Skip to main content

huggingface-best

>-

Install this skill

or
94/100

Security score

The huggingface-best skill was audited on Oct 1, 2026 and we found 6 security issues across 2 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

low line 46

Command substitution pattern

SourceSKILL.md
44
45```bash
46curl -s -H "Authorization: Bearer $(cat ~/.cache/huggingface/token)" \
47 "https://huggingface.co/api/datasets?filter=benchmark:official&limit=500" | jq '[.[] | {id, tags, description}]'
48```
low line 59

Command substitution pattern

SourceSKILL.md
57
58```bash
59curl -s -H "Authorization: Bearer $(cat ~/.cache/huggingface/token)" \
60 "https://huggingface.co/api/datasets/<namespace>/<repo>/leaderboard" | jq '[.[:15] | .[] | {rank, modelId, value, verified}]'
61```
low line 73

Command substitution pattern

SourceSKILL.md
71```bash
72# REST API
73curl -s -H "Authorization: Bearer $(cat ~/.cache/huggingface/token)" \
74 "https://huggingface.co/api/models/org/model1" | jq '{safetensors, tags, cardData}'
75
low line 46

Access to home directory dotfiles

SourceSKILL.md
44
45```bash
46curl -s -H "Authorization: Bearer $(cat ~/.cache/huggingface/token)" \
47 "https://huggingface.co/api/datasets?filter=benchmark:official&limit=500" | jq '[.[] | {id, tags, description}]'
48```
low line 59

Access to home directory dotfiles

SourceSKILL.md
57
58```bash
59curl -s -H "Authorization: Bearer $(cat ~/.cache/huggingface/token)" \
60 "https://huggingface.co/api/datasets/<namespace>/<repo>/leaderboard" | jq '[.[:15] | .[] | {rank, modelId, value, verified}]'
61```
low line 73

Access to home directory dotfiles

SourceSKILL.md
71```bash
72# REST API
73curl -s -H "Authorization: Bearer $(cat ~/.cache/huggingface/token)" \
74 "https://huggingface.co/api/models/org/model1" | jq '{safetensors, tags, cardData}'
75
Scanned on Oct 1, 2026
View Security Dashboard
Installation guide →
Rate this skill
Categorydevelopment
UpdatedOctober 9, 2026
jacobwell/skills