ML/LLM supply-chain attacks
SkillDatabases & dataAttack the ML/LLM supply chain, poisoned models, datasets, plugins, and unsafe model deserialization. Load when an app loads third-party models/weights (HuggingFace, .pt/.pkl/.h5), installs ML deps, uses plugins/extensions, or fine-tunes on external data. Signals: torch.load, pickle model files, model hub downloads, plugin marketplace, RAG over external corpora.
Use ML/LLM supply-chain attacks in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add ML/LLM supply-chain attacks and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the ML/LLM supply-chain attacks skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/ai-ml/ai-supply-chain/SKILL.md and read by Ahel’s review.
When it applies
The target consumes third-party ML artifacts: downloaded model weights, datasets, tokenizers, plugins/extensions, or fine-tuning data. Each is code or data that runs with the app's trust.
Why it works
Model files are frequently pickle-based (torch.load, .pkl, joblib) — loading them executes
arbitrary code (__reduce__), so a malicious model on a hub is RCE on whoever loads it. Datasets
and RAG corpora poison behavior; plugins/extensions run with the assistant's privileges; typosquatted
ML packages inject code at install.
Method
- Unsafe model deserialization (RCE): if the app
torch.load/pickle.loads a model you can supply or influence, craft a pickle with a__reduce__payload (fickling), or scan a suspect model (fickling,modelscan) for embedded code. Prefer safetensors as the safe alternative. - Model/dataset poisoning: contribute or substitute a model/dataset that carries a backdoor (trigger phrase → attacker-chosen output) or degrades safety — relevant when the app auto-pulls "latest" from a hub or fine-tunes on user/external data.
- Plugin / extension abuse: a malicious or over-permissioned plugin the assistant loads →
data access, tool abuse (→
ai-agent-tool-abuse). - Dependency attacks: typosquat/dependency-confusion on ML packages (→
web-dependency-confusion); compromisedrequirements. - Provenance checks: verify signatures/hashes, pinned versions, and safetensors usage.
Gotchas
.pt/.bin/.pkl= code execution on load;.safetensors= data only. The file format is the tell.- Auto-updating to a hub's "latest" model/plugin is the poisoning entry point — flag it.
- Prove RCE with a benign payload (OOB callback), never a destructive one; mind scope/RoE.
Verify success
Code execution when a crafted model/artifact is loaded (OOB beacon), a demonstrated backdoor trigger, or a poisoned dependency/plugin executing in the app's context.
References
OWASP LLM Top 10 (2025) LLM03/LLM04; fickling & modelscan; safetensors; "pickle is not secure".
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
ai-supply-chain- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · stbenjam
The pick for Dependenciesauditing-python-dependencies
Skill · jeremylongshore
The pick for Dependenciessupply-chain-risk-auditor
Skill · trailofbits
The pick for Supply Chainsupply-chain-digital-twin
Skill · a5c-ai
The pick for Supply Chainanalytics
Skill · coreyhaines31
More in Databases & datasupabase
Skill · supabase
More in Databases & data