shell-capability-chain
SECURITY TEST ARTIFACT: DO NOT USE AS A PRODUCTION MODEL
This repository is part of the Layerfault synthetic security corpus. It is deliberately constructed to contain security-relevant characteristics for scanner testing.
Corpus ID: LF-CORPUS-SH-0001
Purpose
Shell package with canary dynamic-code, dot-source, filesystem write, loopback curl-pipe, package-manager and native-load/environment patterns.
Direct expected Layerfault rules
LF-SHELL-SEMANTIC-CREDENTIAL-ACCESSLF-SHELL-SEMANTIC-CURL-PIPE-SHLF-SHELL-SEMANTIC-DYNAMIC-CODELF-SHELL-SEMANTIC-FILESYSTEM-WRITELF-SHELL-SEMANTIC-NATIVE-LOADLF-SHELL-SEMANTIC-PACKAGE-INSTALL
Candidate rules
These are deliberately plausible targets that remain marked as candidates until the exact Layerfault build used for certification confirms them.
LF-SHELL-CURL-PIPELF-SHELL-DOT-SOURCE
Negative-control rules
These should remain silent for this corpus item.
- None
Safety
The corpus uses fake secrets, loopback/.invalid network destinations, harmless marker output,
and synthetic model behavior only. It is intended for static scanning and isolated security testing.