No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by huggingface · Agent Tool · ★ 11.1k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is skills safe to install? View the security audit →
Hugging Face Skills Hugging Face Skills are definitions for AI/ML tasks like dataset creation, model training, and evaluation. The client plugin marketplaces expose the skill as the bootstrap path for core Hub operations; additional workflow skills can be installed on demand with or discovered by skill-aware clients over CLI/MCP integrations. The skills in this repository follow the standardized Agent Skills format. [!NOTE] Just want to give your agent access to the Hugging Face Hub? Start with . It's the recommended first Skill to install: it teaches your agent every command (search models, manage datasets and buckets, launch Spaces, run jobs) and is generated from your locally installed CLI so it stays current. How do Skills work? In practice, skills are self-contained folders that package instructions, scripts, and resources together for an AI agent to use on a specific use case. Each folder includes a file with YAML frontmatter (name and description) followed by the guidance your coding agent follows while the skill is active. [!TIP] If your agent doesn't support skills, you can use directly as a fallback.
| Stars | 11,088 |
| Forks | 748 |
| Language | Python |
| Category | Agent Tool |
| License | Apache-2.0 |
| Quality Score | 64.8642164679472/100 |
| Open Issues | 58 |
| Last Updated | 2026-09-22 |
| Created | 2025-11-24 |
| Platforms | python |
| Est. Tokens | ~16k |
These tools work well together with skills for enhanced workflows:
Looking for a skills alternative? If you're comparing skills with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
A hand-picked collection of the finest of resources for the most awesome of agents, Claude Code, the undispute
A 100% free modern JS SaaS boilerplate (React, NodeJS, Prisma). Full-featured: Auth (email, google, github, sl
Use this skill to enable Claude Code to communicate directly with your Google NotebookLM notebooks. Query your
The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Curso
Skill to give Claude Code (and any coding agent) the ability to generate beautiful and practical Excalidraw di
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and
Explore other popular agent tool tools:
skills is Give your agents the power of the Hugging Face ecosystem. It is categorized as a Agent Tool with 11.1k GitHub stars.
skills is primarily written in Python.
You can find installation instructions and usage details in the skills GitHub repository at github.com/huggingface/skills. The project has 11.1k stars and 748 forks, indicating an active community.
skills is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to skills on Agent Skills Hub include awesome-claude-code, open-saas, notebooklm-skill. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: