[D] Do you check a repo's auto_map before you load a new model?
when you grab a new fine-tune or merge, do you actually look at the config.json first?
I read an Unsloth Studio post last week which made me think about this a bit. Just selecting a model in the picker ran Python from the repo, because the capability check called AutoConfig with trust\_remote\_code on. No weights loaded, no inference. I believe it's fixed in 2026.6.9, so this isn't a dunk on Unsloth. It's more that "I'm only looking at it" turned out to be code execution.
GGUF through llama.cpp mostly avoids the Python part. Anything going through transformers can bring its own code.
So what's the best path? Pin a commit hash? Grep for auto\_map and .py files? A separate box for anything new? Or download counts and vibes?
scorecomments5 sightings
first seen 2026-10-06 15:47 UTClast seen 2026-10-08 19:41 UTCscore then 2score now 3gained +1sightings 5
open on reddit ↗
💬 4 (+3)