Five checks you can do by hand before you download the weights — and where RepoGates answers them for you.
The short answer. Nobody can tell you a model is safe, and a tool that says so is overclaiming. What you can tell in five minutes is whether it is trustworthy enough to download: what format its weights are in, whether loading it runs the publisher's code, what the Hub's own scans found, who published it, and whether its popularity fits its age.
A model file is not only numbers. Weights saved as a Python pickle can run code the moment they are loaded, and a model that needs trust_remote_code runs the publisher's Python on your machine by design. In February 2024 JFrog reported roughly 100 models on the Hub whose pickle files ran attacker code on load; in February 2025 ReversingLabs' "nullifAI" found two that used a corrupted pickle stream to get past the Hub's own scanner. Hugging Face removes these after researchers report them; the question is what you can see before you download.
1. What format are the weights in? Open the Files tab. A .safetensors file holds tensors and nothing else. A .bin, .pt, .pth, .ckpt or .pkl file is usually a pickle, which can carry code. Pickle beside a safetensors copy is ordinary; pickle only is worth a second look — 14 of the 100 most-downloaded models ship that way, so it is a warning, not a verdict.
2. Does loading it run the publisher's code? Python files in the repository, or an auto_map entry in config.json, mean the model needs trust_remote_code=True. That flag runs those files as you load. Read them first, and pin the revision you read. For a dataset, a loading script is the same question.
3. What did the Hub's own scans say? The Files tab marks a file the Hub's malware or pickle-import scan flagged. A flag on an import such as os, subprocess or socket is serious. The absence of a flag is not a clearance: Hugging Face calls these scans best-effort, and a scan that never finished shows no warning either.
4. Who published it, and is the name borrowed? Compare the organisation with the one you meant — a lookalike of a well-known lab is the oldest trick on any registry. A new account publishing weights under a famous model's name deserves more doubt than the same account publishing its own experiment.
5. Do its downloads fit its age, and does it say what it is? A repository a few days old with a vast download count is the shape of bought traction. A model card and a licence are the minimum an honest publisher writes; their absence alone proves nothing, and on a new repository it adds to the doubt.
RepoGates scores a Hugging Face model, dataset or Space on 18 published checks, the five above among them. It answers in three places. In your browser, the extension draws the score and the findings on the model, dataset or Space page on huggingface.co, and holds a weights file you download through the browser until the verdict is in. For your AI agent, the MCP server answers check_repo with the Hugging Face platform before the agent suggests a model. In Claude Code, the plugin's hook reads git clone https://huggingface.co/…, hf download and huggingface-cli download before the Bash tool runs them. On the 100 most-downloaded models, 72 pass, 28 are flagged for review and none is blocked; the named malicious models from both reports are on the intelligence page, with what the checks found on each.
The plugin's hook sees Bash tool calls in Claude Code and nothing else: it does not see a command you type in your own terminal or one another agent runs. A Python from_pretrained() call is never a shell line any hook sees, and the browser extension does not see a Python process, pip install or huggingface_hub. The checks read the repository's record, its file list and the Hub's own scan results, not the weights; a deep scan of a Hugging Face model is on the roadmap, not built. A PASS means every check that could run, ran, and none fired — never a guarantee, and never a claim about a revision uploaded tomorrow.
If the Hub's scan shows nothing, is the model clean? No. Hugging Face calls its own scans best-effort, and in February 2025 two models slipped past them with a deliberately corrupted pickle stream. A missing warning is the absence of a finding, not a clearance.
Does RepoGates check a model my Python code loads with from_pretrained()? No. A from_pretrained() call is never a shell line any hook sees, and the browser extension does not see a Python process. Check the model on its page, or ask through the MCP server, before the code that loads it runs.
Does RepoGates read the weights themselves? No. The 18 checks read the repository's record, its file list and the Hub's own per-file scan results, not the weights. A deep scan of a Hugging Face model is decided but not built yet.
Install the browser extension Set up the Claude Code plugin Plans
The MCP server and the Claude Code plugin need a paid plan. Numbers on this page: the 100 most-downloaded models on the Hub, measured 12 September 2026; the campaigns as JFrog (February 2024) and ReversingLabs (February 2025) published them.