--- license: apache-2.0 tags: - layerfault - security-research - model-security - synthetic - adversarial-testing extra_gated_prompt: >- This repository is a synthetic security-test artifact from the Layerfault corpus. It intentionally contains adversarial characteristics (e.g. suspicious pickle opcodes, executable-format smuggling, prompt-injection strings) designed to exercise security scanner detection rules. It is **not** a usable ML model and must never be loaded or executed outside an isolated scanner-testing environment. By accepting, you confirm you understand this repository is a test fixture, not production model weights. extra_gated_button_content: I understand this is a security test fixture and accept the risk gated: auto --- # python-custom-loader-capability-chain > **SECURITY TEST ARTIFACT — DO NOT USE AS A PRODUCTION MODEL** This repository is part of the Layerfault synthetic security corpus. It is deliberately constructed to contain security-relevant characteristics for scanner testing. **Corpus ID:** `LF-CORPUS-PY-0001` ## Purpose HF-style custom loader containing harmless process, native-load, loopback-network, credential, filesystem, dynamic-code, package-manager and NumPy allow_pickle call sites. ## Direct expected Layerfault rules - `LF-CODE-AUTO-MAP` - `LF-CODE-SUBPROCESS` - `LF-PY-CALL-PROCESS` - `LF-CORR-HF-LOADER-PROCESS` - `LF-CODE-CTYPES` - `LF-PY-NATIVE-LOAD` - `LF-CORR-HF-LOADER-NATIVE-LOAD` - `LF-CODE-NETWORK` - `LF-PY-CALL-NETWORK` - `LF-CORR-HF-LOADER-NETWORK` - `LF-PY-CREDENTIAL-ACCESS` - `LF-CORR-HF-LOADER-CREDENTIALS` - `LF-PY-FILESYSTEM-MUTATION` - `LF-CORR-HF-LOADER-FILESYSTEM` - `LF-CODE-EVAL` - `LF-PY-CALL-DYNAMIC-CODE` - `LF-CORR-HF-LOADER-DYNAMIC-CODE` - `LF-PY-PACKAGE-INSTALL` - `LF-CORR-HF-LOADER-INSTALL` - `LF-PY-NUMPY-ALLOW-PICKLE` - `LF-CORR-NUMPY-ALLOW-PICKLE` ## Candidate rules These are deliberately plausible targets that remain marked as candidates until the exact Layerfault build used for certification confirms them. - None ## Negative-control rules These should remain silent for this corpus item. - None ## Safety The corpus uses fake secrets, loopback/`.invalid` network destinations, harmless marker output, and synthetic model behavior only. It is intended for static scanning and isolated security testing.