Hugging Face Skills teaches coding agents to work with the Hugging Face ecosystem. The starting point is hf-cli, which gives the agent every command of the hf tool: searching models, downloading and uploading, managing datasets and buckets, launching Spaces and running Jobs. On top of that sit about two dozen workflow skills for fine-tuning language and vision models with TRL or Unsloth on Hugging Face's cloud GPUs, training sentence-transformers, running evaluations, browsing datasets, building Gradio demos and ZeroGPU Spaces, reading and publishing papers, choosing GGUF models to run locally, and deploying to Amazon SageMaker.
It is maintained by Hugging Face and follows the open Agent Skills format, so the same folders work in Claude Code, Codex, Gemini CLI and Cursor, with a generated AGENTS.md as a fallback for agents without skill support. The marketplace entry is deliberately limited to hf-cli, and further skills are added with hf skills add when you need them.
The repository is Apache-2.0, with about 11,000 stars and 43 contributors. It is small, about 200 files, so it is easy to read every skill you plan to install.
- Repository: github.com/huggingface/skills
- Licence: Apache-2.0 (Apache License 2.0)
- Language: Python. Stars: 11.2K. Forks: 762. Last push: Oct 1, 2026.
- Scan: safe, Oct 8, 2026, commit ca0325b
Who it is for
ML engineers and researchers who already use the Hugging Face Hub and want their agent to handle the routine parts: finding models, preparing datasets, launching fine-tuning jobs and publishing demos.
Getting started
1. In Claude Code, add the repository as a plugin marketplace
/plugin marketplace add huggingface/skills2. Install the hf-cli skill
/plugin install hf-cli@huggingface/skills3. Add any other skill with the hf CLI
hf skills add <skill-name>4. Gemini CLI
gemini extensions install https://github.com/huggingface/skills.git --consentThe /plugin commands are typed inside Claude Code, not a shell. hf skills add needs the hf CLI installed. Codex users copy skill folders into .agents/skills, and Cursor installs from the repository URL through its plugin flow.
Safety scan
We cloned huggingface/skills at commit ca0325b on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious code patterns, no committed binaries and no bare-IP URLs across 203 files and about 42,000 lines.
- A second, skill-specific pass looked for invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths, pipe-to-shell commands, long base64 and plugin hooks, and found nothing of concern.
- The hosts in the code are huggingface.co, its datasets server, arXiv and GitHub. The hf-cli skill installs the hf CLI with Hugging Face's own first-party installer (curl from hf.co piped to bash), and many skills use your HF token for Hub actions, so jobs and uploads run under your account.
- No lockfiles, so no dependency advisories. 7 workflows with no pull_request_target; both third-party actions are pinned to commits and Dependabot is on. Licence present; no security policy or contributing guide in the repository.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | None. |
| CI workflows | 7 workflows. None use pull_request_target. 0 of 2 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 7 distinct hosts referenced from source; most often huggingface.co, github.com, datasets-server.huggingface.co, arxiv.org. No URLs to bare IP addresses. |
| Known vulnerabilities | No lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day. |
| Project hygiene | Has automated dependency updates, licence file. Missing security policy, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
By the numbers
| Stars | 11.2K |
|---|---|
| Forks | 762 |
| Contributors | 43 |
| Commits | 349 |
| Open issues | 11 |
| Open pull requests | 51 |
| Releases | 0 |
| Latest release | none tagged |
| Licence | Apache-2.0 |
| Main language | Python |
| Project age | 10 months |
| Last push | Oct 1, 2026 |
| Tracked files | 203 |
| Lines of code | 42K |
| Checkout size | 2 MB |
Lines by language: Markdown 24.5K, Python 15.6K, Shell 843, YAML 573, JSON 360, TypeScript 58.
Questions
Is Hugging Face Skills free?
Yes. The skills are Apache-2.0 and free to install. You still need an agent such as Claude Code, Codex, Gemini CLI or Cursor under its own pricing, and some skills start paid Hugging Face services, such as Jobs on cloud GPUs or Spaces hardware, which bill your Hugging Face account.
Which skill should I install first?
hf-cli. Hugging Face recommends it as the first skill: it teaches the agent every hf command and is generated from your installed CLI, so it stays current. Add training, dataset or Spaces skills afterwards with hf skills add.
Can my agent spend money with these skills?
Yes, if you let it. Training and evaluation skills can launch Hugging Face Jobs on paid GPUs, and the SageMaker skills create AWS resources. Approve those commands yourself and check the hardware and time limits before they run.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
