qwen2.5-14b-instruct-abliterated-v2
A real read — read offline against the base, never run. The verdict is reproducible.
◆ Vulcora caught it — offline, against its base, with proof
Vulcora reads the weights- modelauditpromptfooserialization exploit
reads manifests, configs, embedded templates & safetensors
heuristic auditing of a model repo for suspicious files, chat-template SSTI, non-allowlisted pickle globals, and license/provenance smells; a broad repo linter, not a weight-tampering detector.
artifact-only here: README/prose withheld (see policy)
- model-signingOpenSSF / Sigstoreprovenance
reads Sigstore signature bundles
verifying a cryptographic provenance signature over model files; it can only attest what a publisher signed.
requires a published Sigstore bundle; no scanned model ships one
The 3 tools run here found nothing of the kind they read — this model doesn’t ship that kind of file. That is not a clearance. Vulcora read the weights themselves, offline, and never ran the model.
Think this verdict is wrong?
Signed-in users can formally refute a read — Vulcora re-reads the model against your claim and records the outcome. You'll need an account to file one.
Refutations are actor-gated — a guest can't file one.
Want a verdict you can prove — on your own model?