Skip to content

chore(deps): update huggingface/skills digest to c3accb7#649

Merged
samuv merged 2 commits into
mainfrom
renovate/huggingface-skills-digest
May 12, 2026
Merged

chore(deps): update huggingface/skills digest to c3accb7#649
samuv merged 2 commits into
mainfrom
renovate/huggingface-skills-digest

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 11, 2026

This PR contains the following updates:

Package Update Change
huggingface/skills digest 7c71cfbc3accb7

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/huggingface-skills-digest branch from 7d6da73 to 718e002 Compare May 11, 2026 09:59
@toolhive-release-app
Copy link
Copy Markdown
Contributor

toolhive-release-app Bot commented May 11, 2026

🛡️ Skill Security Scan Results

✅ hf-cli

  • Status: Passed
  • Findings: 4

✅ hf-mcp

  • Status: Passed
  • Findings: 6
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ huggingface-community-evals

  • Status: Passed
  • Findings: 5
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ huggingface-datasets

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ huggingface-gradio

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

❌ huggingface-llm-trainer

  • Status: Failed
  • Findings: 329
  • Blocking: 209

Blocking issues:

  • [ATR_2026_00040] (CRITICAL) Pattern detected: Deploy (SKILL.md:598)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: references/gguf_conversion.md for complete conversion guide, inc (SKILL.md:601)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (SKILL.md:604)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (SKILL.md:609)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: references/training_patterns.md for detailed examples inc (SKILL.md:620)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: per_device_train_batch_size=1, increase gradient_accumulation_steps=8. Effective batch size is per_device_train_batch_size x gradient_accumulation_steps. For best performanc (SKILL.md:632)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (SKILL.md:640)
  • [ATR_2026_00012] (HIGH) Pattern detected: `hf_jobs("logs", {"job_id (SKILL.md:650)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (SKILL.md:660)
  • [ATR_2026_00012] (HIGH) Pattern detected: push_to_hub=True, `hub_model_id (SKILL.md:661)
  • [ATR_2026_00062] (CRITICAL) Pattern detected: huggingface (SKILL.md:662)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (SKILL.md:669)
  • [ATR_2026_00062] (CRITICAL) Pattern detected: huggingface (SKILL.md:683)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:685)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:690)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:691)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:692)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:693)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:694)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:695)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:696)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:697)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (SKILL.md:698)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: scripts/hf_benchmarks.py - Search for benc (SKILL.md:707)
  • [ATR_2026_00012] (HIGH) Pattern detected: ; without push (SKILL.md:726)
  • [ATR_2026_00040] (CRITICAL) Pattern detected: bash (SKILL.md:729)
  • [ATR_2026_00040] (CRITICAL) Pattern detected: Deploy (references/gguf_conversion.md:21)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/gguf_conversion.md:30)
  • [ATR_2026_00095] (CRITICAL) Pattern detected: subprocess.run (references/gguf_conversion.md:31)
  • [ATR_2026_00095] (CRITICAL) Pattern detected: subprocess.run (references/gguf_conversion.md:32)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/gguf_conversion.md:39)
  • [ATR_2026_00095] (CRITICAL) Pattern detected: subprocess.run (references/gguf_conversion.md:44)
  • [ATR_2026_00095] (CRITICAL) Pattern detected: subprocess.run (references/gguf_conversion.md:50)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/gguf_conversion.md:63)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `sentenc (references/gguf_conversion.md:79)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/gguf_conversion.md:83)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/gguf_conversion.md:105)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/gguf_conversion.md:115)
  • [ATR_2026_00063] (CRITICAL) Pattern detected: Upload (references/gguf_conversion.md:135)
  • [ATR_2026_00012] (HIGH) Pattern detected: | Good | Recommended - best balanc (references/gguf_conversion.md:143)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/gguf_conversion.md:167)
  • [ATR_2026_00030] (CRITICAL) Pattern detected: run (uses GPU automatically if available) (references/gguf_conversion.md:174)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/gguf_conversion.md:180)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `"sentenc (references/gguf_conversion.md:235)
  • [ATR_2026_00063] (CRITICAL) Pattern detected: Upload (references/gguf_conversion.md:238)
  • [ATR_2026_00063] (CRITICAL) Pattern detected: Upload (references/gguf_conversion.md:241)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/gguf_conversion.md:250)
  • [ATR_2026_00063] (CRITICAL) Pattern detected: upload (references/gguf_conversion.md:294)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: scripts/convert_to_gguf.py inc (references/gguf_conversion.md:296)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: cpu-upgrade - Enhanc (references/hardware_guide.md:9)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hardware_guide.md:152)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hardware_guide.md:157)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hardware_guide.md:162)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hardware_guide.md:167)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hardware_guide.md:172)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hardware_guide.md:233)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hardware_guide.md:238)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hardware_guide.md:274)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:21)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:32)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hub_saving.md:35)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hub_saving.md:39)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:43)
  • [ATR_2026_00076] (HIGH) Pattern detected: token=None (references/hub_saving.md:66)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:85)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hub_saving.md:90)
  • [ATR_2026_00012] (HIGH) Pattern detected: `push (references/hub_saving.md:96)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:109)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:133)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hub_saving.md:134)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:141)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:149)
  • [ATR_2026_00012] (HIGH) Pattern detected: `push (references/hub_saving.md:161)
  • [ATR_2026_00012] (HIGH) Pattern detected: `hub_model_id (references/hub_saving.md:162)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hub_saving.md:163)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:177)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hub_saving.md:207)
  • [ATR_2026_00012] (HIGH) Pattern detected: `hf auth whoami (references/hub_saving.md:208)
  • [ATR_2026_00012] (HIGH) Pattern detected: `hub_model_id (references/hub_saving.md:242)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:249)
  • [ATR_2026_00012] (HIGH) Pattern detected: `push (references/hub_saving.md:265)
  • [ATR_2026_00012] (HIGH) Pattern detected: save_total_limit** to avoid (references/hub_saving.md:268)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:277)
  • [ATR_2026_00063] (CRITICAL) Pattern detected: Upload (references/hub_saving.md:284)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:290)
  • [ATR_2026_00115] (CRITICAL) Pattern detected: os.environ (references/hub_saving.md:302)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/hub_saving.md:351)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/hub_saving.md:356)
  • [ATR_2026_00012] (HIGH) Pattern detected: `push (references/hub_saving.md:362)
  • [ATR_2026_00012] (HIGH) Pattern detected: | 64 GB | ~3B (sh (references/local_training_macos.md:33)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/local_training_macos.md:37)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/local_training_macos.md:45)
  • [ATR_2026_00062] (CRITICAL) Pattern detected: version (references/local_training_macos.md:46)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/local_training_macos.md:50)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/local_training_macos.md:59)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:73)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:74)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:75)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:76)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:77)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:78)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:79)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:80)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:81)
  • [ATR_2026_00091] (CRITICAL) Pattern detected: \n (references/local_training_macos.md:112)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/local_training_macos.md:145)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/local_training_macos.md:151)
  • [ATR_2026_00004] (CRITICAL) Pattern detected: {"role": " (references/local_training_macos.md:161)
  • [ATR_2026_00091] (CRITICAL) Pattern detected: \n (references/local_training_macos.md:164)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `DATA_FILES="file.jsonl" TEXT_FIELD="text" MESSAGES_FIELD="" python (references/local_training_macos.md:166)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/local_training_macos.md:178)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:183)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:184)
  • [ATR_2026_00012] (HIGH) Pattern detected: os.environ (references/local_training_macos.md:192)
  • [ATR_2026_00012] (HIGH) Pattern detected: | MPS unsupported op / crash (references/local_training_macos.md:207)
  • [ATR_2026_00012] (HIGH) Pattern detected: | OOM / system (references/local_training_macos.md:208)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:14)
  • [ATR_2026_00012] (HIGH) Pattern detected: `space_id (references/trackio_guide.md:26)
  • [ATR_2026_00012] (HIGH) Pattern detected: `hf repos create my-trackio-dash (references/trackio_guide.md:31)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:34)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:49)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:57)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:85)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:112)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:121)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:135)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/trackio_guide.md:139)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/trackio_guide.md:146)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/trackio_guide.md:165)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_methods.md:17)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_methods.md:50)
  • [ATR_2026_00040] (CRITICAL) Pattern detected: exec (references/training_methods.md:75)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_methods.md:82)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/training_methods.md:93)
  • [ATR_2026_00012] (HIGH) Pattern detected: | Medium | Paired preferenc (references/training_methods.md:117)
  • [ATR_2026_00012] (HIGH) Pattern detected: | Medium | Paired preferenc (references/training_methods.md:119)
  • [ATR_2026_00040] (CRITICAL) Pattern detected: Deploy (references/training_methods.md:126)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_methods.md:135)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/training_methods.md:140)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/training_methods.md:147)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:9)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/training_patterns.md:17)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:31)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/training_patterns.md:73)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:83)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/training_patterns.md:95)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: references/trackio_guide.md for complete documentation inc (references/training_patterns.md:103)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:107)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:131)
  • [ATR_2026_00012] (HIGH) Pattern detected: | Preferenc (references/training_patterns.md:143)
  • [ATR_2026_00111] (CRITICAL) Pattern detected: eval_strategy="steps" (references/training_patterns.md:148)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:151)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:163)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/training_patterns.md:173)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: scripts/train_sft_example.py - Complete SFT template with Trackio and eval (references/training_patterns.md:198)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/training_patterns.md:201)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/training_patterns.md:202)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/training_patterns.md:203)
  • [ATR_2026_00111] (CRITICAL) Pattern detected: eval_strategy="steps" (references/troubleshooting.md:9)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:14)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:31)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: scripts/train_sft_example.py includes proper eval (references/troubleshooting.md:46)
  • [ATR_2026_00012] (HIGH) Pattern detected: `push (references/troubleshooting.md:68)
  • [ATR_2026_00012] (HIGH) Pattern detected: `hub_model_id (references/troubleshooting.md:69)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/troubleshooting.md:70)
  • [ATR_2026_00012] (HIGH) Pattern detected: `trainer.push (references/troubleshooting.md:73)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/troubleshooting.md:75)
  • [ATR_2026_00111] (CRITICAL) Pattern detected: eval_dataset (references/troubleshooting.md:84)
  • [ATR_2026_00062] (CRITICAL) Pattern detected: init (references/troubleshooting.md:97)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:102)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:119)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/troubleshooting.md:124)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:129)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:151)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/troubleshooting.md:167)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:177)
  • [ATR_2026_00062] (CRITICAL) Pattern detected: huggingface (references/troubleshooting.md:178)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:187)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/troubleshooting.md:188)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:229)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/troubleshooting.md:232)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:234)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:244)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:255)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:267)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/troubleshooting.md:272)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/troubleshooting.md:277)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/troubleshooting.md:278)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: `referenc (references/troubleshooting.md:279)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:26)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:35)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:48)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:97)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:105)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:115)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: messages: Conversation format with image referenc (references/unsloth.md:187)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:189)
  • [ATR_2026_00004] (CRITICAL) Pattern detected: {"role": " (references/unsloth.md:193)
  • [ATR_2026_00004] (CRITICAL) Pattern detected: {"role": " (references/unsloth.md:197)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:206)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:221)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:232)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:245)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:258)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:265)
  • [ATR_2026_00010] (CRITICAL) Pattern detected: scripts/unsloth_sft_example.py for a complete production-ready example that inc (references/unsloth.md:282)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `bash (references/unsloth.md:290)
  • [ATR_2026_00066] (CRITICAL) Pattern detected: `python (references/unsloth.md:298)
  • [ATR_2026_00012] (HIGH) Pattern detected: $HF_TOKEN (references/unsloth.md:303)

Allowlisted (not blocking):

  • TOOL_ABUSE_SYSTEM_PACKAGE_INSTALL (Allowed: The bundled scripts/convert_to_gguf.py references sudo apt-get install / sudo yum install for optional system packages (build tools) when converting trained models to GGUF format. These run in ephemeral HF Jobs containers, not on the user's host. The script is HF-authored and documented in SKILL.md.)
  • TOOL_ABUSE_SYSTEM_PACKAGE_INSTALL (Allowed: The bundled scripts/convert_to_gguf.py references sudo apt-get install / sudo yum install for optional system packages (build tools) when converting trained models to GGUF format. These run in ephemeral HF Jobs containers, not on the user's host. The script is HF-authored and documented in SKILL.md.)
  • TOOL_ABUSE_SYSTEM_PACKAGE_INSTALL (Allowed: The bundled scripts/convert_to_gguf.py references sudo apt-get install / sudo yum install for optional system packages (build tools) when converting trained models to GGUF format. These run in ephemeral HF Jobs containers, not on the user's host. The script is HF-authored and documented in SKILL.md.)
  • TOOL_ABUSE_SYSTEM_PACKAGE_INSTALL (Allowed: The bundled scripts/convert_to_gguf.py references sudo apt-get install / sudo yum install for optional system packages (build tools) when converting trained models to GGUF format. These run in ephemeral HF Jobs containers, not on the user's host. The script is HF-authored and documented in SKILL.md.)
  • TOOL_ABUSE_SYSTEM_PACKAGE_INSTALL (Allowed: The bundled scripts/convert_to_gguf.py references sudo apt-get install / sudo yum install for optional system packages (build tools) when converting trained models to GGUF format. These run in ephemeral HF Jobs containers, not on the user's host. The script is HF-authored and documented in SKILL.md.)
  • TOOL_ABUSE_SYSTEM_PACKAGE_INSTALL (Allowed: The bundled scripts/convert_to_gguf.py references sudo apt-get install / sudo yum install for optional system packages (build tools) when converting trained models to GGUF format. These run in ephemeral HF Jobs containers, not on the user's host. The script is HF-authored and documented in SKILL.md.)
  • DATA_EXFIL_NETWORK_REQUESTS (Allowed: Bundled helper scripts (scripts/dataset_inspector.py, scripts/hf_benchmarks.py) use urllib.request to query the public Hugging Face Hub API for dataset validation and benchmark lookups — documented workflow steps required by the skill.)
  • DATA_EXFIL_NETWORK_REQUESTS (Allowed: Bundled helper scripts (scripts/dataset_inspector.py, scripts/hf_benchmarks.py) use urllib.request to query the public Hugging Face Hub API for dataset validation and benchmark lookups — documented workflow steps required by the skill.)
  • DATA_EXFIL_NETWORK_REQUESTS (Allowed: Bundled helper scripts (scripts/dataset_inspector.py, scripts/hf_benchmarks.py) use urllib.request to query the public Hugging Face Hub API for dataset validation and benchmark lookups — documented workflow steps required by the skill.)

❌ huggingface-paper-publisher

  • Status: Failed
  • Findings: 10
  • Blocking: 2

Blocking issues:

  • [ATR_2026_00111] (CRITICAL) Pattern detected: $(cat citation.txt) (SKILL.md:118)
  • [ATR_2026_00111] (CRITICAL) Pattern detected: $(cat abstract.txt) (SKILL.md:196)

Allowlisted (not blocking):

  • TOOL_ABUSE_UNDECLARED_NETWORK (Allowed: The skill uses network access through its bundled paper_manager.py script (as its documented workflow), but does not declare an explicit network-access tool in frontmatter. All network calls target the public Hugging Face Hub API documented in the SKILL.md.)
  • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)
  • FILE_MAGIC_MISMATCH (Allowed: templates/modern.md is a paper template that legitimately uses Handlebars-style {{}} substitution syntax. Magika detects the Handlebars markers and flags the format mismatch; the file is plain text documentation and safe.)

✅ huggingface-papers

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ huggingface-tool-builder

  • Status: Passed
  • Findings: 6
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ huggingface-trackio

  • Status: Passed
  • Findings: 5
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: huggingface/skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ huggingface-vision-trainer

  • Status: Passed
  • Findings: 7
  • Allowed (not blocking): 1
    • DATA_EXFIL_NETWORK_REQUESTS (Allowed: The bundled scripts/dataset_inspector.py uses urllib.request.urlopen() to query the public Hugging Face Hub API for dataset format validation — a documented workflow step required before launching GPU training.)

✅ transformers-js

  • Status: Passed
  • Findings: 0

Summary: Scanned 12 skill(s), found 211 blocking issue(s).

⚠️ Action Required: Review the blocking findings. Add a justified entry to the skill's security.allowed_issues[] in its spec.yaml if the finding is a false positive.

@renovate renovate Bot force-pushed the renovate/huggingface-skills-digest branch from a5d5483 to 4482229 Compare May 11, 2026 10:05
…ity-evals,huggingface-datasets,huggingface-gradio,huggingface-llm-trainer,huggingface-paper-publisher,huggingface-papers,huggingface-tool-builder,huggingface-trackio,huggingface-vision-trainer,transformers-js
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented May 11, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@samuv samuv merged commit ebb1575 into main May 12, 2026
39 of 43 checks passed
@samuv samuv deleted the renovate/huggingface-skills-digest branch May 12, 2026 09:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant