← All scansHugging Face model
HuggingFaceTB

SmolLM2-135M-Instruct

Under reviewRead against its base — the signed verdict is "abstain", not a clearance.
#abstained
assessed Jul 2026read offline · never run
Book the real read

Under review · HuggingFaceTB/SmolLM2-135M-Instruct WAS read against its base, offline and never run — but the signed dossier Vulcora publishes for it reads "abstain", which is not an absence, so no verdict is claimed here either way: not a clean bill of health, and not an accusation. Check us yourself: https://api.vulcora.se/api/attestations/HuggingFaceTB/SmolLM2-135M-Instruct.

◆ Vulcora read it — and declined to rule. No matched benign reference resolved a verdict, so it is held, not cleared

Vulcora reads the weights
Off-the-shelf tools · run on this model1 of 4 that could read it raised a flag — read each row’s base rate before taking it as a catch
Capability — not run on this modelwhat these tools read and what question they answer — not a result
  • model-signingOpenSSF / Sigstoreprovenance

    reads Sigstore signature bundles

    verifying a cryptographic provenance signature over model files; it can only attest what a publisher signed.

    requires a published Sigstore bundle; no scanned model ships one

4 off-the-shelf tools could read this model’s serialized files, and 1 raised a flag — each row carries the tool’s base rate. None of them reads what the weights mean: they hunt load-time code-execution, repo smells, or a provenance signature — real jobs, none of which is weight-level tampering. Vulcora read the weights and declined to rule — held, not cleared.

Couldn't reach the attestation service to re-verify just now.

Details

from the artifact’s public metadata
Architecture
smollm2
Base
huggingfacetb/smollm2-135m
License
apache-2.0
Parameters
135M

Think this verdict is wrong?

Signed-in users can formally refute a read — Vulcora re-reads the model against your claim and records the outcome. You'll need an account to file one.

Refutations are actor-gated — a guest can't file one.

Cited in a research corpus

someone else’s label — not Vulcora’s live verdict

This model appears as a labelled specimen in a public benchmark corpus. Each panel below states the benchmark authors’ own published ground-truth label and, where the research harness actually ran, its coarse readout — distinct from the Vulcora verdict above.

  • HuggingFace publisher-declared modifications specimen · huggingfacetb/smollm2-135m-instruct
    Benchmark’s published labelclean
    Research-harness readcited label · harness not yet run

    Published-benchmark / research-harness record (benchmark_import). Not a Vulcora live scan — it is the corpus’s statement about this model, shown here for provenance.

Want a verdict you can prove — on your own model?