Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
modelaudit — Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment | Kitploit
Tools/GitHubGitHub/promptfoo/modelaudit
Static AnalysisStatic Code Analysis (SAST)Vulnerability AnalysisData ExfiltrationMalware AnalysisDevSecOpsSecret DetectionSupply Chain SecurityMachine LearningAI SecurityAdversarial AttackTop in Adversarial Attack #14
7521659h 26m agoReviewed by Kitploit
Top in AI Security #14
Top in Machine Learning #9
GitHubpromptfoo/modelaudit

modelaudit

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ModelAudit

Secure your AI models before deployment. Static scanner that detects malicious code, potential backdoor indicators, and security vulnerabilities in ML model files — without ever loading or executing them.

PyPI version Python versions Code Style: ruff License Security policy

ModelAudit scan results

Full Documentation | Usage Examples | Supported Formats

Why ModelAudit

Models download from untrusted registries, pass through CI, and end up running in production. Traditional SAST tools do not look at pickle opcodes, HDF5 group layouts, ONNX proto graphs, or TensorFlow SavedModel signatures — ModelAudit does:

  • Scan statically. No model is ever loaded, unpickled, or executed.
  • Cover the formats you actually ship. 40+ scanners spanning pickle, PyTorch, SafeTensors, ONNX, TensorFlow, Keras, GGUF, archives, and configs.
  • Fit into CI. Machine-readable output (JSON, SARIF), strict mode, exit codes, and selectable scanners.
  • Surface coverage limits. Recognized scanners report bounded-analysis gaps such as truncated reads or exhausted budgets instead of presenting them as fully covered results.

Comparable tools: picklescan (pickle only, Python-based), fickling (pickle only, AST-based), modelscan (pickle + TensorFlow + Keras subset). ModelAudit is broader in coverage and ships a native Rust pickle engine via its companion package modelaudit-picklescan.

Quick Start

Requires Python 3.10-3.13

pip install "modelaudit[all]"

# Scan a file or directory
modelaudit model.pkl
modelaudit ./models/

# Export results for CI/CD
modelaudit model.pkl --format json --output results.json
$ modelaudit suspicious_model.pkl

Files scanned: 1 | Issues found: 2 critical, 1 warning

1. suspicious_model.pkl (pos 28): [CRITICAL] Malicious code execution attempt
   Why: Contains os.system() call that could run arbitrary commands

2. suspicious_model.pkl (pos 52): [WARNING] Dangerous pickle deserialization
   Why: Could execute code when the model loads

What It Detects

  • Code execution attacks in Pickle, PyTorch, NumPy, and Joblib files
  • Potential backdoor indicators — suspicious weight patterns, anomalous tensors, or hidden-code signals
  • Embedded secrets — API keys, tokens, and credentials in model weights or metadata
  • Network indicators — URLs, IPs, and socket usage that could enable data exfiltration
  • Archive exploits — path traversal, symlink attacks in ZIP/TAR/7z files
  • Unsafe ML operations — Lambda layers, custom ops, TorchScript/JIT, template injection
  • Supply chain risks — tampering, license violations, suspicious configurations

Supported Formats

ModelAudit includes 45 registered scanners covering model, archive, and configuration formats:

Download Tool