← Daily AI recipesWork✓ Verified Oct 8, 2026

Check an AI model for backdoors and hidden code before downloading it from Hugging Face

In 5 minutes, scan any model file from Hugging Face right from the command line - the ModelAudit scanner will check pickle files, weights, and configs for malicious code, embedded secrets, and network «beacons» without loading or running the model.

  1. 1.Make sure your computer has a suitable version of Python. Open a terminal (PowerShell on Windows) and run the command below. ModelAudit requires Python from 3.10 to 3.13.

    If the version is below 3.10 or above 3.13, install Python 3.12 from the official website python.org - it is free. If you get an error instead of the version, try the command py --version (Windows) or python3 --version (macOS/Linux).

    Python ↗
    Prompt
    python --version
    What this prompt doesThe command prints the Python version number installed on your computer. You don't need to change anything - just copy it and press Enter.
  2. 2.Install the ModelAudit scanner with a single command:

    If pip is not found, try pip3 install 'modelaudit[all]'. Installation takes 1-2 minutes. The model is not downloaded or launched - the scanner analyzes the files statically.

    ModelAudit ↗
    Prompt
    pip install 'modelaudit[all]'
    What this prompt doesThe command installs the ModelAudit scanner along with all modules for different model formats (PyTorch, ONNX, TensorFlow, Keras, SafeTensors, GGUF, and others). You don't need to change anything.
  3. 3.Verify that the scanner is installed and view the list of available scanners:

    In the list, you will see about 45 modules: checking pickle opcodes, ZIP archives, configs, etc. If the command is not found, close and reopen the terminal.

    ModelAudit ↗
    Prompt
    modelaudit scan --list-scanners
    What this prompt doesThe command shows the IDs of all built-in scanners - you can run them selectively if desired. You don't need to change anything.
  4. 4.Scan a model from Hugging Face without downloading it manually. Take the model address from your browser and substitute it into the command instead of the placeholder:

    Example of a real address: https://huggingface.co/bert-base-uncased - then the command will be modelaudit scan hf://bert-base-uncased. ModelAudit itself will download the model files to a temporary folder, scan them, and delete them. If the service is unavailable in your region, use a mirror or download the model file manually.

    ModelAudit ↗
    Prompt
    modelaudit scan hf://[owner_name]/[model_name]
    What this prompt doesReplace [owner_name]/[model_name] with the model address from the Hugging Face page. For example, for the page https://huggingface.co/microsoft/resnet-50 the command looks like this: modelaudit scan hf://microsoft/resnet-50. Scanning takes from a few seconds to a couple of minutes depending on the model size.
  5. 5.Read the result: the scanner will show a table with findings (issues) and the danger level of each. Green rows - check passed, yellow/red - suspicious spots: dangerous pickle opcodes, embedded links and IP addresses, hidden API keys, suspicious layers like Lambda in Keras.

    A single finding with a URL like huggingface.co in the metadata is usually fine (the model links to itself). Red findings of error level, especially related to code execution, are a reason to abandon this model and look for another.

    ModelAudit ↗
  6. 6.If the model is clean - download and use it as usual. Want to save the report (for example, for colleagues or for CI) - output it to a JSON file:

    In the JSON report, findings are in the issues array - count them; the checks array duplicates the same problems, do not count them twice. Official command documentation is on the promptfoo.dev website.

    ModelAudit ↗
    Prompt
    modelaudit scan hf://[owner_name]/[model_name] --format json --output results.json
    What this prompt doesThe same check, but the result is saved to a results.json file in your current folder. Replace [owner_name]/[model_name] with the model address from Hugging Face, as in step 4.
💰 What it costs to followprices as of 2026-10
  • freeModelAuditOpen-source tool: installation and scanning are completely free, no card required.
  • freeHugging Face (model downloads)Downloading models and viewing repositories are free and unlimited on the free tier; trial requests through widgets on model pages are also free but with rate limits.
Try it and be the first to check in

Why today

AI services change fast - interfaces and free limits may differ from what's described.