huggingface-llm-trainer

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/convert_to_gguf.py

No direct indicators of embedded malware are present in this fragment (it performs model merge → GGUF conversion/quantization → upload). However, the script deliberately creates high-impact supply-chain and remote-code-execution risk by (1) using trust_remote_code=True when loading remote Hugging Face model/tokenizer code and (2) cloning an unpinned llama.cpp repository at runtime, installing its Python requirements via pip, and executing its conversion/quantization tooling. Treat this as a security alert for supply-chain integrity: pin exact revisions, minimize/disable trust_remote_code where possible, and control/validate the environment-provided model identifiers and OUTPUT_REPO.

Confidence: 72%Severity: 66%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:25 AM
Package URL
pkg:socket/skills-sh/huggingface%2Fskills%2Fhuggingface-llm-trainer%2F@617ecb786014c1ac92c86d90cd9859850bd2b65630db8b4d9e87bca22b1a26ad
Security Audit — socket — huggingface-llm-trainer