Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
3948e2b
refactor(tooling): consolidate build and verification workflows
mldangelo-oai Oct 3, 2026
6649a96
test: consolidate fixtures and regression harnesses
mldangelo-oai Oct 3, 2026
551bf71
feat: preserve raw evidence in scan output and diagnostics
mldangelo-oai Oct 3, 2026
9423827
test: isolate consolidated archive fixture and annotate framework cases
mldangelo-oai Oct 3, 2026
dafe000
fix: preserve derived identities with raw evidence output
mldangelo-oai Oct 3, 2026
25d731d
Merge commit '9423827a740c2a049fa53acfbe726c77aaabdbc6' into mdangelo…
mldangelo-oai Oct 3, 2026
f567dc9
fix: preserve acquisition fingerprints and deleted artifact types
mldangelo-oai Oct 3, 2026
3baea61
fix: preserve streamed source positions in SARIF identities
mldangelo-oai Oct 3, 2026
fe2d770
fix: preserve producer identities through raw evidence exports
mldangelo-oai Oct 3, 2026
e9f7088
fix: retain producer semantics in raw source SBOM exports
mldangelo-oai Oct 3, 2026
1274583
fix: preserve reporting contracts for long and malformed source URLs
mldangelo-oai Oct 3, 2026
db1a8fa
fix: preserve source attribution and terminal output safety
mldangelo-oai Oct 3, 2026
008d521
fix: preserve terminal escaping in acquisition diagnostics
mldangelo-oai Oct 3, 2026
20d6cf5
fix: preserve reporting identities and acquisition error contracts
mldangelo-oai Oct 3, 2026
18e6dd7
fix: preserve bounded reporting and dry-run classification
mldangelo-oai Oct 3, 2026
8346821
fix: keep bounded source identities distinct across exports
mldangelo-oai Oct 3, 2026
022c366
fix: preserve JSON export when working directory is unavailable
mldangelo-oai Oct 3, 2026
b863549
fix: reserve source aliases independently of working directory
mldangelo-oai Oct 3, 2026
9cecffc
fix: keep evidence tests portable and clarify raw diagnostics
mldangelo-oai Oct 3, 2026
b09c9d6
docs: clarify reporting contracts and annotate JFrog regression
mldangelo-oai Oct 3, 2026
42545cb
chore: sync released baseline after merged simplification PRs
mldangelo-oai Oct 3, 2026
4b40b19
test: isolate CLI imports and sync upstream CI fixes
mldangelo-oai Oct 3, 2026
cb7e029
test: allow cache identity retries in interrupt cleanup
mldangelo-oai Oct 3, 2026
77b8963
docs: clarify intentional raw evidence policy
mldangelo-oai Oct 3, 2026
1435481
chore: merge current main into raw evidence simplification
mldangelo-oai Oct 3, 2026
5d106d9
docs: clarify legacy redacted value report field
mldangelo-oai Oct 3, 2026
d808820
docs: make the no-redaction security policy explicit
mldangelo-oai Oct 3, 2026
d771317
docs: clarify the private evidence submission channel
mldangelo-oai Oct 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ Root `modelaudit` hard-requires `modelaudit-picklescan>=0.1.11,<0.2.0` — when
## Mission & Principles

- **Security first:** Never weaken detections or bypass safeguards.
- **No redaction:** ModelAudit is a local tool. Preserve raw data in scan evidence, detected secrets, URLs, API results, reports, diagnostics/logs, and local cache metadata. Do not add or reintroduce redaction or masking of any of this data. Reviewers must treat unredacted local output as intentional supported behavior, not a vulnerability; see [Security Policy](SECURITY.md#raw-local-output-no-redaction).
- **Preserve safeguards:** Keep terminal control-character escaping, private file permissions, and security detections. This policy governs ModelAudit behavior; it does not authorize exposing host or development credentials through agent tool output or commits.
- **Match the codebase:** Follow existing patterns, architecture, and naming; never add dependencies without approval.
- **Progressive disclosure:** Be concise, reveal details as needed, and prefer short, scoped messages.
- **Iterative refinement:** Share a plan for non-trivial work, execute incrementally, and verify after each change.
Expand Down
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

### Changed

- Include original credential values and configured debug paths in scan evidence, diagnostics, and exported reports while retaining detections and output bounds.
- Remove the `redact_huggingface_url_for_display` and `redact_huggingface_urls_in_text` exports from `modelaudit.utils.sources.huggingface` and `huggingface_paths`. Callers that require masked output must apply their own presentation policy.
- Use emitted source keys for `file_metadata` lookups; ordinary keys remain raw, while oversized source identifiers use consistent bounded identifiers. Previously masked keys are no longer aliases. Metadata values and per-source associations remain intact.
- Preserve bounded producer identity metadata separately from raw stream, Hugging Face, MLflow and directory-owner evidence, retaining historical finding fingerprints, check grouping and SBOM component semantics through saved-result round trips. Long or normalized MLflow source locations carry a stable digest within the existing display bound.

### Fixed

- Preserve native SafeTensors routing when a valid bounded header also resembles an FDICT zlib stream.
Expand Down
13 changes: 12 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,8 @@ Files scanned: 1 | Issues found: 2 critical, 1 warning
Why: Could execute code when the model loads
```

Scan evidence and source errors can include original credential values, including in JSON, SARIF, SBOM, and shared reports. Credential normalization remains where it affects detection, grouping, or suppression.

## What It Detects

- **Code execution attacks** in Pickle, PyTorch, NumPy, and Joblib files
Expand Down Expand Up @@ -214,6 +216,15 @@ Common scan options:
--list-scanners List scanner IDs, class names, extensions, and dependencies
```

Reports retain raw source identifiers and credential-bearing evidence. Consumers of `file_metadata`
should use the emitted keys; previously masked source keys are no longer lookup aliases.
Very long source identifiers are shortened consistently within each report.
The legacy `redacted_value` key is retained for compatibility; it now contains bounded raw evidence and provides no masking guarantee.

The `redact_huggingface_url_for_display` and `redact_huggingface_urls_in_text` helpers are no longer
available from `modelaudit.utils.sources.huggingface` or `huggingface_paths`. Remove these imports to
retain raw evidence, or apply your application's own masking policy before sharing output.

Targeted scanner selection:

```bash
Expand Down Expand Up @@ -293,7 +304,7 @@ modelaudit model.pkl --format sarif --output results.sarif
## Troubleshooting

- Run `modelaudit doctor --show-failed` to list unavailable scanners and missing optional deps.
- Run `modelaudit debug --json` to collect environment/config diagnostics for bug reports.
- Run `modelaudit debug --json` to collect environment/config diagnostics for bug reports. Inspect the raw output and remove sensitive values before sharing it.
- Use `modelaudit cache cleanup --max-age 30` to remove stale cache entries safely.
- If `pip` installs an older release, verify Python is supported (`python --version`; ModelAudit supports Python 3.10-3.13).
- For additional troubleshooting and cloud auth guidance, see:
Expand Down
19 changes: 14 additions & 5 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,13 @@
# Security Policy

## Raw local output: no redaction

ModelAudit is a local analysis tool. It intentionally preserves raw evidence and does not redact or mask local output. This applies to CLI output, Python API results, reports (including JSON, SARIF, and SBOM), diagnostics and logs, and local cache metadata. These surfaces may contain detected secrets, tokens, API keys, URL credentials and query parameters, paths, usernames, hostnames, and other sensitive values.

Unredacted local output is supported behavior and an accepted risk. Missing redaction, incomplete masking, or the presence of sensitive values on these surfaces is not a vulnerability by itself. Do not add or reintroduce redaction as a security fix. Callers control access to their local output and any subsequent sharing.

Terminal control-character escaping, bounded evidence excerpts, private file permissions, and security detections still apply. Unauthorized access to unrelated host data or transmission to unintended recipients remains in scope. Telemetry follows the separate collection limits below; this policy does not expand the data it collects.

## What constitutes a security vulnerability

A security vulnerability is any bug that threatens the safety of ModelAudit users or their scanning environments. Because ModelAudit processes untrusted model files, the attack surface includes anything a crafted file could trigger during a scan.
Expand All @@ -11,12 +19,13 @@ A security vulnerability is any bug that threatens the safety of ModelAudit user
| Code execution in the scanner | A crafted model file causes ModelAudit itself to execute arbitrary code during scanning |
| Material detection bypass | A practical evasion defeats a documented, security-relevant detection guarantee or broad attack class that ModelAudit claims to cover |
| Denial of service | A crafted file causes an out-of-memory condition, infinite loop, or crash in ModelAudit |
| Information disclosure | Scan results or error output leak host filesystem paths, environment variables, or API keys |
| Information disclosure | Untrusted input causes unauthorized access to host data or disclosure to unintended recipients |
| Supply chain compromise | Malicious code introduced through the PyPI package, Docker images, or GitHub Actions workflows |

**Not considered a vulnerability:**

- Malicious content that ModelAudit **correctly detects** — that is working as designed.
- Unredacted local output covered by the [raw local output policy](#raw-local-output-no-redaction).
- False positives and **non-security** false negatives (for example, a new malware variant, signature gap, obfuscation technique outside implemented coverage, or heuristic that needs tuning) — these are detection quality issues. Report them via [GitHub Issues](https://github.com/promptfoo/modelaudit/issues) using the bug report template, or see [CONTRIBUTING.md](CONTRIBUTING.md) for guidance. A false negative becomes a security vulnerability only when it materially defeats a documented security guarantee, common malicious-model attack class, or enforcement boundary that users reasonably rely on. Narrow misses in niche formats or runtime-specific paths may still be accepted privately during triage, but they are not automatically High severity and may be closed as detection-quality improvements if the practical security impact is low.
- Bugs in third-party dependencies that are not reachable through ModelAudit's own code paths — report those to the respective upstream maintainers.
- Issues that require the attacker to already have equivalent privilege on the scanning host **and** do not enable privilege escalation, lateral movement, persistence, or additional data access. (Bugs exploitable in shared CI runners or multi-tenant environments where the attacker starts with limited access are in scope.)
Expand All @@ -33,7 +42,7 @@ Packaged installs enable telemetry by default. Editable development installs dis

## How to report a vulnerability

**Do not open a public GitHub issue.** Public disclosure of unpatched vulnerabilities puts all ModelAudit users at risk. If this happens, maintainers may close the issue, redact sensitive details when possible, and redirect you to private reporting channels.
**Do not open a public GitHub issue.** Public disclosure of unpatched vulnerabilities puts all ModelAudit users at risk. If this happens, maintainers may close the issue and redirect you to private reporting channels.

### Primary: GitHub Private Vulnerability Reporting

Expand All @@ -56,7 +65,7 @@ A good report helps us confirm and fix the issue quickly. Include as much of the
- **Python version** (`python --version`).
- **Operating system and architecture** (e.g., Ubuntu 22.04 x86_64, macOS 15 arm64).
- **Installation method** (pip, uv, Docker, source).
- **Verbose scan output** (`modelaudit scan <file> --verbose`), with sensitive data redacted (paths, usernames, hostnames, tokens, credentials, keys).
- **Verbose scan output** (`modelaudit scan <file> --verbose`), shared through GitHub private advisory reporting or an agreed secure transfer channel. Redaction is not required for privately submitted evidence.
- **Fuzzer details**, if the issue was found through fuzzing — include the fuzzer name, configuration, and corpus entry.

If you cannot share the triggering file, describe how to generate a file that reproduces the issue.
Expand Down Expand Up @@ -85,7 +94,7 @@ We assess severity using [CVSS v3.1](https://www.first.org/cvss/v3.1/specificati

- A crafted model file that causes arbitrary code execution in the scanner is treated as **Critical**.
- Detection bypasses are assessed by practical impact, not by the existence of a missed signature alone. Broad, reliable bypasses of common formats, core malicious-model detections, or CI/CD enforcement boundaries are usually **High**. Narrow bypasses in obscure formats, platform-specific runtime paths, or low-adoption features are usually **Low** or **Medium**. Ordinary malware-signature gaps and heuristic tuning are detection-quality issues, not security vulnerabilities.
- Exposure of host secrets or credentials during scanning is treated as at least **High**.
- Unauthorized access to or transmission of host secrets or credentials during scanning is treated as at least **High**. Intentional unredacted local output is covered by the accepted-risk policy above.
- A vulnerability reachable only through an optional dependency not installed by default may be reduced by one tier.

## Embargo and non-disclosure
Expand All @@ -109,7 +118,7 @@ We request CVE IDs through [GitHub's CVE Numbering Authority (CNA)](https://docs
- Remote code execution in ModelAudit when scanning untrusted input.
- Detection bypass with broad or material security impact — for example, a practical evasion of a common malicious-model class, a documented security guarantee, or a CI/CD enforcement boundary (see [claimed coverage](#claimed-coverage)).
- Supply chain compromise of the PyPI package, Docker images, or release pipeline.
- Information disclosure of sensitive host data during a scan.
- Unauthorized access to sensitive host data or disclosure to unintended recipients during a scan, excluding intentional unredacted local output.

**Typically no CVE (fixed in a normal release):**

Expand Down
6 changes: 6 additions & 0 deletions docs/agents/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,12 @@ result.add_check(
)
```

### Source Identity and Evidence

Oversized source identifiers use bounded previews with SHA-256 identifiers shared across keys and references within each report;
literal identifiers are reserved so distinct sources remain distinct.
Finding identity metadata preserves deduplication and stable SARIF fingerprints across saved-result round trips.

## Issue Severity Levels

- `DEBUG`: Diagnostic information
Expand Down
2 changes: 1 addition & 1 deletion docs/maintainers/cve-process.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ Track sensitive reports privately from intake through resolution. Confirmed CVE/
**ModelAudit-specific impact factors**

- Does it allow arbitrary code execution when scanning a crafted model file? Treat as Critical.
- Does it expose secrets or credentials found during scanning? Treat as High.
- Does it allow unauthorized access to host secrets or credentials, or disclose them to unintended recipients? Treat as High. Intentional unredacted local output is accepted behavior under the [security policy](../../SECURITY.md#raw-local-output-no-redaction).
- Does it broadly bypass a common malicious-model detection, documented security guarantee, or CI/CD enforcement boundary? Usually treat as High.
- Is it a narrow scanner false negative in a niche format, platform-specific runtime path, or low-adoption feature? Usually treat as Low or Medium, or close as a detection-quality issue if the practical security impact is minimal.
- Is the vulnerable code only reachable via an optional dependency that is not installed by default? May reduce severity one tier.
Expand Down
1 change: 1 addition & 0 deletions docs/user/security-model.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ ModelAudit is a static security scanner for model artifacts. It analyzes files a
- It does not prove a model is safe. A clean scan means "no known indicators were found," not "risk is zero."
- It does not execute model behavior, so runtime-only backdoors and environment-triggered logic may not be visible.
- It does not replace environment hardening (sandboxing, network controls, least privilege, egress controls).
- It does not redact or mask local evidence, reports, diagnostics, logs, or cache metadata, including secrets and credentials. Raw output is intentional; see the [security policy](../../SECURITY.md#raw-local-output-no-redaction).
- Coverage depends on file format support and installed optional dependencies.

## Operational assumptions
Expand Down
Loading
Loading