Automic VaultAutomic Vault

brew / 受保护工具覆盖 / 排名 868

安装 hf

查看 hf 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

agent safety

Agent safety answer

hf controls Hugging Face model, dataset, and Space workflows.

Credential access

Reads Hugging Face tokens, cache files, repository credentials, and environment variables.

Remote mutation

Can upload, delete, and change models, datasets, and Spaces.

Publish/artifact risk

Publishes ML artifacts, datasets, and app spaces.

Recommended control

Gate upload, delete, login, repo, and token commands.

Agent-use guidance

Allow public model inspection; require approval for uploads, deletes, private repo access, and token use.

安装

使用 Automic Vault 安装

Automic Vault
下载 AV
sudo av install brew:hf

macOS

Homebrewverified · 100%
brew install hf

local Homebrew formula metadata

平台说明

  • 没有特定于此软件包的平台说明。

概览

软件包摘要

Client library for huggingface.co hub

命令和别名

  • hf
  • huggingface-cli
  • tiny-agents

受保护工具覆盖

Plain Text Hugging Face Token

Hugging Face Hub stores the active CLI token in ~/.cache/huggingface/token. Our isotope stores that token in the macOS keychain and injects it as HF_TOKEN only while `hf` runs.

Risk classifier

green risk · low confidence · appliance

Why

  • no executable entrypoint in the package index

Signals

  • metadata:no-indexed-executables

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Installs with 4 runtime dependencies.
  • Build metadata lists 2 build dependencies.

本地 README 摘录

huggingface-cli Protected-tool coverage

Hugging Face Hub stores the active CLI token in ~/.cache/huggingface/token.

This protected-tool coverage migrates that active token into the Automic Vault keychain and wraps hf so HF_TOKEN is present only while the CLI runs.

Caveats

  • We currently migrate the active token file only.
  • Named stored_tokens entries are not migrated.
  • Direct execution of the original binary will not receive the credentials.

来源: local coverage notes

覆盖来源

来源摘录

Caveats

  • We currently migrate the active token file only.
  • Named stored_tokens entries are not migrated.
  • Direct execution of the original binary will not receive credentials.

可执行文件

已安装的可执行文件

命令类型暴露范围备注
hfcliglobal executable
huggingface-clicliglobal executable
tiny-agentscliglobal executable

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-06-10
管理器版本1.18.0
管理器更新时间2026-06-06
本地数据ok
上游not checked
检测到的最新版本not detected

https://huggingface.co/docs/huggingface_hub/guides/cli

安装元数据

软件包元数据

Package keybrew:hf
Version1.18.0
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/hf
Homepagehttps://huggingface.co/docs/huggingface_hub/guides/cli
Repositoryhttps://github.com/huggingface/huggingface_hub
Upstream docshttps://huggingface.co/docs/huggingface_hub/guides/cli
LicenseApache-2.0
Source archivehttps://files.pythonhosted.org/packages/fb/d8/748ea0a47f0fa15227fe682f7a80826b4b7c096e4818044b8f56d6cb66d6/huggingface_hub-1.18.0.tar.gz
Last updated2026-06-06T12:13:07Z
Pulseupdated
Dependenciescertifi, git-lfs, libyaml, python@3.14
Build dependenciespkgconf, rust
Bottleavailable (arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namehf
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated agent safety answer
  • local coverage README
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • secret-handling manifest