Instructions to use ykilcher/totally-harmless-model with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use ykilcher/totally-harmless-model with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("feature-extraction", model="ykilcher/totally-harmless-model")# Load model directly from transformers import AutoTokenizer, AutoModel tokenizer = AutoTokenizer.from_pretrained("ykilcher/totally-harmless-model") model = AutoModel.from_pretrained("ykilcher/totally-harmless-model") - Notebooks
- Google Colab
- Kaggle
fix: convert pytorch_model.bin to safetensors (RCE vulnerability)
#3
by abdellahennajari - opened
Vulnerability Found
pytorch_model.bin contains a CRITICAL RCE vulnerability:
- Unsafe eval from builtin in Pickle payload
- Anyone running torch.load() executes arbitrary code
Fix
- Extracted 100 tensors with a custom SafeUnpickler
- Converted to safetensors format (safe by design)
- Verified clean with modelscan
Fork with fix: abdellahennajari/totally-harmless-model (branch: fix/convert-to-safetensors)