ML/LLM supply-chain attacks
SkillDatabases & dataAttack the ML/LLM supply chain, poisoned models, datasets, plugins, and unsafe model deserialization. Load when an app loads third-party models/weights (HuggingFace, .pt/.pkl/.h5), installs ML deps, uses plugins/extensions, or fine-tunes on external data. Signals: torch.load, pickle model files, model hub downloads, plugin marketplace, RAG over external corpora.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the ML/LLM supply-chain attacks skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/ai-ml/ai-supply-chain/SKILL.md and read by ahel’s review.
When it applies
The target consumes third-party ML artifacts: downloaded model weights, datasets, tokenizers, plugins/extensions, or fine-tuning data. Each is code or data that runs with the app's trust.
Why it works
Model files are frequently pickle-based (torch.load, .pkl, joblib) — loading them executes
arbitrary code (__reduce__), so a malicious model on a hub is RCE on whoever loads it. Datasets
and RAG corpora poison behavior; plugins/extensions run with the assistant's privileges; typosquatted
ML packages inject code at install.
Method
- Unsafe model deserialization (RCE): if the app
torch.load/pickle.loads a model you can supply or influence, craft a pickle with a__reduce__payload (fickling), or scan a suspect model (fickling,modelscan) for embedded code. Prefer safetensors as the safe alternative. - Model/dataset poisoning: contribute or substitute a model/dataset that carries a backdoor (trigger phrase → attacker-chosen output) or degrades safety — relevant when the app auto-pulls "latest" from a hub or fine-tunes on user/external data.
- Plugin / extension abuse: a malicious or over-permissioned plugin the assistant loads →
data access, tool abuse (→
ai-agent-tool-abuse). - Dependency attacks: typosquat/dependency-confusion on ML packages (→
web-dependency-confusion); compromisedrequirements. - Provenance checks: verify signatures/hashes, pinned versions, and safetensors usage.
Gotchas
.pt/.bin/.pkl= code execution on load;.safetensors= data only. The file format is the tell.- Auto-updating to a hub's "latest" model/plugin is the poisoning entry point — flag it.
- Prove RCE with a benign payload (OOB callback), never a destructive one; mind scope/RoE.
Verify success
Code execution when a crafted model/artifact is loaded (OOB beacon), a demonstrated backdoor trigger, or a poisoned dependency/plugin executing in the app's context.
References
OWASP LLM Top 10 (2025) LLM03/LLM04; fickling & modelscan; safetensors; "pickle is not secure".
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
ai-supply-chain- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · stbenjam
The pick for Dependenciesreview-dependencies
Skill · tobihagemann
The pick for Dependenciessupply-chain-risk-auditor
Skill · trailofbits
The pick for Supply Chaincompetition-supply-chain
Skill · alicewe1
The pick for Supply Chainowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)