T03 · Remote Payload Retrieval and Execution
- Location
references/troubleshooting.md:35- Finding
Untrusted Model Repository Code Execution via trust_remote_code
- Content
View full analysis
Vulnerability Details
File Location:
references/troubleshooting.md, lines 35–44
Vulnerability Type: Execution of remotely supplied model code
Risk Level: HighVulnerable code:
markdown ### Issue: trust_remote_code required **Symptom:** `OSError: xxx requires trust_remote_code=True` **Solution:** ```python from transformers import AutoModel, AutoTokenizer model = AutoModel.from_pretrained(path, trust_remote_code=True)text The related workflow in `SKILL.md`, lines 75–84, permits a model repository identifier as input and instructs the agent to download model-local implementation files when they are absent locally. ### Technical Analysis Setting `trust_remote_code=True` instructs Transformers to load and execute custom Python implementation code supplied by the selected model repository. The repository provider therefore controls executable code that runs in the local Python process. This crosses the trust boundary between externally supplied model artifacts and the agent's local execution environment. The Skill's stated purpose only requires static inspection of configuration and implementation files; executing model-provided Python is unnecessary for that analysis. The documented troubleshooting instruction does not require source review, repository revision pinning, isolation, restricted credentials, or explicit informed approval before execution. ### Attack Path 1. An attacker publishes or controls a model repository containing a configuration that references custom model implementation code. 2. A user or agent selects that repository for compatibility analysis. 3. The normal workflow obtains the repository's configuration or model-local implementation files. 4. Model loading reports that `trust_remote_code=True` is required. 5. The agent follows `references/troubleshooting.md` and invokes `AutoModel.from_pretrained(path, trust_remote_code=True)`. 6. Transformers imports and executes the repository-controlled Python code ...[truncated 692 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the recommendation to use
trust_remote_code=True. - Analyze model-local implementation files statically without importing or executing them.
- Download only the configuration, index, and source files required for inspection; do not instantiate the remote model.
- If execution is indispensable, require explicit informed user approval identifying that repository-controlled Python will run.
- Execute such code only inside a disposable sandbox or container with:
- No host credentials or secrets.
- No writable host mounts.
- No elevated privileges.
- Network access disabled by default.
- Strict CPU, memory, and runtime limits.
- Pin the model repository to an immutable revision and review the exact source at that revision before execution.
- Treat
auto_mapand all model-local Python modules as untrusted input, and stop the analysis when safe static inspection is insufficient.
- Remove the recommendation to use
