hf-upload — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited hf-upload (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill requires Python 3.8+ and standard library only. No external packages needed.
To install this skill's dependencies:
pip-compile ./requirements.in
pip install -r ./requirements.txtSee ./requirements.txt for the dependency lockfile (currently empty — standard library only).
Status: Active Author: Richard Fremmerlid Domain: HuggingFace Integration Depends on: hf-init (credentials must be configured first)
Provides consolidated upload operations for all HF-consuming plugins (Primary Agent, Orchestrator, etc.). All uploads include exponential backoff for rate-limit handling.
| Function | Description | Remote Path |
|---|---|---|
upload_file() | Upload a single file | Custom path |
upload_folder() | Upload an entire directory | Custom prefix |
upload_soul_snapshot() | Upload a sealed learning snapshot | lineage/seal_<timestamp>_*.md |
upload_semantic_cache() | Upload RLM semantic cache | data/rlm_summary_cache.json |
append_to_jsonl() | Append records to soul traces | data/soul_traces.jsonl |
ensure_dataset_structure() | Create ADR 081 folders | lineage/, data/, metadata/ |
ensure_dataset_card() | Create/verify tagged README.md | README.md |
from hf_upload import upload_file, upload_soul_snapshot, append_to_jsonl
# Upload a single file
result = await upload_file(Path("my_file.md"), "lineage/my_file.md")
# Upload a sealed learning snapshot
result = await upload_soul_snapshot(Path("snapshot.md"), valence=-0.5)
# Append records to soul_traces.jsonl
result = await append_to_jsonl([{"type": "learning", "content": "..."}])hf-init first to validate credentials and dataset structurehuggingface_hub installed (pip install huggingface_hub)HUGGING_FACE_USERNAME, HUGGING_FACE_TOKENAll operations return HFUploadResult with:
success: bool — whether the upload succeededrepo_url: str — HuggingFace dataset URLremote_path: str — path within the dataseterror: str — error message if failedRate-limited requests retry with exponential backoff (up to 5 attempts).
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.