent|json|quiet]]` |
| 214 | - `hf webhooks update WEBHOOK_ID` — Update an existing webhook. Only provided options are changed. `[--url TEXT --watch TEXT --domain [repo|discussions] --secret TEXT --format [auto|human|agent|json|quiet]]` |
medium line 214
Webhook reference
SourceSKILL.md
| 212 | - `hf webhooks info WEBHOOK_ID` — Show full details for a single webhook. `[--format [auto|human|agent|json|quiet]]` |
| 213 | - `hf webhooks list` — List all webhooks for the current user. `[--format [auto|human|agent|json|quiet]]` |
| 214 | - `hf webhooks update WEBHOOK_ID` — Update an existing webhook. Only provided options are changed. `[--url TEXT --watch TEXT --domain [repo|discussions] --secret TEXT --format [auto|human|agent|json|quiet]]` |
| 215 | |
| 216 | ## Common options |
critical line 6
Curl pipe to interpreter
SourceSKILL.md
| 4 | --- |
| 5 | |
| 6 | Install: `curl -LsSf https://hf.co/cli/install.sh | bash -s`. |
| 7 | |
| 8 | The Hugging Face Hub CLI tool `hf` is available. IMPORTANT: The `hf` command replaces the deprecated `huggingface-cli` command. |
high line 17
Download and run instruction
SourceSKILL.md
| 15 | |
| 16 | - `hf cp SRC` — Copy files between local paths, repositories, and buckets. `[--format [auto|human|agent|json|quiet]]` |
| 17 | - `hf download REPO_ID` — Download files from the Hub. `[--type [model|dataset|space|kernel] --revision TEXT --include TEXT --exclude TEXT --cache-dir TEXT --local-dir TEXT --force-download --dry-run --max-workers INTEGER --format [auto|human|agent|json|quiet]]` |
| 18 | - `hf env` — Print information about the environment. `[--format [auto|human|agent|json|quiet]]` |
| 19 | - `hf sync` — Sync files between local directory and a bucket. `[--delete --ignore-times --ignore-sizes --plan TEXT --apply TEXT --dry-run --include TEXT --exclude TEXT --filter-from TEXT --existing --ignore-existing --verbose --format [auto|human|agent|json|quiet]]` |
Scanned on Oct 1, 2026
View Security Dashboard