media-jpeg-zip-python-source

SECURITY TEST ARTIFACT: DO NOT USE AS A PRODUCTION MODEL

This repository is part of the Layerfault synthetic security corpus. It is deliberately constructed to contain security-relevant characteristics for scanner testing.

Corpus ID: LF-CH-MCONT-0009

Purpose

JPEG appends a ZIP with dormant Python capability source.

Direct expected Layerfault rules

  • None; this repository is a control/comparison input.

Candidate rules

These are deliberately plausible targets that remain marked as candidates until the exact Layerfault build used for certification confirms them.

  • LF-FORMAT-APPENDED-ARCHIVE
  • LF-CODE-SUBPROCESS

Negative-control rules

These should remain silent for this corpus item.

  • None

Safety

The corpus uses fake secrets, loopback/.invalid network destinations, harmless marker output, and synthetic model behavior only. It is intended for static scanning and isolated security testing.

Challenge classification

  • Severity: critical
  • Difficulty: compound
  • Expected admission decision: BLOCK
  • Control type: compound
  • Attack surface: media-container, package-evasion
  • Techniques: appended-archive, nested-source
  • Transformations: nesting, cross-format

Ground-truth oracle IDs

  • LF-ORACLE-MEDIA-APPENDED-CONTAINER

These oracle IDs describe synthetic ground truth. They do not claim that a matching Layerfault detector already exists. A challenge may intentionally expose a scanner blind spot and remain unmapped until the detector is implemented.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Collection including LayerFault/media-jpeg-zip-python-source