Person tag · Building Now
PS — Command risk
Flags commands that download code and run it, or execute supported encoded code.
This warns about a command pattern. It does not prove a scam. An untagged answer may still be unsafe.
Validation · On-device preview
Validation in progress
The local workflow has passed development checks. Independent accuracy testing and human accessibility review are still pending.
Try the local PS checker. It does not certify an AI answer as true or safe.
Use this tag
On phone or computer: copy an AI answer, choose Check on this device, paste and check. No account, extension or Docker needed. The command patterns are checked, never executed.
Open aitrustid.com/#person/PS and choose Check on this device. Optional: save the public app for offline use and add it to your home screen. No answer is uploaded; the phone preview performs no redaction.
Developer local service (optional)
Developer preview: Linux or macOS, Python 3.12+, Git, make, and Docker Engine with Compose. First setup downloads packages and models. A one-click installer and a Chrome Web Store release are not available yet.
Download source · Full setup guide
Get the source
Download the ZIP and read its README, or use Git:
git clone https://github.com/knwvmbrr/aitrust-id.git cd aitrust-idPrepare the checker
From the repository folder, install its checker dependencies:
python3 -m venv .venv .venv/bin/python -m pip install -r eval/requirements.txt python3 scripts/aitrust.py initStart your local services
With Docker Engine and Compose running, build and start only AI Trust ID:
make deploy ENV_FILE="$HOME/.config/aitrust-id/runtime.env" .venv/bin/python scripts/aitrust.py doctorCheck an answer
Save the answer as response.txt in this folder, then run:
.venv/bin/python scripts/aitrust.py check response.txt
PS finding = a supported command-risk pattern. No finding = no supported pattern found, not “safe.” UNAVAILABLE = the check did not complete successfully.
Optional Chrome tags: open chrome://extensions, enable Developer mode, choose Load unpacked, select this repository’s extension folder, then enter your local token in its options. Keep the services running and open ChatGPT. Tags appear below supported answers; click a tag for a short explanation.
Your answer goes to your own local service, not this website or a training database. Keep your token private. Do not paste it into a public report.
Stop the checker
make down ENV_FILE="$HOME/.config/aitrust-id/runtime.env"Baseline job
Find supported network-to-shell and encoded-payload execution patterns in an identified response.
What the tag can claim
A supported command-risk pattern was found. The adopted PS name previously overclaimed scam detection; this preview uses a bounded explanation.
Method and evidence
- Local lexical matching. Pipe and substitution methods check stdout routing and the execution layer; supported comments, immediate warnings and literal display forms are excluded. No payload is fetched or executed. The evaluator source hash identifies the exact method.
- Development · standard v0.1.0
- 0.70 editorial floor. Method scores are uncalibrated heuristics, not probabilities.
Input
Text, currently through the Chrome/ChatGPT development adapter and authenticated local gateway.
Output
A versioned tag record with subject binding, method, evidence, limitations, and a result state.
Supported scope
- curl or wget piped to sh or bash, with optional sudo
- Bounded curl/wget stdout command, process and backtick substitution into supported execution commands
- eval/exec receiving base64.b64decode, atob, or bytes.fromhex
- Exact spans in normalized redactor output
Limits
- Does not identify a scam, malicious intent, or human/AI authorship
- Does not execute commands or parse every shell/language form
- Some quotations and mixed contexts may still trigger
- No finding is not a safety clearance; one live Homebrew response verified, broader live-site coverage remains open
Accuracy and validation
Current context-v5 development regression: 86 cases across five active sets, TP 31 / FP 0 / FN 0 / TN 55. These were used during development, not an independent holdout. Development Wilson 95% lower bounds are 0.890 for precision and recall; the candidate precision gate fails. Independent labels and calibration are missing. Earlier live and container evidence covers context-v4; this update has executed HTTP and routing checks, but its full local container/browser pipeline has not been rerun.
Cost and access
Free personal workflow. No paid detector, evidence, or verification gate.
Privacy
This catalogue does not evaluate your content. The personal reference implementation uses local services; detected redaction can miss sensitive information.
Dependencies
- Versioned claim and evidence contract
- Independent review for this tag
- Accessible presentation and a clear failure state
- Local redaction before evaluation
- Independent use/mention labels
Failure behavior
A failed or unsupported check must not become a finding. A problem with this tag must not disable unrelated tags.
Who owns the outcome
Maintainers own implementation; independent reviewers own validation; the product owner accepts release.
Before release
Candidate lower bounds 0.93 precision / 0.75 recall need accepted sampling and independent labels. Browser, accessibility, security, challenge/correction and latency gates remain open.
Tag enhancements in scope
- F-010 — sig.piped_installer.v1 — curl/wget piped to a shell. Specify and deliver sig.piped_installer.v1 — curl/wget piped to a shell. Scope record; not an implementation claim.
- F-011 — sig.obfuscated_payload.v1 — base64/hex into eval/exec. Specify and deliver sig.obfuscated_payload.v1 — base64/hex into eval/exec. Scope record; not an implementation claim.
- F-012 — sig.credential_exfil.v1 — reads a secret path, writes to a network sink. Specify and deliver sig.credential_exfil.v1 — reads a secret path, writes to a network sink. Scope record; not an implementation claim.
- F-013 — sig.typosquat.v1 — package name within edit distance 1–2 of a top-N name. Specify and deliver sig.typosquat.v1 — package name within edit distance 1–2 of a top-N name. Scope record; not an implementation claim.
- F-014 — Use/mention discriminator — is the command being recommended or discussed?. Specify and deliver use/mention discriminator — is the command being recommended or discussed?. Scope record; not an implementation claim.
Shared tag capabilities
- F-001 — Assertion envelope schema, JSON Schema 2020-12. Specify and deliver assertion envelope schema, JSON Schema 2020-12. Scope record; not an implementation claim.
- F-003 — Signal registry, 22 registered IDs with version suffixes. Specify and deliver signal registry, 22 registered IDs with version suffixes. Scope record; not an implementation claim.
- F-004 — Abstention as a first-class state — UNK. Specify and deliver abstention as a first-class state — UNK. Scope record; not an implementation claim.
- F-005 — Per-tag confidence floors. Specify and deliver per-tag confidence floors. Scope record; not an implementation claim.
- F-007 — Content-free assertion records. Return hashes, offsets, and metadata without embedding evaluated text Scope record; not an implementation claim.
- F-008 — Signed assertion integrity. Sign an exact canonical tag record with an identified key Scope record; not an implementation claim.
- F-009 — Cost-to-defeat ladder — statistical / behavioural / structural / cryptographic. Specify and deliver cost-to-defeat ladder — statistical / behavioural / structural / cryptographic. Scope record; not an implementation claim.
- N-005 — Label dispute, correction, and supersession workflow. Specify and deliver label dispute, correction, and supersession workflow. Scope record; not an implementation claim.
- N-006 — Versioned regression checks and revalidation triggers. Specify and deliver versioned regression checks and revalidation triggers. Scope record; not an implementation claim.
References
- taxonomy.md
- signals.md
- PS-01.md
- PS-01-acceptance.md
- regression-gates.json
- live-gap-implementation.json
- browser-checks.json
- extension-integration.json
- ps_v1.jsonl
- fetch_execute_v1.jsonl
- counterexamples_v2.jsonl
- live_gap_v1.jsonl
- routing_boundaries_v1.jsonl
- ps-routing-regressions.json
- ps-routing-gates.json
- independent-review.md
Scope record T-PS. Preserved scope is not implementation evidence.