Aeon Huggingface TrendingSAFE
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Overview
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
4029e336cef5OBSERVED · 2026-10-09What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: aeon-huggingface-trending description: | Trending Hugging Face models, datasets, and spaces — filtered by license sanity, dedup vs same-week quantizations, with a "why notable" line per pick (architecture shift, size step, license change, notable author). Surfaces what's actually shifting rather than just popular. Triggers: "trending on HF", "what models are hot", "huggingface trending", "new spaces today", "best new datasets". --- # aeon-huggingface-trending Daily filtered scan over HF's three trending surfaces — models, datasets, spaces — cluster-ranked rather than raw-download ranked. ## Endpoints ```bash curl -s "https://huggingface.co/api/models?sort=trending&direction=-1&limit=30" curl -s "https://huggingface.co/api/datasets?sort=trending&direction=-1&limit=30" curl -s "https://huggingface.co/api/spaces?sort=trending&direction=-1&limit=30" ``` ## Filters - Empty repos, no commits, no model card → drop. - Same-week quantization of an already-trending model → demoted to "Quantizations" tail. - Fork without README delta vs upstream → drop. - Authors with > 5 trending entries in 24h → demoted (typically aggregators). - License unclear or missing → flagged inline, not dropped. ## "Why notable" line Per surfaced entry, a one-sentence tag: new architecture / size step / context-window jump / notable author affiliation / license change. If no concrete reason exists, the entry says "no clear why — popular but unremarkable" rather than inventing one. ## Output Three sections — Models, Datasets, Spaces — each with the surviving picks, "why notable", license, and download/view count. Tail section for quantizations. ## Rules - "Why notable" is a hard requirement. No reason → no surface. - License flags appear inline (Apache 2.0, MIT, OpenRAIL-M, custom-no-commercial). Operators trading on model output care. - Spaces section often beats Models for builder-tier signal — a working demo is stronger validation than a card claim.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4029e336cef5full audit observations/trust-audit/skill/bankrbot__aeon-huggingface-trending.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4029e336cef5 | SAFE | B | 89 | first audit |
Questions
What does the Aeon Huggingface Trending skill do?
Bankr Skills equip builders with plug-and-play tools to build more powerful agents.
Is Aeon Huggingface Trending safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Aeon Huggingface Trending access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.