DO NOT load this model in production environments. DO NOT use this model for any purpose other than security research.
SaveV2 op that bypasses modelscan detection (which only checks ReadFile/WriteFile) and writes files to arbitrary paths during inference.