huggingface-llm-trainer
Warn
Audited by Socket on Aug 10, 2026
1 alert found:
AnomalyAnomalyscripts/convert_to_gguf.py
LOWAnomalyLOW
scripts/convert_to_gguf.py
No direct indicators of embedded malware are present in this fragment (it performs model merge → GGUF conversion/quantization → upload). However, the script deliberately creates high-impact supply-chain and remote-code-execution risk by (1) using trust_remote_code=True when loading remote Hugging Face model/tokenizer code and (2) cloning an unpinned llama.cpp repository at runtime, installing its Python requirements via pip, and executing its conversion/quantization tooling. Treat this as a security alert for supply-chain integrity: pin exact revisions, minimize/disable trust_remote_code where possible, and control/validate the environment-provided model identifiers and OUTPUT_REPO.
Confidence: 72%Severity: 66%
Audit Metadata