TwinEthosRequest access

Catalog

NIST SP 800-218A

NIST (U.S. Dept of Commerce) · pack 0.1.0 · verified against the official source as of 2026-10-01.

Standard / soft law

Acquired AI models and components should be verified and scanned before use and loaded safely (NIST SP 800-218A PW.4.4, PW.6.1)

NIST SP 800-218A asks that any model or model component an organization takes from elsewhere (weights, datasets, reward models, adapters, configuration) be checked for integrity, origin and security, and scanned and tested for vulnerabilities and malicious content, before it is used (PW.4.4), and it points to serialization formats that leave less room for malicious content (PW.6.1). Detect third-party model artifacts loaded without a pinned revision, without a hash or signature check, or through loaders that can execute code (pickle, joblib, torch.load with weights_only=False, trust_remote_code=True).

nist-sp800-218a.pw-4-4-verify-acquired-models · NIST SP 800-218A, PW.4.4 (R1, R2) + PW.6.1 (C1): verify acquired AI models before use; secure model serialization · official source · jurisdictions: *

Standard / soft law

AI model inputs and outputs should be validated and encoded so they cannot execute unauthorized code (NIST SP 800-218A PW.5.1)

NIST SP 800-218A applies the SSDF secure-coding task PW.5.1 to AI: prompts, user data and model output are all treated as input to be recorded, checked against what the model's context allows, and cleaned or discarded when they fail, and they are encoded so that nothing going into or coming out of a model can run as unauthorized code. Detect model or agent output that reaches an interpreter or renderer (eval or exec, a shell, a SQL query, HTML or Markdown rendering that allows raw HTML or remote images, a file path) without schema validation and encoding or parameterization for that sink.

nist-sp800-218a.pw-5-1-model-io-handling · NIST SP 800-218A, PW.5 / PW.5.1 (R1-R3): secure coding for AI model inputs and outputs · official source · jurisdictions: *