3 min read

Hugging Face Skills: Train, Evaluate and Ship Models With Your Agent (GitHub, Scanned)

Hugging Face's official agent skills for the Hub, datasets, model training, Spaces and Jobs.

Hugging Face Skills logo
✅
Scan: safe. Nothing to warn about. It is instructions and helper scripts that talk to Hugging Face's own services, and the only installer is Hugging Face's own. Scanned Oct 8, 2026; the full report is below.

Hugging Face Skills teaches coding agents to work with the Hugging Face ecosystem. The starting point is hf-cli, which gives the agent every command of the hf tool: searching models, downloading and uploading, managing datasets and buckets, launching Spaces and running Jobs. On top of that sit about two dozen workflow skills for fine-tuning language and vision models with TRL or Unsloth on Hugging Face's cloud GPUs, training sentence-transformers, running evaluations, browsing datasets, building Gradio demos and ZeroGPU Spaces, reading and publishing papers, choosing GGUF models to run locally, and deploying to Amazon SageMaker.

It is maintained by Hugging Face and follows the open Agent Skills format, so the same folders work in Claude Code, Codex, Gemini CLI and Cursor, with a generated AGENTS.md as a fallback for agents without skill support. The marketplace entry is deliberately limited to hf-cli, and further skills are added with hf skills add when you need them.

The repository is Apache-2.0, with about 11,000 stars and 43 contributors. It is small, about 200 files, so it is easy to read every skill you plan to install.

  • Repository: github.com/huggingface/skills
  • Licence: Apache-2.0 (Apache License 2.0)
  • Language: Python. Stars: 11.2K. Forks: 762. Last push: Oct 1, 2026.
  • Scan: safe, Oct 8, 2026, commit ca0325b

Who it is for

ML engineers and researchers who already use the Hugging Face Hub and want their agent to handle the routine parts: finding models, preparing datasets, launching fine-tuning jobs and publishing demos.

Getting started

1. In Claude Code, add the repository as a plugin marketplace

/plugin marketplace add huggingface/skills

2. Install the hf-cli skill

/plugin install hf-cli@huggingface/skills

3. Add any other skill with the hf CLI

hf skills add <skill-name>

4. Gemini CLI

gemini extensions install https://github.com/huggingface/skills.git --consent

The /plugin commands are typed inside Claude Code, not a shell. hf skills add needs the hf CLI installed. Codex users copy skill folders into .agents/skills, and Cursor installs from the repository URL through its plugin flow.

Safety scan

We cloned huggingface/skills at commit ca0325b on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious code patterns, no committed binaries and no bare-IP URLs across 203 files and about 42,000 lines.
  • A second, skill-specific pass looked for invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths, pipe-to-shell commands, long base64 and plugin hooks, and found nothing of concern.
  • The hosts in the code are huggingface.co, its datasets server, arXiv and GitHub. The hf-cli skill installs the hf CLI with Hugging Face's own first-party installer (curl from hf.co piped to bash), and many skills use your HF token for Hub actions, so jobs and uploads run under your account.
  • No lockfiles, so no dependency advisories. 7 workflows with no pull_request_target; both third-party actions are pinned to commits and Dependabot is on. Licence present; no security policy or contributing guide in the repository.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflows7 workflows. None use pull_request_target. 0 of 2 third-party actions pinned to a tag rather than a commit.
Network hosts7 distinct hosts referenced from source; most often huggingface.co, github.com, datasets-server.huggingface.co, arxiv.org. No URLs to bare IP addresses.
Known vulnerabilitiesNo lockfile to check: dependencies are declared as ranges, so what gets installed is whatever is current on the day.
Project hygieneHas automated dependency updates, licence file. Missing security policy, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

By the numbers

Stars11.2K
Forks762
Contributors43
Commits349
Open issues11
Open pull requests51
Releases0
Latest releasenone tagged
LicenceApache-2.0
Main languagePython
Project age10 months
Last pushOct 1, 2026
Tracked files203
Lines of code42K
Checkout size2 MB

Lines by language: Markdown 24.5K, Python 15.6K, Shell 843, YAML 573, JSON 360, TypeScript 58.

Questions

Is Hugging Face Skills free?

Yes. The skills are Apache-2.0 and free to install. You still need an agent such as Claude Code, Codex, Gemini CLI or Cursor under its own pricing, and some skills start paid Hugging Face services, such as Jobs on cloud GPUs or Spaces hardware, which bill your Hugging Face account.

Which skill should I install first?

hf-cli. Hugging Face recommends it as the first skill: it teaches the agent every hf command and is generated from your installed CLI, so it stays current. Add training, dataset or Spaces skills afterwards with hf skills add.

Can my agent spend money with these skills?

Yes, if you let it. Training and evaluation skills can launch Hugging Face Jobs on paid GPUs, and the SageMaker skills create AWS resources. Approve those commands yourself and check the hardware and time limits before they run.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.