huggingface-tool-builder
Use this skill when the user wants to build tool/scripts or achieve a task where using data from the Hugging Face API would help. This is especially useful when chaining or combining API calls or the task will be repeated/automated. This Skill creates a reusable script to fetch, enrich or process...
Install this skill
or
75/100
Security score
The huggingface-tool-builder skill was audited on Oct 1, 2026 and we found 3 security issues across 1 threat category, including 1 high-severity. Review the findings below before installing.
Categories Tested
Security Issues
high line 16
Curl to non-GitHub URL
SourceSKILL.md
| 14 | - Non-destructive scripts should be tested before handing over to the User |
| 15 | - Shell scripts are preferred, but use Python or TSX if complexity or user need requires it. |
| 16 | - IMPORTANT: Use the `HF_TOKEN` environment variable as an Authorization header. For example: `curl -H "Authorization: Bearer ${HF_TOKEN}" https://huggingface.co/api/`. This provides higher rate limits and appropriate authorization for data access. |
| 17 | - Investigate the shape of the API results before commiting to a final design; make use of piping and chaining where composability would be an advantage - prefer simple solutions where possible. |
| 18 | - Share usage examples once complete. |
medium line 72
Curl to non-GitHub URL
SourceSKILL.md
| 70 | |
| 71 | ```bash |
| 72 | curl -s "https://huggingface.co/.well-known/openapi.json" | jq '.paths | keys | sort' |
| 73 | ``` |
| 74 |
medium line 78
Curl to non-GitHub URL
SourceSKILL.md
| 76 | |
| 77 | ```bash |
| 78 | curl -s "https://huggingface.co/.well-known/openapi.json" | jq '.paths["/api/models"]' |
| 79 | ``` |
| 80 |
Scanned on Oct 1, 2026
View Security Dashboard