Instructions to use dr3x1/jevsec with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- llama.cpp
How to use dr3x1/jevsec with llama.cpp:
Install (macOS, Linux)
curl -LsSf https://llama.app/install.sh | sh # Start a local OpenAI-compatible server with a web UI: llama serve -hf dr3x1/jevsec:Q8_0 # Run inference directly in the terminal: llama cli -hf dr3x1/jevsec:Q8_0
Install from WinGet (Windows)
winget install llama.cpp # Start a local OpenAI-compatible server with a web UI: llama serve -hf dr3x1/jevsec:Q8_0 # Run inference directly in the terminal: llama cli -hf dr3x1/jevsec:Q8_0
Use pre-built binary
# Download pre-built binary from: # https://github.com/ggerganov/llama.cpp/releases # Start a local OpenAI-compatible server with a web UI: ./llama-server -hf dr3x1/jevsec:Q8_0 # Run inference directly in the terminal: ./llama-cli -hf dr3x1/jevsec:Q8_0
Build from source code
git clone https://github.com/ggerganov/llama.cpp.git cd llama.cpp cmake -B build cmake --build build -j --target llama-server llama-cli # Start a local OpenAI-compatible server with a web UI: ./build/bin/llama-server -hf dr3x1/jevsec:Q8_0 # Run inference directly in the terminal: ./build/bin/llama-cli -hf dr3x1/jevsec:Q8_0
Use Docker
docker model run hf.co/dr3x1/jevsec:Q8_0
- LM Studio
- Jan
- Ollama
How to use dr3x1/jevsec with Ollama:
ollama run hf.co/dr3x1/jevsec:Q8_0
- Unsloth Desktop
- Pi
How to use dr3x1/jevsec with Pi:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf dr3x1/jevsec:Q8_0
Configure the model in Pi
# Install Pi: npm install -g @earendil-works/pi-coding-agent # Add to ~/.pi/agent/models.json: { "providers": { "llama-cpp": { "baseUrl": "http://localhost:8080/v1", "api": "openai-completions", "apiKey": "none", "models": [ { "id": "dr3x1/jevsec:Q8_0" } ] } } }Run Pi
# Start Pi in your project directory: pi
- Docker Model Runner
How to use dr3x1/jevsec with Docker Model Runner:
docker model run hf.co/dr3x1/jevsec:Q8_0
- Lemonade
How to use dr3x1/jevsec with Lemonade:
Pull the model
# Download Lemonade from https://lemonade-server.ai/ lemonade pull dr3x1/jevsec:Q8_0
Run and chat with the model
lemonade run user.jevsec-Q8_0
List all available models
lemonade list
- Hermes Agent
How to use dr3x1/jevsec with Hermes Agent:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf dr3x1/jevsec:Q8_0
Configure Hermes
# Install Hermes: curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash hermes setup # Point Hermes at the local server: hermes config set model.provider custom hermes config set model.base_url http://127.0.0.1:8080/v1 hermes config set model.default dr3x1/jevsec:Q8_0
Run Hermes
hermes
- Atomic Chat
- OpenClaw
How to use dr3x1/jevsec with OpenClaw:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf dr3x1/jevsec:Q8_0
Configure OpenClaw
# Install OpenClaw: npm install -g openclaw@latest # Register the local server and set it as the default model: openclaw onboard --non-interactive --mode local \ --auth-choice custom-api-key \ --custom-base-url http://127.0.0.1:8080/v1 \ --custom-model-id "dr3x1/jevsec:Q8_0" \ --custom-provider-id llama-cpp \ --custom-compatibility openai \ --custom-text-input \ --accept-risk \ --skip-health
Run OpenClaw
openclaw agent --local --agent main --message "Hello from Hugging Face"
jevsec — a fine-tuned decision model for security triage
Current release: jevsec-003 (file jevsec-003-q8_0.gguf; the second iteration stays in the
repository history). A LoRA fine-tune of XHToken/Spark-X2.5-4B
(Apache-2.0) that answers typed decisions with probabilities on the System One wire contract
(POST /v1/systemone: noul, choice, score), trained to support two tasks in authorized
security work:
- finding triage — verdict (true_positive / false_positive / needs_review) and pre-auth reachability, on redacted scanner findings;
- observation prioritization — atomic questions about engagement observations (credentials exposed? privilege? reachability? escalation path?), recombined into impact scores by code, not by the model.
The model only ever sees redacted text (hex/base64 blobs replaced, bodies truncated) and never sees the objective or scenario words: it judges facts.
Serving
Any System One-compatible runtime on top of llama.cpp can serve this GGUF and expose
/v1/systemone; JEVSEC (github.com/s3m3y4z4/jevsec) points its base_url at it. One forward
pass per question set, zero generated tokens.
Training
- LoRA r=16, alpha=32, all attention/MLP linear layers, lr 5e-5, 8 epochs, bf16, merged into the base weights. Hyperparameters are identical across iterations: only the data changes.
- Data: a private, de-identified dataset of 317 security observations with human-verified labels (68 operator verdicts where the operator's judgment overrides the model's), documentation-reserved IPs/domains only, scenario words filtered out, content-deduplicated. The third iteration absorbs field feedback from two King-of-the-Hill engagements, including verdicts that corrected the previous model on external intel and duplicated facts.
- Measured on a held-out dev set: decision accuracy 0.81 (majority baseline ~0.56), prioritization accuracy 0.79.
Training curves
Limitations — read before deploying
- Probabilities are not calibrated on your domain: temperature scaling on your own labeled data is required before any threshold-based decision.
- Prompt injection moves the model: injected instructions in finding bodies can push probabilities (measured). This model is intended for human-in-the-loop triage; never wire it to automatic actions. JEVSEC ships with its auto-gate disabled for exactly this reason.
- Small training set (317 examples): treat it as an experiment that learns operator judgment, not as a production classifier. Validate on your own material first.
- English observations only.
Intended use
Decision support for authorized security testing (engagements you are permitted to test, CTF/King-of-the-Hill practice). The model sorts and explains; the operator decides.
License
Apache-2.0 (base model: XHToken/Spark-X2.5-4B, Apache-2.0; fine-tuning and redistribution permitted).
- Downloads last month
- 42
8-bit

