Person tag · Coming Soon
UC — Unsafe command
A proposed clearer name for the command-risk findings currently shown as PS.
This code is not adopted or issued. Existing PS records keep their meaning.
Validation · Research proposal
Validation required before release
This capability is not available yet. It needs a working method and independent testing before release.
Use this tag
Research proposal. This code is not issued and has no downloadable checker yet.
See How it works for its intended job. Help improve this tag to contribute or follow its progress.
Baseline job
Create an accurate successor code for supported command-risk observations.
What the tag can claim
Proposed successor to the bounded command portion of PS.
Method and evidence
- Proposed in RFC-0004; current development still emits PS.
- Development · standard v0.1.0
- Proposed; not release calibrated.
Input
Supported text/code instructions.
Output
A versioned tag record with subject binding, method, evidence, limitations, and a result state.
Supported scope
- Proposal and existing PS development methods
Limits
- Not adopted and not emitted
- No rename can silently change existing records
- Requires independent context validation
Accuracy and validation
Not independently release validated.
Cost and access
Free personal workflow. No paid detector, evidence, or verification gate.
Privacy
This catalogue does not evaluate your content. The personal reference implementation uses local services; detected redaction can miss sensitive information.
Dependencies
- Versioned claim and evidence contract
- Independent review for this tag
- Accessible presentation and a clear failure state
Failure behavior
A failed or unsupported check must not become a finding. A problem with this tag must not disable unrelated tags.
Who owns the outcome
Maintainers own implementation; independent reviewers own validation; the product owner accepts release.
Before release
Publish agreed acceptance criteria, run independent validation, and verify the complete user workflow before release.
Tag enhancements in scope
- F-010 — sig.piped_installer.v1 — curl/wget piped to a shell. Specify and deliver sig.piped_installer.v1 — curl/wget piped to a shell. Scope record; not an implementation claim.
- F-011 — sig.obfuscated_payload.v1 — base64/hex into eval/exec. Specify and deliver sig.obfuscated_payload.v1 — base64/hex into eval/exec. Scope record; not an implementation claim.
- F-014 — Use/mention discriminator — is the command being recommended or discussed?. Specify and deliver use/mention discriminator — is the command being recommended or discussed?. Scope record; not an implementation claim.
Shared tag capabilities
- F-001 — Assertion envelope schema, JSON Schema 2020-12. Specify and deliver assertion envelope schema, JSON Schema 2020-12. Scope record; not an implementation claim.
- F-003 — Signal registry, 22 registered IDs with version suffixes. Specify and deliver signal registry, 22 registered IDs with version suffixes. Scope record; not an implementation claim.
- F-004 — Abstention as a first-class state — UNK. Specify and deliver abstention as a first-class state — UNK. Scope record; not an implementation claim.
- F-005 — Per-tag confidence floors. Specify and deliver per-tag confidence floors. Scope record; not an implementation claim.
- F-007 — Content-free assertion records. Return hashes, offsets, and metadata without embedding evaluated text Scope record; not an implementation claim.
- F-008 — Signed assertion integrity. Sign an exact canonical tag record with an identified key Scope record; not an implementation claim.
- F-009 — Cost-to-defeat ladder — statistical / behavioural / structural / cryptographic. Specify and deliver cost-to-defeat ladder — statistical / behavioural / structural / cryptographic. Scope record; not an implementation claim.
- N-005 — Label dispute, correction, and supersession workflow. Specify and deliver label dispute, correction, and supersession workflow. Scope record; not an implementation claim.
- N-006 — Versioned regression checks and revalidation triggers. Specify and deliver versioned regression checks and revalidation triggers. Scope record; not an implementation claim.
References
Scope record T-UC. Preserved scope is not implementation evidence.