Yes, absolutely. Many forks contain malicious code. Always review the script ( main.py , requirements.txt ) before running. Look for base64-encoded strings, eval() functions, or os.system() commands contacting unknown IPs.
Within minutes, you can have a local AI detection server running on localhost:7860 . aio checker github
(Python-based)