Instructions to use impacte/bunker-laya with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers.js
How to use impacte/bunker-laya with Transformers.js:
// npm i @huggingface/transformers import { pipeline } from '@huggingface/transformers'; // Allocate pipeline const pipe = await pipeline('text-classification', 'impacte/bunker-laya'); - Laya
How to use impacte/bunker-laya with Laya:
# No code snippets available yet for this library. # To use this model, check the repository files and the library's documentation. # Want to help? PRs adding snippets are welcome at: # https://github.com/huggingface/huggingface.js
impacte/bunker-laya
Fine-tuned convaiinnovations/laya
for the opencode-bunker
guardrail: typed decisions over PII, prompt injection, jailbreak
attempts and harmful requests.
Laya is a non-autoregressive System 1 decision model: give it a state (text)
and typed questions (choice, score, noul) and it returns typed answers with
calibrated probabilities in a single forward pass. It never generates text, so
there is nothing to parse and nothing to hallucinate.
Question bank
pii_present: Does the text contain personally identifiable information (PII)?pii_email: Does the text contain an email address?pii_phone: Does the text contain a phone number?pii_ssn: Does the text contain a government identification number such as a Social Security number?pii_credit_card: Does the text contain a payment card number?pii_ip_address: Does the text contain an IP address?pii_secret: Does the text contain an API key, password, token, or other credential?pii_person_name: Does the text contain a person's name?pii_address: Does the text contain a physical mailing address?injection_present: Does the content attempt to override, bypass, or manipulate an AI system's instructions, safety measures, or identity? Examples: 'ignore previous instructions', 'reveal your system prompt', 'act as an unrestricted AI', 'pretend you have no rules'.jailbreak_attempt: Does the content attempt to bypass an AI system's safety measures or jailbreak it?harmful_request: Is the content a request for harmful, illegal, or disallowed activity?
Files
| Path | What |
|---|---|
onnx/model.onnx + onnx/model.onnx.data |
FP32 graph (external data) β use this (correct; ~1.6 GB) |
onnx/model.int8.onnx |
INT8 weight-only graph β degraded (the PII head collapses to ~0.5); not recommended |
tokenizer/ |
ModernBERT tokenizer (tokenizer.json, tokenizer_config.json) |
encoder/config.json |
encoder config (incl. cls_token_id) |
rl_agent_config.json |
max_len, head_max_len, per-question-type temperatures |
model.safetensors |
PyTorch checkpoint (for re-export / further fine-tuning) |
Graph contract
Inputs:
| name | dtype | shape | meaning |
|---|---|---|---|
input_ids |
int64 | [batch, seq_len] |
token ids |
attention_mask |
int64 | [batch, seq_len] |
1 for real tokens |
marker_pos |
int64 | [batch, num_markers] |
position of each option's [MASK] |
marker_mask |
bool | [batch, num_markers] |
which marker slots are real |
qtype |
int64 | [batch] |
choice=0, score=1, noul=2 |
Outputs:
| name | shape | meaning |
|---|---|---|
logits |
[batch, num_markers] |
per-option logits (softmax over the question's options) |
act_logits |
[batch, 2] |
action head (softmax) |
For a noul question there are exactly two options (false, true), so
P(true) = softmax(logits[:2] / temperature)[1].
Sequence format
Each question is one row. The head is built as:
[CLS] <qtype> question: <instructions> [SEP] [MASK] false: ... [MASK] true: ... [SEP] <state> [SEP]
marker_pospoints at each[MASK]token;marker_maskmarks the real ones.- The state is appended after the head and truncated to the room left by
max_len - head_max_len. qtypeis2for everynoulquestion in this model.
Use with Transformers.js
Transformers.js provides the tokenizer and the ONNX Runtime backend. Because the
graph is a custom decision head (not a standard AutoModel architecture), load
the tokenizer with AutoTokenizer and run the graph with an ONNX Runtime
session:
import { AutoTokenizer } from "@huggingface/transformers";
import { InferenceSession, Tensor } from "onnxruntime-node"; // or onnxruntime-web
const REPO = "impacte/bunker-laya";
const tokenizer = await AutoTokenizer.from_pretrained(REPO);
const session = await InferenceSession.create("model.onnx"); // keep model.onnx.data alongside
// 1. Build the head: [CLS] <qtype> question: <instructions> [SEP] [MASK] false: ... [MASK] true: ... [SEP]
// 2. Append the state, then [SEP]; truncate to max_len - head_max_len.
// 3. Run:
const out = await session.run({
input_ids: new Tensor("int64", ids, [1, ids.length]),
attention_mask: new Tensor("int64", mask, [1, ids.length]),
marker_pos: new Tensor("int64", markerPos, [1, markerPos.length]),
marker_mask: new Tensor("bool", markerMask, [1, markerMask.length]),
qtype: new Tensor("int64", [2n], [1]),
});
// logits: [1, 2] -> softmax -> P(true)
opencode-bunker's onnx-local provider does exactly this (see
src/classifier/onnx-local.ts), so the plugin needs no Python sidecar.
Pairing with opencode-bunker
opencode turn
β chat.message / messages.transform
βΌ
opencode-bunker plugin
β classify(text)
βΌ
onnx-local provider ββ AutoTokenizer (transformers.js) βββΊ ids
β ββ ONNX Runtime session ββββββββββββΊ logits
βΌ
typed decisions (pii_*, injection_present, β¦) βββΊ allow / flag / redact / block
β
βΌ
audit.jsonl (pre-provider proof) βββΊ provider request (or blocked)
The plugin fuses these model probabilities with its regex presets and custom
patterns; regex increment deltas raise a question's probability and can
escalate the action. See the plugin's .planning/ARCHITECTURE.md.
Provenance
Built by the opencode-bunker-laya pipeline. Base model Apache-2.0. Each
training dataset keeps its own license (see the pipeline README).
Model tree for impacte/bunker-laya
Base model
convaiinnovations/laya