Huggingface ApiSAFE
🔬 A curated collection of 23,000+ agent skills for empirical research across 8 social science disciplines. | 精选 23,000+ AI Agent 技能库,覆盖8大社会科学学科的实证研究。CoPaper.AI 20分钟完成一篇可复现的规范实证论文,并支持用户上传 Skills。-- Maintained by CoPaper.AI from Stanford REAP.
Overview
🔬 A curated collection of 23,000+ agent skills for empirical research across 8 social science disciplines. | 精选 23,000+ AI Agent 技能库,覆盖8大社会科学学科的实证研究。CoPaper.AI 20分钟完成一篇可复现的规范实证论文,并支持用户上传 Skills。-- Maintained by CoPaper.AI from Stanford REAP.
e1ba289846fdOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: huggingface-api
description: "Search and discover ML models, datasets, and Spaces on Hugging Face"
metadata:
openclaw:
emoji: "🤗"
category: "domains"
subcategory: "ai-ml"
keywords: ["Hugging Face", "ML models", "datasets", "model hub", "transformers", "NLP", "computer vision"]
source: "https://huggingface.co/docs/hub/api"
---
# Hugging Face Hub API
## Overview
The Hugging Face Hub is the largest open-source ML ecosystem, hosting over 1 million models, 200,000+ datasets, and 400,000+ Spaces (demo apps). The Hub API at `https://huggingface.co/api` provides programmatic access to search, discover, and retrieve metadata for all public resources without authentication.
For academic researchers, the Hub API enables systematic model selection for benchmarking, dataset discovery for experiments, tracking community adoption metrics (downloads, likes), and building reproducible ML pipelines that reference specific model revisions by SHA.
## Authentication
**Read endpoints require no authentication.** All search and metadata queries work without a token.
For write operations (uploading models, creating repos), set a User Access Token:
```bash
export HF_TOKEN="hf_..."
# Pass via header:
curl -H "Authorization: Bearer $HF_TOKEN" https://huggingface.co/api/...
```
Generate tokens at: https://huggingface.co/settings/tokens
## Core Endpoints
### Search Models
```
GET https://huggingface.co/api/models?search={query}&limit={n}&sort={field}&direction={-1|1}
```
**Parameters**: `search` (query string), `limit` (max results), `sort` (field: `downloads`, `likes`, `lastModified`, `trending`), `direction` (-1 descending, 1 ascending), `filter` (pipeline tag like `text-classification`), `author` (org/user filter), `library` (e.g. `transformers`, `pytorch`)
**Example** -- top 2 models for "bert" by downloads:
```bash
curl -s "https://huggingface.co/api/models?search=bert&limit=2&sort=downloads&direction=-1"
```
```json
[
{
"id": "google-bert/bert-base-uncased",
"likes": 2587,
"downloads": 71053483,
"pipeline_tag": "fill-mask",
"library_name": "transformers",
"tags": ["transformers","pytorch","tf","jax","bert","fill-mask","en",
"dataset:bookcorpus","dataset:wikipedia","arxiv:1810.04805",
"license:apache-2.0"]
},
{
"id": "google-bert/bert-base-multilingual-uncased",
"likes": 153,
"downloads": 5017183,
"pipeline_tag": "fill-mask",
"library_name": "transformers"
}
]
```
### Get Model Details
```
GET https://huggingface.co/api/models/{owner}/{model_name}
```
Returns full metadata including `config.architectures`, `cardData` (license, datasets, language), `siblings` (file listing), `sha` (exact revision), and `lastModified`.
```bash
curl -s "https://huggingface.co/api/models/google-bert/bert-base-uncased"
```
Key fields in response:
```json
{
"id": "google-bert/bert-base-uncased",
"sha": "86b5e0934494bd15c9632b12f734a8a67f723594",
"lastModified": "2024-02-19T11:06:12.000Z",
"downloads": 71053483,
"config": { "architectures": ["BertForMaskedLM"], "model_type": "bert" },
"cardData": { "language": "en", "license": "apache-2.0",
"datasets": ["bookcorpus","wikipedia"] }
}
```
### Search Datasets
```
GET https://huggingface.co/api/datasets?search={query}&limit={n}
```
**Parameters**: `search`, `limit`, `sort`, `direction`, `author`, `filter` (task tag like `question-answering`)
```bash
curl -s "https://huggingface.co/api/datasets?search=squad&limit=2"
```
```json
[
{
"id": "rajpurkar/squad_v2",
"likes": 242,
"downloads": 36017,
"description": "Stanford Question Answering Dataset (SQuAD)...",
"tags": ["task_categories:question-answering","language:en",
"license:cc-by-sa-4.0","size_categories:100K<n<1M",
"arxiv:1806.03822"]
}
]
```
### Get Dataset Details
```
GET https://huggingface.co/api/datasets/{owner}/{dataset_name}
```
```bash
curl -s "https://huggingface.co/api/datasets/rajpurkar/squad_v2"
```
Returns `cardData` with structured metadata (task categories, languages, license, size), `description`, `paperswithcode_id` for cross-referencing, and `tags` with arXiv paper IDs.
### Search Spaces
```
GET https://huggingface.co/api/spaces?search={query}&limit={n}
```
```bash
curl -s "https://huggingface.co/api/spaces?search=chatbot&limit=2"
```
```json
[
{
"id": "21Hg/chatbot",
"likes": 5,
"sdk": "docker",
"tags": ["docker","streamlit","region:us"]
},
{
"id": "lmarena-ai/chatbot-arena",
"likes": 234,
"sdk": "static"
}
]
```
## Advanced Filters
Combine filters via query params to narrow results:
```bash
# PyTorch text-generation models with 1000+ likes
curl -s "https://huggingface.co/api/models?filter=text-generation&library=pytorch&sort=likes&direction=-1&limit=5"
# Datasets for NER tasks in Chinese
curl -s "https://huggingface.co/api/datasets?filter=token-classification&language=zh&limit=10"
# Gradio Spaces sorted by trending
curl -s "https://huggingface.co/api/spaces?filter=gradio&sort=trending&direction=-1&limit=5"
```
## Rate Limits
- **Unauthenticated**: generous but undocumented; suitable for interactive use and small scripts
- **Authenticated**: higher limits with Bearer token
- **Best practice**: add `limit` parameter to avoid fetching thousands of results; cache responses locally for batch analysis
- No strict per-minute quota is published; if you receive HTTP 429, back off exponentially
## Academic Use Cases
1. **Model selection for benchmarks**: Search by pipeline tag (`text-classification`, `token-classification`, `summarization`) and sort by downloads to find community-validated baselines
2. **Dataset discovery**: Filter by `task_categories`, `language`, and `size_categories` tags to find training data matching your experimental requirements
3. **Reproducibility**: Pin model versions using the `sha` field from model details -- load exact revisions with `Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
e1ba289846fdfull audit observations/trust-audit/skill/brycewang-stanford__huggingface-api.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e1ba289846fd | SAFE | B | 89 | first audit |
Questions
What does the Huggingface Api skill do?
🔬 A curated collection of 23,000+ agent skills for empirical research across 8 social science disciplines. | 精选 23,000+ AI Agent 技能库,覆盖8大社会科学学科的实证研究。CoPaper.AI 20分钟完成一篇可复现的规范实证论文,并支持用户上传 Skills。-- Maintained by CoPaper.AI from Stanford REAP.
Is Huggingface Api safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Huggingface Api access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Huggingface Api work with?
Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (e1ba289846fd), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.