Broad capability surfaceEmail addresses presentPhone number presentPotentially unbounded loop
scanned 1mo ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓
Stanford Alpaca
Code, documentation, and the instruction-following dataset behind Stanford's Alpaca models, which fine-tuned LLaMA on 52K instruction–response pairs generated via self-instruct.
The repository includes the dataset, the data-generation pipeline, and training details, and was highly influential in the open instruction-tuning wave.
Apache-2.0 licensed; a foundational reference dataset for instruction tuning and alignment research.
! Security: Review · 7575/100 · grade Bscanned 1mo ago
✓ no compromise signals5 risk-surface · 8/20 OWASP controls flagged
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
Data card · high confidence (static)
jsontxtjsonl
PII surface: Email addresses present, Phone number present
22 files
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
OWASP Top 10 for LLM Applications
⚠LLM03Supply Chaincritical
Vulnerable/compromised dependencies, models or archives in the artifact.