hf-init — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited hf-init (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill requires Python 3.8+ and standard library only. No external packages needed.
To install this skill's dependencies:
pip-compile ./requirements.in
pip install -r ./requirements.txtSee ./requirements.txt for the dependency lockfile (currently empty — standard library only).
Status: Active Author: Richard Fremmerlid Domain: HuggingFace Integration
Sets up everything needed for HuggingFace persistence. Run this once when onboarding a new project, or whenever credentials change.
.env variables are setlineage/, data/, metadata/)| Variable | Required | Description |
|---|---|---|
HUGGING_FACE_USERNAME | ✅ Yes | Your HF username |
HUGGING_FACE_TOKEN | ✅ Yes | API token (set in ~/.zshrc, NOT .env) |
HUGGING_FACE_REPO | ✅ Yes | Model repo name |
HUGGING_FACE_DATASET_PATH | ✅ Yes | Dataset repo name |
HUGGING_FACE_TAGS | ❌ No | Comma-separated discovery tags for dataset card |
HUGGING_FACE_PROJECT_NAME | ❌ No | Pretty name for dataset card heading |
SOUL_VALENCE_THRESHOLD | ❌ No | Moral/emotional charge filter (default: -0.7) |
python ./hf_config.pypython ./hf_init.pypython ./hf_init.py --validate-only# Token goes in shell profile (never committed):
export HUGGING_FACE_TOKEN=hf_xxxxxxxxxxxxx
# Project vars go in .env:
HUGGING_FACE_USERNAME=<your-username>
HUGGING_FACE_REPO=<your-model-repo>
HUGGING_FACE_DATASET_PATH=<your-dataset-repo>
# Optional customization:
HUGGING_FACE_TAGS=reasoning-traces,cognitive-continuity,your-project-tag
HUGGING_FACE_PROJECT_NAME=My Project Soul
# Run init
python ./hf_init.py~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.