Hugging Face Dataset Viewer
Give your agents the power of the Hugging Face ecosystem
Install this skill
or
69/100
Security score
The Hugging Face Dataset Viewer skill was audited on Oct 1, 2026 and we found 7 security issues across 2 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
medium line 44
Curl to non-GitHub URL
SourceSKILL.md
| 42 | |
| 43 | ```bash |
| 44 | curl "https://datasets-server.huggingface.co/rows?dataset=stanfordnlp/imdb&config=plain_text&split=train&offset=0&length=100" |
| 45 | curl "https://datasets-server.huggingface.co/rows?dataset=stanfordnlp/imdb&config=plain_text&split=train&offset=100&length=100" |
| 46 | ``` |
medium line 45
Curl to non-GitHub URL
SourceSKILL.md
| 43 | ```bash |
| 44 | curl "https://datasets-server.huggingface.co/rows?dataset=stanfordnlp/imdb&config=plain_text&split=train&offset=0&length=100" |
| 45 | curl "https://datasets-server.huggingface.co/rows?dataset=stanfordnlp/imdb&config=plain_text&split=train&offset=100&length=100" |
| 46 | ``` |
| 47 |
medium line 69
Curl to non-GitHub URL
SourceSKILL.md
| 67 | |
| 68 | ```bash |
| 69 | curl -s "https://datasets-server.huggingface.co/parquet?dataset=<namespace>/<repo>" |
| 70 | ``` |
| 71 |
medium line 98
Access to home directory dotfiles
SourceSKILL.md
| 96 | The Hub supports raw agent session traces from Claude Code, Codex, and Pi Agent. Upload them to Hugging Face Datasets as original JSONL files and the Hub can auto-detect the trace format, tag the dataset as `Traces`, and enable the trace viewer for browsing sessions, turns, tool calls, and model responses. Common local session directories: |
| 97 | |
| 98 | - Claude Code: `~/.claude/projects` |
| 99 | - Codex: `~/.codex/sessions` |
| 100 | - Pi: `~/.pi/agent/sessions` |
medium line 99
Access to home directory dotfiles
SourceSKILL.md
| 97 | |
| 98 | - Claude Code: `~/.claude/projects` |
| 99 | - Codex: `~/.codex/sessions` |
| 100 | - Pi: `~/.pi/agent/sessions` |
| 101 |
medium line 100
Access to home directory dotfiles
SourceSKILL.md
| 98 | - Claude Code: `~/.claude/projects` |
| 99 | - Codex: `~/.codex/sessions` |
| 100 | - Pi: `~/.pi/agent/sessions` |
| 101 | |
| 102 | Default to private dataset repos because traces can contain prompts, file paths, tool outputs, secrets, or PII. Preserve the raw `.jsonl` files and nest them by project/cwd instead of uploading every session at the dataset root. |
low line 106
Access to home directory dotfiles
SourceSKILL.md
| 104 | ```bash |
| 105 | hf repos create <namespace>/<repo> --type dataset --private --exist-ok |
| 106 | hf upload <namespace>/<repo> ~/.codex/sessions codex/<project-or-cwd> --type dataset |
| 107 | ``` |
| 108 |
Scanned on Oct 1, 2026
View Security Dashboard