@huggingface/hub

npm

Is @huggingface/hub safe to use?

The latest brin safety scan flagged @huggingface/hub v2.8.1 with risk indicators that warrant review. No known CVE vulnerabilities. Trust score: 75/100. Review the findings below before use. This is an automated assessment and may contain errors.

Install (safety-checked)

@huggingface/hub Has Warnings

Warnings detected due to potential concerns

warning
CVEs

0

Threats

0

Install Scripts

0

Risk Indicators

  • Can spawn child processes

brin Recommendations

  • This package has warnings detected. Evaluate the specific concerns before proceeding.

Install with brin add @huggingface/hub to automatically apply these checks before installation.

This is an automated, point-in-time assessment and may contain errors. Findings are risk indicators, not confirmed threats. Security posture may change over time. Maintainers can dispute findings via the brin review process.

@huggingface/hub Capabilities & Permissions

What @huggingface/hub can access when installed. Review these capabilities before using with AI agents like Cursor, Claude Code, or Codex.

Network Access

This package makes network requests.

aschen.techburtleburtle.netcas.cocdn-avatars.huggingface.cocdn-thumbnails.huggingface.codeveloper.mozilla.orgdiscuss.huggingface.cofetch.cofoor.bargit-lfs.github.com+10 more
Protocols: http, https

Filesystem Access

Reads and writes to the filesystem.

/etc/ (r).env (r).env (r).env (r)package.json (r)package.json (r).env (w).env (w)+12 more

Process Spawning

This package can spawn child processes.

Environment Variables

Accesses the following environment variables.

HF_ENDPOINTHF_HOMEHF_HUB_CACHEHF_TOKENHUGGINGFACE_HUB_CACHEXDG_CACHE_HOME

AGENTS.md for @huggingface/hub

Good instructions lead to good results. brin adds @huggingface/hub documentation to your AGENTS.md so your agent knows how to use it properly—improving both safety and performance.

brin init

Vercel's research: 100% accuracy with AGENTS.md vs 53% without →

@huggingface/hub Documentation & Source Code

For the full @huggingface/hub README, API documentation, and source code, visit the official package registry.

Frequently asked questions about @huggingface/hub safety

Weekly Downloads

89.9K

Version

2.8.1

License

MIT

Other Versions

Last Scanned

Feb 4, 2026

Trust Score

75/100·Legitimacy signals, not safety

Capabilities

Network

Connects to: aschen.tech, burtleburtle.net, cas.co...

Filesystem

Reads & Writes files

Process

Spawns child processes

Environment

Accesses: HF_ENDPOINT, HF_HOME, HF_HUB_CACHE...

Is @huggingface/hub Safe? | npm Safety Scan - brin