Model File Format Safety Checker
Check a list of model files and see which formats execute arbitrary code on load, which are safe to deserialise, and what provenance evidence each one carries.
Last reviewed by the Radiatus Cloud team
Securing AI in production?
We build guardrails, governance & compliance for AI systems.
Loading a PyTorch checkpoint runs code
The classic .bin, .pt and .pth checkpoint formats are Python pickles, and unpickling executes whatever the pickle instructs. A model file from an untrusted source is therefore not data to be inspected but a program to be run, and it runs with the privileges of whatever loaded it, typically a GPU host with credentials to a model registry and a data store. This is not a subtle vulnerability requiring a crafted exploit; it is the documented behaviour of the format, and downloading weights from an unfamiliar repository and loading them is closer to running a downloaded binary than to opening a file.
Safetensors exists specifically to fix this
The safetensors format stores tensors as raw bytes with a JSON header and no executable content, so loading it cannot run code by construction rather than by validation. Where a model is published in both formats, taking the safetensors version removes the entire class of problem for the cost of choosing a different file. Where only a pickle format is available, the mitigation is to convert it once in an isolated environment and then use the converted file, rather than loading the original on every deployment.
A hash without a trusted source is decoration
Recording the hash of a downloaded file proves the file has not changed since you recorded it. It says nothing about whether the file was the right one when you first fetched it, which is the question that matters when a repository has been compromised or a name has been typosquatted. The hash becomes meaningful when it is compared against one published by the model's actual author through a channel the attacker does not control, and that comparison is the step usually skipped.
Related tools
- AI Prompt Leakage Analyzer — Paste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
- LLM Data Exposure Checker — Check if text contains data likely to be memorized or exposed by LLMs.
- AI Usage Policy Generator — Generate an acceptable use policy for AI tools in your company.
- Model Hallucination Estimator — Estimate risk of hallucinations based on task type and temperature.
Frequently Asked Questions
Why is a .bin model file dangerous?
Because it is a Python pickle, and unpickling executes whatever the pickle instructs. Loading one from an untrusted source runs code on the host with whatever credentials that host holds.
Is safetensors actually safer?
Yes, by construction rather than by validation. It stores tensors as raw bytes behind a JSON header with no executable content, so loading it cannot run code.
Does weights_only=True make pickle safe?
It substantially reduces the risk by restricting which globals may be loaded, and it is the right default, but it has had bypasses. Preferring safetensors removes the class of problem rather than narrowing it.
Is a GGUF file safe to load?
GGUF is a data format without executable content, so it does not carry the pickle problem. Parsing bugs in any loader remain possible, which is a different and much smaller risk.
Why is a hash not enough on its own?
Because it proves the file has not changed since you recorded it, not that it was the right file when you fetched it. It becomes meaningful only when compared against one published by the author through a channel you trust.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste your model file names and provenance details to check them.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
AI Prompt Leakage Analyzer
AI SecurityPaste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
LLM Data Exposure Checker
AI SecurityCheck if text contains data likely to be memorized or exposed by LLMs.
AI Usage Policy Generator
AI SecurityGenerate an acceptable use policy for AI tools in your company.