SECOND MEASUREMENT SM-010

Hugging Face says every file goes through its malware scanner. Nothing over 2 GB does, and the badge says safe anyway

Markovian ProtocolMeasured 2026-10-02Status: sent to Hugging Face 2026-10-02, response pendingDOI: 10.5281/zenodo.23123005

Hugging Face’s documentation says every file in every repository goes through a malware scanner at each commit, within minutes. We read the per-file scan status Hugging Face itself publishes on 3,038 files across 450 repositories, including the 150 most-downloaded models. Under 2 gigabytes the claim holds: 2,539 of 2,551 files scanned. At 2 gigabytes and above it stops: 0 of 487. Those are the model weights, 89% of the bytes in the sample and 92% in the top models, and 476 of the 494 files the scanner never read wear a green “safe” badge.

The short version

Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisation measured. How we work.

Details

Every file on the Hugging Face Hub carries a security status that the website shows as a badge and the API returns as a field, securityFileStatus, with one entry per scanner: Hugging Face’s own malware scanner (avScan, ClamAV according to the documentation), its pickle-import scanner, and partner scanners from Protect AI, JFrog and VirusTotal. The overall badge is a roll-up. We drew 450 repositories: the 150 most-downloaded models, the 150 most-downloaded datasets, and 150 models picked at random from recently updated ones. For each we listed the root directory with the API’s expand option, which returns the status fields, and kept files committed at least a day earlier. 54 files in three gated repositories (two meta-llama models and one dataset) can’t be read without accepting terms and were left out. Every file the listing called unscanned or left blank was looked up again through a second endpoint, paths-info; the two agreed on 479 of 483 unscanned verdicts; the other 4 were in gated repositories, and most blanks (105 of 121 readable) turned out to be listing gaps; 15 came back unscanned and are counted, so the counts here use the second answer.

What they said, what we found

Hugging Face saidWe found
Hugging Face, pull request huggingface_hub#2397, July 2024: “ClamAV scans files of up to 3.9GB. By lowering the shard size, we can ensure files are scanned.” A user asked on the Hub forum in August 2023 how files over 2 GB were scanned at all.4The cut we measured is 2 GiB, not 3.9 GB: 0 of 487 files at 2 GiB or more carry a scan result. The limit was known inside Hugging Face in 2024; the badge did not change.
“We run every file of your repositories through a malware scanner. Scanning is triggered at each commit.”1Under 2 GiB: 2,539 of 2,551 files scanned. 2 GiB and over: 0 of 487, including every weight file in the most-downloaded models.
“It can take up to a few minutes to be scanned.”1The skipped files were committed between 15 days and 6.8 years before the run. The oldest dates from December 2019.
“If at least one file has a been scanned as unsafe, a message will warn the users” (sic)1476 of the 494 skipped files show the “safe” badge; 12 show “unscanned”; 6 show “queued”.
JFrog: “Model files are scanned by the JFrog scanner and we expose the scanning results on the Hub interface.”249 of the 1,132 files older than a year that carry a JFrog status are still “queued”, including five files in GPT-2 committed in 2019, 2020 and 2021.

The cut-off

The malware scanner stops at 2 GiB, and the edge is sharp. Nothing above it is scanned; almost nothing below it is missed.

File sizeFilesScannedNot scanned
under 1 MB1,6991,6936
1 MB to 100 MB3483440
100 MB to 1 GB3423401
1 GB to 2 GB1451450
2 GB to 3 GB781761
3 GB to 5 GB2520252
over 5 GB1740174

Decimal gigabytes in the buckets; the cut sits at 2 GiB (2,147,483,648 bytes), which falls inside the 2 to 3 GB row. The 17 scanned files in that row are all below 2 GiB. Four files marked “suspicious” and one “error” are counted as neither.

Where the bytes are, by group:

GroupFilesNot scannedBytes not scannedRepositories with a skipped file
150 most-downloaded models1,95538892%55 of 149
150 most-downloaded datasets85610280%6 of 122
150 recently updated models, random227475%1 of 23

Repository counts are those with at least one readable file older than a day. Random recent models are small; most have no file near the limit.

The ten most-downloaded models by skipped volume:

RepositoryFiles not scannedVolumeBadge shown
unsloth/Qwen3-Coder-30B-A3B-Instruct-GGUF26 of 31445 GBsafe
unsloth/Qwen3.8-27B-GGUF24 of 30414 GBsafe
zai-org/GLM-5.3-Flash43 of 49231 GBsafe
ornith-ai/Ornith-1.5-35B-A3B-GGUF5 of 8185 GBqueued
deepseek-ai/DeepSeek-V3.240 of 47173 GBsafe
deepseek-ai/DeepSeek-V4-Flash-073142 of 48150 GBsafe
farbodtavakkoli/OTel-2.0-LLM-31B-IT28 of 39126 GBsafe
dphn/dolphin-2.9.1-yi-1.5-34b14 of 2468 GBsafe
prism-ml/Ternary-Bonsai-2-27B-gguf3 of 1067 GBsafe
Qwen/Qwen3-32B17 of 2766 GBsafe

Most of that is safetensors and GGUF, formats that hold numbers and cannot run code when loaded. The format that can is pickle, which PyTorch’s .bin files use. Seven of those in the sample are over the limit. The malware scanner never read them; Hugging Face’s separate pickle-import scanner did, and found only ordinary imports.

FileSizePickle scannerBadge
BAAI/bge-m3/pytorch_model.bin2.27 GBsafesafe
intfloat/multilingual-e5-large/pytorch_model.bin2.24 GBsafesafe
openai/whisper-large-v3/pytorch_model.bin3.09 GBsafesafe
openai/whisper-large-v3/pytorch_model.fp32-00001-of-00002.bin4.99 GBsafesafe
E-MIMIC/inclusively-reformulation-it5/pytorch_model.bin3.13 GBsafesafe
facebook/esm2_t33_650M_UR50D/pytorch_model.bin2.61 GBsafesafe
FacebookAI/xlm-roberta-large/pytorch_model.bin2.24 GBsafesafe

How this ends

It ends when the Hub scans files of 2 GiB and above, or when the documentation and the badge say that it doesn’t. The recheck re-reads the same 487 files; the day their status changes from “unscanned”, or the page says “not scanned” next to the badge, is the day this closes.

The evidence

Every quote below was copied from the source and checked against a saved copy, fetched 2026-10-02. The copies, the API responses, and the full sample with both readings per file are published next to this page (SHA256SUMS).

Exhibit 1 · The claim

“We run every file of your repositories through a malware scanner. Scanning is triggered at each commit. … If your file has neither an ok nor infected badge, it could mean that it is either currently being scanned, waiting to be scanned, or that there was an error during the scan. It can take up to a few minutes to be scanned.”

huggingface.co/docs/hub/security-malware · saved copy hf_security_malware.html

Exhibit 2 · openai/whisper-large-v3, the model’s own answer

POST /api/models/openai/whisper-large-v3/paths-info/main  {"paths": [...], "expand": true}

pytorch_model.bin   3,087,394,553 bytes   status: "safe"   avScan: "unscanned"
model.safetensors   3,087,130,976 bytes   status: "safe"   avScan: "unscanned"
config.json                 1,272 bytes   status: "safe"   avScan: "safe"

raw response whisper-large-v3-paths-info.json · the same for four of Qwen3-8B’s five weight shards; the fifth, 1.24 GB, is scanned: qwen3-8b-tree.json

Exhibit 3 · GPT-2, queued since 2019

openai-community/gpt2  64-fp16.tflite  committed 2019-12-12
  status: "queued"
  avScan: "safe"            protectAiScan: "safe"
  virusTotalScan: "safe"    jFrogScan: "queued"

raw response gpt2-paths-info.json; the same three calls returned the same answer

Exhibit 4 · Two endpoints, one answer

80 files re-read through paths-info:
  40 marked "unscanned" by the listing  ->  40 "unscanned"   (overall badge differed on 2)
  20 with no status in the listing       ->  12 "safe", 1 "unscanned", 7 gated (401)
  20 marked "safe"                       ->  18 "safe", 2 gated
Then every non-safe file (658) re-read the same way: 479 of 483 "unscanned" confirmed.

verify_paths_info.json · full sample with both readings: hf_scan_sample.json

Our questions to Hugging Face

Sent to security@huggingface.co and filed as huggingface/hub-docs issue 2850 on 2 October 2026. Answers will be printed here as written.

  1. Is 2 GiB a deliberate limit on the malware scanner? If so, can the documentation say so?
  2. Why does the overall badge show “safe” for a file the malware scanner has not read?
  3. Are large pickle-format files, such as the seven PyTorch .bin files over 2 GiB here, covered by any scanner other than the pickle-import check?
  4. JFrog shows “queued” on files committed in 2019. Is that queue still being worked, or is it abandoned?
  5. Do Enterprise Hub customers get a different size limit?

Their reply, scored

Waiting for a reply. When it comes, each question gets marked answered, partly answered or not answered, and the reply goes here in full.

Disclosure timeline

2 OctPublished; sent to Hugging Face with the five questions above, as huggingface/hub-docs issue 2850 and by email to security@huggingface.co.

Waiting on Hugging Face since 2 Oct.

What we can’t be sure of

Run it yourself

Python 3 standard library. About half an hour against the public API; no token needed except for gated repositories, which this skips.

python3 hf_scan_sample.py          # 450 repositories, root listings with expand=true
python3 hf_requery.py              # paths-info for every non-safe file, then the tables

Reproduced from the public repository on 3 October 2026 on a clean machine, on a fresh sample: holds (0 of 688 files of 2 GiB or more scanned; 2,502 of 2,801 smaller files safe; 519 unscanned files behind a safe badge). Full table on the track record.

What you can do with this

References

  1. Hugging Face. Malware Scanning. huggingface.co/docs/hub/security-malware.
  2. Hugging Face. Third-party scanner: JFrog. huggingface.co/docs/hub/security-jfrog; Third-party scanner: Protect AI; Pickle Scanning.
  3. Hugging Face Hub API: GET /api/{models|datasets}/{repo}/tree/main?expand=true, POST /api/{models|datasets}/{repo}/paths-info/main.
  4. huggingface/huggingface_hub, pull request #2397, “Reduce max shard size”, July 2024; Hugging Face forum, ClamAV - Scanning Files Larger than 2GB, August 2023. Saved copies in the exhibits.

Cite as

@misc{markovian-sm010,
  author = {{Markovian Protocol}},
  title  = {Hugging Face malware scanning by file size, October 2026},
  number = {SM-010},
  doi    = {10.5281/zenodo.23123005},
  year   = {2026},
  month  = oct,
  url    = {https://markovianprotocol.com/measurements/sm-010.html}
}