SECURITY FOR DOWNLOADED MODELS

Inspect model files
before loading.

When you download an open-source or third-party model to run yourself, you also take in its files. Model Clearance checks those files for code they would run and for risky loading paths before you load them.

model clearance sample
NEVER EXECUTED
FILEFORMATVERDICT
Meta-Llama-3-8B / *.ggufno finding in this exampleggufCLEAN
acct/model-b / tf_model.h5↳ layer function calls execkeras-h5MALICIOUS
yolov8n.ptno finding in this examplepytorchCLEAN
acct/model-a / data.pkl↳ os.system via REDUCEpickleMALICIOUS
resnet50 / pytorch_model.binno finding in this examplepytorchCLEAN
bert-base-uncased / model.safetensorsno finding in this examplesafetensorsCLEAN
Illustrative scan sequence static · no code run
WHY THE FILE MATTERS

A model file can contain more than weights

If your application only calls a hosted model API, you do not load the model files yourself. Guard and Red address application and agent risks in that setup. Teams running downloaded models also need file inspection.

Opening some formats runs code

Certain serialization and custom-layer mechanisms can carry executable behavior alongside weights. Model Clearance checks those paths before the file is loaded.

A working model can still carry risk

A model can produce useful outputs while its file or loading path carries unexpected executable behavior.

The file needs its own inspection

General file checks may not explain what a model loader can reach inside an artifact. Format-aware analysis adds that context.

NINE RISK CLASSES

What Model Clearance looks for

We sort what a model file can do to the machine that opens it into nine classes. Each one is described in our research series, and Model Clearance reports findings under the same names.

pickle · pytorch · joblib · numpy

Load-Time Execution

Opening the file is enough to run code. Model Clearance rebuilds which functions a file would actually call, and with what arguments, so a function that is only referenced is told apart from one that is invoked. It also follows attribute walks toward the interpreter and flags files that carry whole serialized functions.

Read the research
keras · h5 · savedmodel

Inference-Time Logic

Code that lives in the model as a layer or graph step and runs on every prediction. Model Clearance reads the function bodies stored in layers, layer settings that resolve to system calls by name, and graph steps that read files, write files, or call out to Python or a shell.

Read the research
onnx

Conditional Output Tampering

A graph built to answer differently when it sees a chosen input. Model Clearance reports operators from outside the expected operator sets and nodes that hand control to Python. A trigger trained purely into the weights is beyond what reading a file can show.

Read the research
gguf · ggml

Metadata Template Injection

Chat templates and descriptions that your serving stack renders on each request. Model Clearance reads the metadata header and reports template expressions that reach for interpreter internals, ignoring comments and plain text that would never execute.

Read the research
all formats

Outbound Beaconing

A model file has no reason to know a web address. Model Clearance lists the endpoints embedded in a file and separates known callback services from unfamiliar external hosts, leaving ordinary ML infrastructure out of the report.

Read the research
zip · tar · onnx

Path Escape

Files that place themselves outside the model folder. Model Clearance checks archive member names, the targets of links inside archives, and the side files an ONNX model points to for its weights, before anything is unpacked.

Read the research
zip · gguf

Resource Exhaustion

Small files that consume the machine. Model Clearance measures how far an archive expands and how many iterations a chat template can force, counting the real cost of nested loops instead of reacting to how a template looks.

Read the research
config · json · yaml

Deferred Trust

Settings that tell the loader to fetch and run the author's code later. Model Clearance surfaces remote-code switches and class mappings that point at remote sources, so you decide whether to extend that trust.

Read the research
all formats

Concealment and Evasion

Files built to be misread. Model Clearance recognises a serialized object stream under a misleading filename, looks inside compressed wrappers, reads archives whose checksums were altered on purpose, and reports Python source text in formats meant to hold only weights.

Read the research
File types Model Clearance reads
.pkl.pickle.joblib.pt.pth.bin.npy.npz.keras.h5.pb.onnx.gguf.safetensors.zip.tar.json.yaml
THE FINDING

A result you can act on

Model Clearance reports the specific thing it found and where, so the person reviewing a model can check it instead of taking a label on trust.

Where it is and what it does

Each finding names the file, the location inside it, and the operation found there, with the exact text or call that raised it.

How serious and how sure

Findings carry a severity and a confidence level. Weak, uncorroborated signals are left out, and repeated hits for the same issue are merged into one entry.

What could not be read

If part of a repository or archive could not be finished, the result is marked incomplete instead of clean, and the unread files are listed.

HOW IT TREATS THE FILE

Reading a file without trusting it

The model is never loaded

Model Clearance reads the file as bytes and interprets its structure itself. No model framework opens it and nothing inside it runs.

Same file, same result

The result comes from fixed analysis rules, so a repeat run on the same bytes returns the same findings. No language model decides the outcome.

Built for hostile input

Nesting depth, entry counts and unpacked size are all bounded, so a file designed to exhaust the analyzer is stopped and reported.

TWO WAYS IN

Point it at a file or a repo

Upload an archive

Send a ZIP of model files. Each member is identified and routed to the analysis that fits it, and archives inside archives are opened too.

  • Every member examined
  • Nested archives opened, within limits
  • Findings listed per file

Hugging Face repository

Paste a huggingface.co/org/model URL. Model Clearance takes the repository file listing and reads the part of each file where code can live, without pulling gigabytes of weights.

  • No local download needed
  • Config files read first
  • Unfinished files reported, not hidden