// posture advisories 100 provenance 75 resolution 100 xyz safety 100 load safety 100 supply chain 100 scanner trust 100 code execution 25 fig. 01 — posture on eight axes, 100 is clean. Weakest: code execution at 25. // the finding 0.0 xyz score out of 10 LOW
MEDIUM config.json declares `auto_map` — from_pretrained(trust_remote_code=True) executes Python shipped in this repo.
INFO authored against vulnerable: further detail on this finding is available to account holders.INFO inferred stack advisories: further detail on this finding is available to account holders.2 more findings on this model.
Author XiaomiMiMo Task text-generation Loader transformers License mit Downloads 98,892 Remote code ships Python that runs on load (trust_remote_code) // dependencies 10 direct, 7 with findings, 50 reachable
Package Evidence Advisories Worst transformers direct, runtime 23 none pinned torch direct, runtime 13 none pinned numpy direct, install 8 hidden huggingface-hub direct, install 0 hidden safetensors direct, install 0 hidden tokenizers direct, install 0 hidden annotated-doc direct, install 0 hidden anyio direct, install 0 hidden
Risk computed 2026-09-22 at 18:49 UTC. Dependencies come from the model's requirements, its declared loader and the code it ships; advisories from NVD, GHSA and OSV.
Model risk is computed from the model's declared and observed Python dependencies and the code it ships. If a finding is wrong, tell us. Report an issue with this page