Spaces:
Running
title: Hayward
emoji: 🌾
colorFrom: green
colorTo: blue
sdk: static
app_file: index.html
pinned: false
license: mit
short_description: Check whether loading a model repo will run code
tags:
- security
- pickle
- model-security
- supply-chain
- safetensors
Hayward
Paste a Hub repo id, or drop a checkpoint from your own machine. Hayward reads the model files and tells you whether loading them will run code.
torch.load, joblib.load and numpy.load(allow_pickle=True) execute code
from the file they read. That is what pickle does, and the Hub is still full
of pickle.
The real thing runs offline, in your CI, with one dependency:
pip install hayward
hayward scan ./models
Source and documentation: https://github.com/hedgerow-dev/hayward
Hayward is built by Hedgerow.
How this page works
There is no server. The page loads the hayward wheel from PyPI into
Pyodide and runs the identical scanner in WebAssembly, in your browser. A file
you drop here is never uploaded anywhere. A repo you name is fetched from the
Hub straight into the tab.
That is the same property the CLI has, which is the point: a scanner that phones home is a scanner you cannot run on a file you are worried about.
What it does
- Lists the repo's files and keeps the ones Hayward can read.
- Fetches them one at a time, scans, then discards.
- Shows every finding, and every file it had to skip.
A clean result means Hayward read the files and recognised nothing dangerous in them. It does not mean the model is safe.
Limits
A browser tab is not a build box: this stops at 25 files and 500 MB per file. Anything it skips is listed as skipped rather than quietly dropped.