Skip to main content
Scan results use the v3 report schema. The sections below describe the fields you typically use when reading CLI or API output. For the full schema, see the Get scan results API in the HiddenLayer Developer Portal (Console login required).
  • Detections — Known exploits in model files. Ranked from Critical to Low severity and usable in Supply Chain policy.
  • Advisories — Files or patterns of concern that are not exploits by themselves. Review before model usage.

Report structure

Summary fields

File results

Each entry in file_results describes one scanned file.

Detections

Present when a file triggers a detection rule.

Advisories

Informational findings that are not exploits by themselves (for example, tokenizer family or container manifest notes).

Type-specific evidence

file_results[].details.file_type_details includes extra fields for some model formats. Use these fields to understand format metadata that often contextualizes detections.
Not every file type populates file_type_details. Empty objects are normal for formats that do not expose additional metadata.