Family: model-file-supply-chain · Fixture:
modelaudit-5bacb3518633· Severity: Medium · Confidence: High. Deterministic check — no LLM judge, only opcodes that match or do not.
What this shows
A Python pickle can run arbitrary code the instant it is loaded, because unpickling calls the object's __reduce__ hook. Model weights get shipped and shared as pickles constantly. So "download a model and load it" is, for a pickle-backed file, the same trust decision as "download a program and run it." This finding is the canonical positive control for that: a model file whose __reduce__ invokes posix.system, caught by a static opcode scan before it ever runs.
Why it matters
The AI supply chain moves model files the way the software supply chain moves packages, but with far less scrutiny. People pull weights from hubs, mirrors, and colleagues and load them into a process that often has network access, credentials, and a shell. A malicious pickle needs no exploit and no user interaction beyond the load itself. Static detection before load is the only safe checkpoint, because once it deserializes, the code has already run.
How it was tested
The harness ran the modelaudit CLI's real static pickle/safetensors/GGUF opcode scan. No account, no network, no execution of the payload.
- Target:
malicious.pkl, a canonical__reduce__-based malicious-pickle fixture that would invokeposix.systemon load. - Control: a clean file scanned in the same pass.
- Detection: the scanner reads opcodes statically and flags dangerous constructs without deserializing.
Result: the malicious file was flagged (pickle_verdict= malicious, rule S201) and the clean control passed.
The twin fixture (why two files)
This fixture has a twin, modelaudit-8afc82bacbbd, scanning the same payload shape through the unified-suite adapter — the same payload delivered through a different ingestion path. The pair exists to pin the detection to the payload class, not to one adapter. Both replay PASS as of 2026-10-01.
Verification
- Promotion gate: this family has no LLM judge (the check is deterministic), so the gate reran the real static scan against the same file. Rule
S201fired again, so the fixture promoted. - Replay suite:
replay-fixturesreruns the real scan; verified PASS 2026-10-01 (modelaudit 0.2.37). - Score: COMPLIED at 9.0.
Because the detection is deterministic, this is one of the highest-confidence entries in the portfolio: there is no judge to disagree, only opcodes that either match a dangerous pattern or do not.
Responsible-disclosure boundary
This write-up names the class, the rule, and the mechanism (a __reduce__ hook reaching a system call). It does not ship the crafted pickle. The fixture stays in the gitignored lab, referenced by hash in the canonical record.
Reproduce
The replay suite is part of the cipher_machine harness:
cd agents/cipher/tools && python3 -m cipher_machine replay-fixtures