Scanning a single file
Use the AI Supply Chain Security CLI to scan a single file stored locally on your system.Local setup
-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. -
The model to be scanned is on the host machine at path
/home/user/models/. Change this path to match your system. -
The model to be scanned is named
my_model.keras. Change this name to match the file you want to scan. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.--persistadds the scan results to an existing model in the HiddenLayer Console.--model-nameand--model-versionare the name and version number that appear in the Supply Chain.
Container execution
Output Example - STDOUT
Scan results will be JSON-minified, but are shown formatted here for readability.EXPAND to see an example for scan results.
EXPAND to see an example for scan results.
Scanning a directory
Use the Supply Chain CLI to scan all files in a directory that is stored locally on your system.Local Setup
-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. -
The models to be scanned are on the host machine at path
/home/user/models/. Change this path to match your system. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.
Container execution
Output Example - STDOUT
Scan results will be JSON-minified, but are shown formatted here for readability.EXPAND to see an example for scan results.
EXPAND to see an example for scan results.
Globbing File Paths
PreviewThis feature is in Preview.
- Scan all
.pklfiles in the current directory and all subdirectories:--input . --include-pattern "*.pkl" - Scan all files in the directory tree rooted at the directory models, excluding
.txtfiles:--input ./models --exclude-pattern "*.txt" - Scan all
.onnxfiles in the directory tree rooted at the current working directory, except those labeled with a “v1” in the name:modelscan-cli . --include-pattern "*.onnx" --exclude-pattern "*v1*" - Scan all files except
.jsonand.txtfiles in the current directory and all subdirectories:--input . --exclude-pattern "*.json" --exclude-pattern "*.txt" - Scan all files in the current directory and all subdirectories that start with
pytorch_model-:--input . --include-pattern "pytorch_model-*.bin"
Azure Blob Storage
URL for Single Blob with Shared Access Signature
An HTTPS URL with a shared access signature can be used with the —input parameter, but only a single blob is supported.Blob Enumeration
Multiple blobs in a single container can be scanned by using a wasbs:// URI with the —input parameter. The URI should be of the following form: wasbs://your-container-name@your-storage-account.blob.core.windows.net/your-optional-prefix Depending on the storage configuration, credentials may be required. Set the following environment variables:AZURE_TENANT_IDAZURE_CLIENT_IDAZURE_CLIENT_SECRET
Download Model from Azure
If none of the previous methods are suitable, the model can be downloaded from Azure, then scanned using the Supply Chain CLI’s support for local files. This example uses the Azure CLI to download the file. To install the Azure CLI, see the Azure documentation. After installing the Azure CLI, configure authentication for the Azure CLI.Download a Model from Azure to Local
- Replace
<storage-account>with the name of the Azure storage account. - Replace
<container>with the name of the Azure Blob container. Replace<model-name>with the file name you are downloading. - Replace
<~/destination/path/for/file>with the path and file name for your local storage (example:~/Downloads/pytorch_model.bin).
Scan Model from Amazon S3
Presigned URL for Single Object
An HTTPS URL that is presigned can be used with the--input parameter, but only a single object is supported.
-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. -
Replace
presigned_urlwith your AWS S3 presigned URL for the model file you want to scan. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.--persistadds the scan results to an existing model in the Supply Chain.--model-nameand--model-versionare the name and version number that appear in the Supply Chain.
Bucket Enumeration
Multiple objects in a single bucket can be scanned by using as3:// URI with the --input parameter.
The URI should be of the following form: s3://some-bucket/some-optional-prefix
Depending on the bucket policy, AWS credentials may be required.
-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. -
Replace
AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY,AWS_SESSION_TOKEN,AWS_REGION, andAWS_ENDPOINTwith your AWS information. -
Replace
s3://some-bucket/some-optional-prefixwith your AWS S3 bucket information for the bucket you want to scan. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.
Scan Model from Google Cloud Storage
Multiple objects in a single bucket can be scanned by using ags:// URI with the --input parameter.
-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. - Create a credentials file (credentials.json) for the service account. See Google documentation for more information.
-
Replace
gs://some-bucket/some-prefixwith your Google storage information for the bucket you want to scan. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.
Scan a Hugging Face Repository
Scan the files within a Hugging Face repository by providing the Hugging Face repository URL in the scan request. Example:https://huggingface.co/username/repo_name.
When scanning a Hugging Face repository, the Supply Chain CLI will:
- Identify and download all files within the specified repository.
- Perform the scanning process on each downloaded file, according to the standard scanning rules and logic of the Supply Chain CLI.
- Generate a scan report.
Hugging Face Repository
Use the following command to scan a Hugging Face repository.-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. -
Replace
<username>/<repo_name>with the appropriate Hugging Face repository information. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.--persistadds the scan results to an existing model in the Supply Chain.
Private or Gated Hugging Face Repository
To scan a private or gated Hugging Face repository, include the Hugging Face token as an environment variable in the scan request.-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. -
Replace
<username>/<repo_name>with the appropriate Hugging Face repository information. -
Replace
<hf-token>with the Hugging Face token for the private or gated repository. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.--persistadds the scan results to an existing model in the Supply Chain.
Scan a NIM Container
Scan a NVIDIA NIM container image using anoci://nvcr.io/nim/... input. NIM container scanning is available in Supply Chain version 26.6.0 and later. See NIM Container Scanning for manifest parsing, referenced models, and follow-up scan workflows.
Local setup
-
HL_LICENSEis your HiddenLayer product license as an environment variable. See Running Supply Chain CLI for information about setting the HiddenLayer environment variables. -
NGC_API_KEYis required to pull NIM images from NVIDIA’s container registry. Create an API key in the NGC portal. -
Replace
oci://nvcr.io/nim/nvidia/test-model:latestwith the NIM image reference you want to scan. -
For Disconnected Mode:
- The scan results are saved at path
/home/user/results. Change this path to match your system.
- The scan results are saved at path
-
For Hybrid Mode:
HL_CLIENT_IDandHL_CLIENT_SECRETare the API key and secret to allow communication with the HiddenLayer AI Security Platform.--persistadds the scan results to an existing model in the HiddenLayer Console.--model-nameand--model-versionare the name and version number that appear in the Supply Chain.

