Every target moves through the same five stages. Nothing under inspection is loaded, imported, or executed at any point.
Pulled from Hugging Face, GitHub, Ollama, npm, PyPI, or a local path into an isolated, read-only quarantine.
Read as bytes and AST only: pickle opcodes, tensor headers, source syntax, manifest JSON. Never unpickled, never imported, never run.
Malware, dataset poison, and LLM/Agent/MCP detectors run over the parsed structure in parallel.
Every finding gets a severity and a policy check against your --fail-on
threshold.
A verdict and exit code, plus table, JSON, or SARIF output for your pipeline.
Every screen below is an actual amara run session, not a mockup.
Every model format AMARA supports is walked structurally, never loaded, pickle opcodes, Keras layer graphs, ONNX/TF/TFLite graph ops, and archive members.
Allowlist-first pickle walker, every global is suspicious until proven safe, with the real payload shown
Catches Keras/TF/TFLite layers that run code at load time, and ONNX path traversal before the graph loads
Zip-Slip, symlink tricks, decompression bombs, and pickles hidden past an archive's declared end
Datasets are first-class, not an afterthought. File-safety and provenance
checks run by default; opt in with dataset-scan for row-level content
analysis.
AST-parses loader scripts, never executes them, to catch shell-out, eval, and unsafe deserialization
Detects embedded pickles/executables in Parquet, Arrow, and TFRecord shards, plus PII in row content
Scores rows for backdoor-trigger tokens, label anomalies, and outliers; flags unpinned fetches
Weights are only half the AI supply chain, the other half is the code
that decides what the LLM is wired up to do. Three independent flags cover it, or
run --full-scan for everything at once.
LLM ScanLLM output executing in shell, SQL, or deserializer; Hardcoded API keys; Untrusted Content in a Prompt
Agent Scan Shell tools handed to an Agent, Unbounded Loops, and Injection hidden in agent-readable documents
MCP Scan Launches shell commands, Unpinned Packages, Auto-Approved Tools, and Hardcoded API keys