Command risk
Building Now
Job
Find supported network-to-shell and encoded-payload execution patterns in an identified response.
Outcome
Read the matched pattern and its limits before acting.
Claim
A supported command-risk pattern was found. The adopted PS name previously overclaimed scam detection; this preview uses a bounded explanation.
Method
Local lexical matching. Substitution methods check stdout routing and the execution layer; supported comments, immediate warnings and literal display forms are excluded. No payload is fetched or executed. The evaluator source hash identifies the exact method.
Input
Text, currently through the Chrome/ChatGPT development adapter and authenticated local gateway.
Output
A versioned tag record with subject binding, method, evidence, limitations, and a result state.
Supported scope
- curl or wget piped to sh or bash, with optional sudo
- Bounded curl/wget stdout command, process and backtick substitution into supported execution commands
- eval/exec receiving base64.b64decode, atob, or bytes.fromhex
- Exact spans in normalized redactor output
Limits
- Does not identify a scam, malicious intent, or human/AI authorship
- Does not execute commands or parse every shell/language form
- Some quotations and mixed contexts may still trigger
- No finding is not a safety clearance; one live Homebrew response verified, broader live-site coverage remains open
Validation
Development regression: 24 examples, TP 10 / FP 0 / FN 0 / TN 14. Not an independent holdout. 95% Wilson lower bounds: 0.722 for precision and recall; candidate gates fail. Additional reviewer counterexamples, schema/HTTP checks, observed-DOM race checks and real local extension integration pass; these do not estimate independent accuracy.
Cost
Free personal workflow. No paid detector, evidence, or verification gate.
Privacy
This catalogue does not evaluate your content. The personal reference implementation uses local services; detected redaction can miss sensitive information.
Dependencies
- Versioned claim and evidence contract
- Independent review for this tag
- Accessible presentation and a clear failure state
- Local redaction before evaluation
- Independent use/mention labels
Failure
A failed or unsupported check must not become a finding. A problem with this tag must not disable unrelated tags.
Owner
Maintainers own implementation; independent reviewers own validation; the product owner accepts release.
Release requirements
Candidate lower bounds 0.93 precision / 0.75 recall need accepted sampling and independent labels. Browser, accessibility, security, challenge/correction and latency gates remain open.
T-PS · Not release validated