Skip to content

The 8 Hugging Face security checks Black Cat runs

Black Cat SSPM evaluates 8 security policies against your Hugging Face configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.

access control

highResource Group Auto-Join With Write Access

Avoid auto-joining every org member to a resource group at write/admin role

authentication

lowSSO Not Observed

Confirm SSO is configured and in use for the organization

data exposure

mediumPublic Org Repository

Review org repositories that are publicly visible

lowPublic Gated Repository Misconfiguration

Consider gating sensitive datasets/models that must remain shareable

logging

lowAudit Logs Unavailable

Enable an org plan that provides audit logs

privilege

mediumExcessive Organization Admins

Reduce the number of organization administrators

lowMember With Org Admin Role

Review members holding the organization admin role

token governance

highToken Approval Policy Disabled

Re-enable the access-token approval policy

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial