Last released Sep 4, 2026
Scan Hugging Face and local ML models for pickle RCE, unsafe torch.load/pickle.load paths, trust_remote_code, Zip Slip, and supply-chain risks — without executing the artifact