Products Lemma APIProof issuance & verification platformTrust402Delegate to agents, and transactSealSign-in for the agent era — no keys handed over
Use cases Manufacturing & Critical InfraInspection Record AssuranceFinance & FinTechCounterparty Record VerificationPublic SectorCertificate-less ProceduresHealthcareQualified Worker AssuranceProcurement & Supply ChainSupplier Credential MonitoringMedia & ContentContent AuthenticityService & RetailCross-group IdentityAI Adoption (cross-industry)AI Run GovernanceDevelopers & Agent OpsAgent Authority Control ▸ Browse the use-case index
Pricing
Resources Critical BriefThe frontier of AI × trustBlogThinking and implementation notesDocumentationAPI & specsVerification CenterReal verification & issuance countsAbout usFRAME00, Inc.ContactSales & press inquiriesNewsletterUpdates by emailGlossaryDefinitionsFAQFrequently asked questions
Get Started ↗ JA
Home / Critical Brief / Category archive
Lemma Critical Brief · Category archive

Model Supply Chain

Poisoned model weights, backdoored checkpoints, evaluation-data contamination.

6 Briefs
No. 121 · 2026-08-04

"FaceHugger" in Hugging Face Diffusers: loading a model ran arbitrary code

the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)

Pillar 02 Verifiable AI Model Supply Chain Code ProvenanceAgent Infrastructure Brief →
No. 116 · 2026-07-31

A fake OpenAI model hit #1 trending on Hugging Face

publisher provenance never verified before execution

Pillar 02 Verifiable AI Model Supply Chain Code ProvenanceIdentity & Auth Brief →
No. 090 · 2026-06-30

AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents

the Blind Spot Was an External Link Mutable After the Scan

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureIdentity & AuthModel Supply Chain Brief →
No. 072 · 2026-06-19

Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel

deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)

Pillar 03 Agent Authority Proof Agent Infrastructure Identity & AuthCode ProvenanceModel Supply Chain Brief →
No. 073 · 2026-06-19

ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks

the same flaw spread at ecosystem scale through reuse (Oligo Security)

Pillar 03 Agent Authority Proof Agent Infrastructure Code ProvenanceIdentity & AuthModel Supply Chain Brief →
No. 048 · 2026-06-12

TrapDoor Plants Hidden Directives in AI Assistant Instruction Files Across npm, PyPI, and Crates.io

Pillar 01 Verifiable Origin Code Provenance Agent InfrastructureAI Decision IntegrityModel Supply Chain Brief →