Skip to content
Back to skills

cli-anything-hf-spaces

ASecurity

CLI harness for HuggingFace Spaces administration. Manages hardware tiers, env vars, secrets, sleep/restart, logs, README sync, and manifest-driven desired-state apply.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 11, 2026
toolsbashapi

Works with

  • cli
  • api

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned September 11, 2026

npx -y skills add SkyyRoseLLC/DevSkyy --skill skills --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of cli-anything-hf-spaces?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for cli-anything-hf-spaces
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/skyyrosellc-cli-anything-hf-spaces/badge)](https://www.skillsdirectory.com/skills/skyyrosellc-cli-anything-hf-spaces)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cli-anything-hf-spaces
description: >
  CLI harness for HuggingFace Spaces administration. Manages hardware tiers,
  env vars, secrets, sleep/restart, logs, README sync, and manifest-driven
  desired-state apply.
---

# cli-anything-hf-spaces

## When to use this skill

Use this skill when you need to:
- Administer HuggingFace Spaces from the command line
- Change hardware tiers (with billing awareness)
- Manage Space secrets and environment variables
- Stream runtime or build logs
- Sync README.md files
- Apply manifest-driven desired state to a Space

## Prerequisites

```bash
pip install 'cli-anything-hf-spaces[all]'
# or for minimal install:
pip install cli-anything-hf-spaces
```

Auth (in priority order):
1. `--token <token>` (in-memory only, never written to disk)
2. `HF_TOKEN` environment variable
3. `~/.cache/huggingface/token` (from `huggingface-cli login`)

## Command groups

| Group      | Description                                      |
|------------|--------------------------------------------------|
| `space`    | info, list, pause, restart, duplicate            |
| `hardware` | get, set (STOP-AND-SHOW), list-tiers             |
| `secrets`  | set, delete (STOP-AND-SHOW), list (manifest only)|
| `vars`     | list, get, set, delete                           |
| `logs`     | run, build (httpx SSE streaming)                 |
| `readme`   | get, set, sync                                   |
| `manifest` | init, show, plan, apply (STOP-AND-SHOW)          |
| `session`  | list, show, delete                               |
| `doctor`   | auth + SDK health check                          |

## Key constraints

- **Secrets are write-only** via HfApi. `secrets list` reads local manifest only.
- **Log streaming** requires `httpx`: `pip install 'cli-anything-hf-spaces[logs]'`
- **Factory reset** is web-UI only — not available in this CLI.
- **STOP-AND-SHOW gate** on: `hardware set`, `secrets delete`, `space pause`, `manifest apply`
- Token is **never** written to disk by the CLI.

## Quick reference

```bash
# Space info
hf-spaces space info owner/my-space

# Change hardware (billing — requires --confirm)
hf-spaces hardware set owner/my-space t4-small --confirm

# Set a secret (value prompted interactively)
hf-spaces secrets set owner/my-space MY_API_KEY

# List variables
hf-spaces vars list owner/my-space

# Stream runtime logs
hf-spaces logs run owner/my-space

# Sync README
hf-spaces readme sync owner/my-space ./README.md

# Manifest workflow
hf-spaces manifest init owner/my-space --out ./hf-space-manifest.json
# edit hf-space-manifest.json ...
hf-spaces manifest plan ./hf-space-manifest.json
hf-spaces manifest apply ./hf-space-manifest.json --confirm

# Health check
hf-spaces doctor

# Interactive REPL
hf-spaces
```

## JSON output

Every command supports `--json` for machine-readable output:

```bash
hf-spaces --json space info owner/my-space | jq .stage
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…