# Install hf

Client library for huggingface.co hub. Version 1.18.0 via Homebrew; verified 2026-06-06.

## Install

```sh
sudo av install brew:hf
```

## Agent safety answer

hf controls Hugging Face model, dataset, and Space workflows.

- **Credential access:** Reads Hugging Face tokens, cache files, repository credentials, and environment variables.
- **Remote mutation:** Can upload, delete, and change models, datasets, and Spaces.
- **Publish/artifact risk:** Publishes ML artifacts, datasets, and app spaces.
- **Recommended control:** Gate upload, delete, login, repo, and token commands.
- **Agent-use guidance:** Allow public model inspection; require approval for uploads, deletes, private repo access, and token use.

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install hf
```

  Evidence: local Homebrew formula metadata

## Package Facts

- **Package key:** brew:hf
- **Package manager:** Homebrew
- **Package manager URL:** <https://formulae.brew.sh/formula/hf>
- **Version:** 1.18.0
- **Source summary:** Client library for huggingface.co hub
- **Homepage:** <https://huggingface.co/docs/huggingface_hub/guides/cli>
- **Repository:** <https://github.com/huggingface/huggingface_hub>
- **Upstream docs:** <https://huggingface.co/docs/huggingface_hub/guides/cli>
- **License:** Apache-2.0
- **Source archive:** <https://files.pythonhosted.org/packages/fb/d8/748ea0a47f0fa15227fe682f7a80826b4b7c096e4818044b8f56d6cb66d6/huggingface_hub-1.18.0.tar.gz>
- **Last updated:** 2026-06-06T12:13:07Z
- **Generated:** 2026-06-10T07:18:26+00:00

## Executables

- hf (cli)
- huggingface-cli (cli)
- tiny-agents (cli)
- hf (alias)
- huggingface-cli (alias)
- tiny-agents (alias)

## Dependencies

- certifi
- git-lfs
- libyaml
- python@3.14

## Build Dependencies

- pkgconf
- rust

## Install Behavior

- Post-install hook: not defined
- Bottle: available on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux

## Freshness

- Page generated: 2026-06-10
- Package-manager version: 1.18.0
- Package-manager updated: 2026-06-06
- Local data status: ok
- Upstream repository: https://huggingface.co/docs/huggingface_hub/guides/cli
- info: Release/tag comparison is only available for GitHub repositories.

## 安全说明

no executable entrypoint in the package index.

- **Protected-tool coverage:** Plain Text Hugging Face Token
- **Geiger risk:** green / low
- no executable entrypoint in the package index

## Source Database Details

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** hf
- **Version Scheme:** 0
- **Revision:** 0
- **Head Version:** HEAD
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** head, stable


## Related Links

- [Secret-risk packages](https://www.automicvault.com/zh-hans/pkg/secret-risk-packages/) - Has protected-tool coverage, approval-gate, or non-low Geiger security signals.
- [Terminal utility packages](https://www.automicvault.com/zh-hans/pkg/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Text processing packages](https://www.automicvault.com/zh-hans/pkg/text-processing-tools/) - Matched text, document, or structured-data processing metadata.
- [Developer build packages](https://www.automicvault.com/zh-hans/pkg/developer-build-tools/) - Matched build, compiler, generator, or developer workflow metadata.
- [python@3.14](https://www.automicvault.com/zh-hans/pkg/brew/python-3-14/) - Runtime dependency declared by Homebrew.
- [git-lfs](https://www.automicvault.com/zh-hans/pkg/brew/git-lfs/) - Runtime dependency declared by Homebrew.
- [pkgconf](https://www.automicvault.com/zh-hans/pkg/brew/pkgconf/) - Build dependency declared by Homebrew.
- [rust](https://www.automicvault.com/zh-hans/pkg/brew/rust/) - Build dependency declared by Homebrew.
- [hf-mcp-server](https://www.automicvault.com/zh-hans/pkg/brew/hf-mcp-server/) - Shares av.db curated category or tags: cli, developer-tools, hugging-face, machine-learning.
- [text-embeddings-inference](https://www.automicvault.com/zh-hans/pkg/brew/text-embeddings-inference/) - Shares av.db curated category or tags: cli, developer-tools, hugging-face, machine-learning.
- [llama.cpp](https://www.automicvault.com/zh-hans/pkg/brew/llama-cpp/) - Shares av.db curated category or tags: cli, developer-tools, machine-learning.
- [pytorch](https://www.automicvault.com/zh-hans/pkg/brew/pytorch/) - Shares av.db curated category or tags: cli, developer-tools, machine-learning.
- [mlx](https://www.automicvault.com/zh-hans/pkg/brew/mlx/) - Shares av.db curated category or tags: cli, developer-tools, machine-learning.
- [dvc](https://www.automicvault.com/zh-hans/pkg/brew/dvc/) - Shares av.db curated category or tags: cli, developer-tools, machine-learning.
- [mlx-lm](https://www.automicvault.com/zh-hans/pkg/brew/mlx-lm/) - Shares av.db curated category or tags: cli, developer-tools, machine-learning.
- [crf++](https://www.automicvault.com/zh-hans/pkg/brew/crf/) - Shares av.db curated category or tags: cli, developer-tools, machine-learning.

## Sources

- Nucleus package database
- Geiger risk classifier
- secret-handling manifest
- local coverage README
- package-page enrichment
- package version freshness
- av.db category and tag curation
- package relationship graph
- cross-ecosystem install command graph
- curated agent safety answer
