The 8 Hugging Face security checks Black Cat runs
Black Cat SSPM evaluates 8 security policies against your Hugging Face configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.
access control
highResource Group Auto-Join With Write Access
Avoid auto-joining every org member to a resource group at write/admin role
authentication
lowSSO Not Observed
Confirm SSO is configured and in use for the organization
data exposure
mediumPublic Org Repository
Review org repositories that are publicly visible
lowPublic Gated Repository Misconfiguration
Consider gating sensitive datasets/models that must remain shareable
logging
lowAudit Logs Unavailable
Enable an org plan that provides audit logs
privilege
mediumExcessive Organization Admins
Reduce the number of organization administrators
lowMember With Org Admin Role
Review members holding the organization admin role
token governance
highToken Approval Policy Disabled
Re-enable the access-token approval policy