Skip to content
Back to skills

Huggingface Hub

DSecurity

Hugging Face Hub CLI (hf) — search, download, and upload models and

  • 125 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added June 6, 2026
ai-agentspythongobashsqlgit

Works with

  • cli

Security analysis

D42/100
  • criticalPipes output to a shell interpreter
  • mediumUses curl or wget to download content
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro shows the line behind each finding and how to fix it

Scanned June 6, 2026

npx -y skills add ArgentAIOS/argentos-core --skill huggingface-hub --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Huggingface Hub?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Huggingface Hub
[![Security: D — Skills Directory](https://www.skillsdirectory.com/api/skills/argentaios-huggingface-hub/badge)](https://www.skillsdirectory.com/skills/argentaios-huggingface-hub)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: community-huggingface-hub
description: Hugging Face Hub CLI (hf) — search, download, and upload models and
  datasets, manage repos, query datasets with SQL, deploy inference endpoints,
  manage Spaces and buckets.
version: 1.0.0
author: Hugging Face
license: MIT
tags:
  - huggingface
  - hf
  - models
  - datasets
  - hub
  - mlops
metadata:
  upstream_import:
    original_name: huggingface-hub
    source: community catalog active profile ~/.argent/skills
---

# Hugging Face CLI (`hf`) Reference Guide

The `hf` command is the modern command-line interface for interacting with the Hugging Face Hub, providing tools to manage repositories, models, datasets, and Spaces.

> **IMPORTANT:** The `hf` command replaces the now deprecated `huggingface-cli` command.

## Quick Start

- **Installation:** `curl -LsSf https://hf.co/cli/install.sh | bash -s`
- **Help:** Use `hf --help` to view all available functions and real-world examples.
- **Authentication:** Recommended via `HF_TOKEN` environment variable or the `--token` flag.

---

## Core Commands

### General Operations

- `hf download REPO_ID`: Download files from the Hub.
- `hf upload REPO_ID`: Upload files/folders (recommended for single-commit).
- `hf upload-large-folder REPO_ID LOCAL_PATH`: Recommended for resumable uploads of large directories.
- `hf sync`: Sync files between a local directory and a bucket.
- `hf env` / `hf version`: View environment and version details.

### Authentication (`hf auth`)

- `login` / `logout`: Manage sessions using tokens from [huggingface.co/settings/tokens](https://huggingface.co/settings/tokens).
- `list` / `switch`: Manage and toggle between multiple stored access tokens.
- `whoami`: Identify the currently logged-in account.

### Repository Management (`hf repos`)

- `create` / `delete`: Create or permanently remove repositories.
- `duplicate`: Clone a model, dataset, or Space to a new ID.
- `move`: Transfer a repository between namespaces.
- `branch` / `tag`: Manage Git-like references.
- `delete-files`: Remove specific files using patterns.

---

## Specialized Hub Interactions

### Datasets & Models

- **Datasets:** `hf datasets list`, `info`, and `parquet` (list parquet URLs).
- **SQL Queries:** `hf datasets sql SQL` — Execute raw SQL via DuckDB against dataset parquet URLs.
- **Models:** `hf models list` and `info`.
- **Papers:** `hf papers list` — View daily papers.

### Discussions & Pull Requests (`hf discussions`)

- Manage the lifecycle of Hub contributions: `list`, `create`, `info`, `comment`, `close`, `reopen`, and `rename`.
- `diff`: View changes in a PR.
- `merge`: Finalize pull requests.

### Infrastructure & Compute

- **Endpoints:** Deploy and manage Inference Endpoints (`deploy`, `pause`, `resume`, `scale-to-zero`, `catalog`).
- **Jobs:** Run compute tasks on HF infrastructure. Includes `hf jobs uv` for running Python scripts with inline dependencies and `stats` for resource monitoring.
- **Spaces:** Manage interactive apps. Includes `dev-mode` and `hot-reload` for Python files without full restarts.

### Storage & Automation

- **Buckets:** Full S3-like bucket management (`create`, `cp`, `mv`, `rm`, `sync`).
- **Cache:** Manage local storage with `list`, `prune` (remove detached revisions), and `verify` (checksum checks).
- **Webhooks:** Automate workflows by managing Hub webhooks (`create`, `watch`, `enable`/`disable`).
- **Collections:** Organize Hub items into collections (`add-item`, `update`, `list`).

---

## Advanced Usage & Tips

### Global Flags

- `--format json`: Produces machine-readable output for automation.
- `-q` / `--quiet`: Limits output to IDs only.

### Extensions & Skills

- **Extensions:** Extend CLI functionality via GitHub repositories using `hf extensions install REPO_ID`.
- **Skills:** Manage AI assistant skills with `hf skills add`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…