Opening some formats runs code
Certain serialization and custom-layer mechanisms can carry executable behavior alongside weights. Model Clearance checks those paths before the file is loaded.
ContactWhen you download an open-source or third-party model to run yourself, you also take in its files. Model Clearance checks those files for code they would run and for risky loading paths before you load them.
If your application only calls a hosted model API, you do not load the model files yourself. Guard and Red address application and agent risks in that setup. Teams running downloaded models also need file inspection.
Certain serialization and custom-layer mechanisms can carry executable behavior alongside weights. Model Clearance checks those paths before the file is loaded.
A model can produce useful outputs while its file or loading path carries unexpected executable behavior.
General file checks may not explain what a model loader can reach inside an artifact. Format-aware analysis adds that context.
We sort what a model file can do to the machine that opens it into nine classes. Each one is described in our research series, and Model Clearance reports findings under the same names.
Opening the file is enough to run code. Model Clearance rebuilds which functions a file would actually call, and with what arguments, so a function that is only referenced is told apart from one that is invoked. It also follows attribute walks toward the interpreter and flags files that carry whole serialized functions.
Read the researchCode that lives in the model as a layer or graph step and runs on every prediction. Model Clearance reads the function bodies stored in layers, layer settings that resolve to system calls by name, and graph steps that read files, write files, or call out to Python or a shell.
Read the researchA graph built to answer differently when it sees a chosen input. Model Clearance reports operators from outside the expected operator sets and nodes that hand control to Python. A trigger trained purely into the weights is beyond what reading a file can show.
Read the researchChat templates and descriptions that your serving stack renders on each request. Model Clearance reads the metadata header and reports template expressions that reach for interpreter internals, ignoring comments and plain text that would never execute.
Read the researchA model file has no reason to know a web address. Model Clearance lists the endpoints embedded in a file and separates known callback services from unfamiliar external hosts, leaving ordinary ML infrastructure out of the report.
Read the researchFiles that place themselves outside the model folder. Model Clearance checks archive member names, the targets of links inside archives, and the side files an ONNX model points to for its weights, before anything is unpacked.
Read the researchSmall files that consume the machine. Model Clearance measures how far an archive expands and how many iterations a chat template can force, counting the real cost of nested loops instead of reacting to how a template looks.
Read the researchSettings that tell the loader to fetch and run the author's code later. Model Clearance surfaces remote-code switches and class mappings that point at remote sources, so you decide whether to extend that trust.
Read the researchFiles built to be misread. Model Clearance recognises a serialized object stream under a misleading filename, looks inside compressed wrappers, reads archives whose checksums were altered on purpose, and reports Python source text in formats meant to hold only weights.
Read the researchModel Clearance reports the specific thing it found and where, so the person reviewing a model can check it instead of taking a label on trust.
Each finding names the file, the location inside it, and the operation found there, with the exact text or call that raised it.
Findings carry a severity and a confidence level. Weak, uncorroborated signals are left out, and repeated hits for the same issue are merged into one entry.
If part of a repository or archive could not be finished, the result is marked incomplete instead of clean, and the unread files are listed.
Model Clearance reads the file as bytes and interprets its structure itself. No model framework opens it and nothing inside it runs.
The result comes from fixed analysis rules, so a repeat run on the same bytes returns the same findings. No language model decides the outcome.
Nesting depth, entry counts and unpacked size are all bounded, so a file designed to exhaust the analyzer is stopped and reported.
Send a ZIP of model files. Each member is identified and routed to the analysis that fits it, and archives inside archives are opened too.
Paste a huggingface.co/org/model URL. Model Clearance takes the repository file listing and reads the part of each file where code can live, without pulling gigabytes of weights.