Hugging FaceBLOCK
Hugging Face MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Welcome to the official Hugging Face MCP Server 🤗. Connect your LLM to the Hugging Face Hub and thousands of Gradio AI Applications.
Installing the MCP Server
Follow the instructions below to get started:
Install in Claude Desktop or claude.ai
Click here to add the Hugging Face connector to your account.
Alternatively, navigate to https://claude.ai/settings/connectors, and add "Hugging Face" from the gallery.
Install in Claude Code
Enter the command below to install in Claude Code:
claude mcp add hf-mcp-server -t http https://huggingface.co/mcp?login
Then start claude and follow the instructions to complete authentication.
claude mcp add hf-mcp-server \ -t http https://huggingface.co/mcp \ -H "Authorization: Bearer "
Install in Gemini CLI
Enter the command below to install in Gemini CLI:
gemini mcp add -t http huggingface https://huggingface.co/mcp?login
Then start gemini and follow the instructions to complete authentication.
Install in VSCode
Click here to add the Hugging Face connector directly to VSCode. Alternatively, install from the gallery at https://code.visualstudio.com/mcp:
28fb65863538OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add hf-mcp --env DEFAULT_HF_TOKEN=${DEFAULT_HF_TOKEN} --env HF_TEST_TOKEN=${HF_TEST_TOKEN} --env HF_TOKEN=${HF_TOKEN} --env LOGGING_HF_TOKEN=${LOGGING_HF_TOKEN} -- npx -y @llmindset/[email protected]{
"mcpServers": {
"hf-mcp": {
"command": "npx",
"args": [
"-y",
"@llmindset/[email protected]"
],
"env": {
"DEFAULT_HF_TOKEN": "${DEFAULT_HF_TOKEN}",
"HF_TEST_TOKEN": "${HF_TEST_TOKEN}",
"HF_TOKEN": "${HF_TOKEN}",
"LOGGING_HF_TOKEN": "${LOGGING_HF_TOKEN}"
}
}
}
}Exposed tools (21)
19 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
BadName | read | bad |
OmniParser_v2_process | read | |
a | read | |
alpha | read | first skill |
app_tool | read | Tool with an app |
child | read | child |
create_repo | write | |
dynamic_space | read | Find (semantic/task search), inspect (view parameter schema) and dynamically invoke Hugging Face Spaces. |
extra | read | |
first | read | First app tool |
hf_jobs | write | Remote compute for Hugging Face workflows. Run Python/UV or Docker jobs to deeply analyze Hub datasets, repos, traces, models, and large files; compute trends/statistics; run batch inference/evaluation; or perform long-running work with installed libraries. |
hf_whoami | read | |
hub_repo_details | read | Get details for one or more Hugging Face repos (model, dataset, or space). |
hub_repo_search | read | Search Hugging Face repositories with a shared query interface. |
private-skill | read | PRIVATE_DESCRIPTION |
progress_test | read | |
refunds | read | Process refunds |
second | read | Second app tool |
test_tool | read | Test tool |
tool1 | read | Tool 1 |
tool2 | read | Tool 2 |
Trust audit
BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(conn: SandboxConnection, args: SandboxExecRequest, options?: SandboxExecOptions): Promise<SandboxExecResult>;
console.log(` client secret returned: ${clientInfo.client_secret ? 'yes (redacted)' : 'no'}`);secret = 'SYNTHETIC_PRIVATE_DO_NOT_OUTPUT'
const token = 'hf_oauth_header.payload.signature';
const token = 'credential-must-not-appear';
"-----BEGIN RSA PRIVATE KEY-----",
.env.test.example
.hintrc
.prettierignore
import { BOUQUETS } from '../../shared/bouquet-presets.js';import type { DefinitionDigestsStatus, DefinitionDigestsStats } from '../../shared/definition-digests-status.js';import type { DefinitionDigestsStats } from '../../shared/definition-digests-status.js';const { version } = require('../../package.json') as { version: string };import type { SkillCatalogStatus } from '../../shared/skill-catalog-status.js';'169.254.169.254',
pnpm oauth:diagnose -- --server 'http://127.0.0.1:3000/mcp?login'
1. Starts the OAuth callback at `http://127.0.0.1:8090/oauth/callback`.
5. Includes `http://127.0.0.1:8090/oauth/callback` in the document's `redirect_uris`.
--redirect-uri 'http://127.0.0.1:8090/oauth/callback'
with urlopen(f'http://127.0.0.1:{server.server_port}/healthz') as response:@types/node, concurrently, knip, prettier, typescript
@huggingface/hub, @radix-ui/react-checkbox, @radix-ui/react-dropdown-menu, @radix-ui/react-separator, @radix-ui/react-slot, @radix-ui/react-tabs, @tailwindcss/vite, @tanstack/react-table
@huggingface/hub, mime-types, picomatch, shell-quote, @eslint/js, @types/node, eslint, rimraf
curl -X POST 'https://host/api/definition-digests/salt?value=v2' -H 'X-Metrics-Password: ...'
The optional `MONITOR_HF_TOKEN` is passed only to the Doctor as its read-only `HF_TOKEN`; the parent credential is
Gates applied: no_behavioural_pass.
28fb65863538full audit observations/trust-audit/mcp-server/evalstate__hugging-face-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 28fb65863538 | BLOCK | D | 64 | first audit |
Questions
What is the Hugging Face MCP server?
Hugging Face MCP Server
What tools does Hugging Face expose?
21 in total: 19 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Hugging Face safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (64/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Hugging Face need?
It reads DEFAULT_HF_TOKEN, HF_TEST_TOKEN, HF_TOKEN, LOGGING_HF_TOKEN, MCP_STRICT_TOKEN, METRICS_PAGE_PASSWORD, MONITOR_HF_TOKEN, OPENAI_API_KEY, PROXY_TOKEN and RESPONSES_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Hugging Face run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @llmindset/hf-mcp at 0.4.28.
How current is this page?
The grade is for one exact copy of the source (28fb65863538), read on 2026-10-07. The repository is watched and re-audited when it changes.