The first install-time gate for AI models.
A model pulled from Hugging Face is a package tree, a loader stack and sometimes code that runs the moment it loads. CyberXYZ tracks the models your teams pull and every package they declare, scans pickle-format weights opcode by opcode without executing them, and re-checks the whole fleet against fresh threat intel every hour.
- Pickle weights scanned before anything loads
trust_remote_codeand unsafe loaders flagged- Gated repos reported as unknown, never as clean
- Silent weight overwrites caught on the next poll
Next: a per-model forecast of the most likely attack vector, ranked across eight classes, from instructed dependency confusion and weak-maintainer chokepoints to remote-code trust and silent overwrites.