SECURITY / DEVELOPER TOOLS
TELL
A deterministic black-box auditor for checking whether a local command rejects presumed-invalid binary inputs uniformly.
- Current state
- Audit tool
- Discipline
- Security · Developer tools
- Built with
- Go / Linux process groups / SHA-256 / JSON / Go standard library
The idea
A program may reject different binary inputs through different exit codes or output. TELL makes those discrete rejection differences visible through a bounded, deterministic audit of a local command.
How it works
Starting from one accepted binary input, TELL creates a fixed set of mutations and runs a command directly with each input. It groups rejection observations by exact exit code, stdout bytes and stderr bytes, with bounded execution and deterministic reports.
What’s implemented
- Checks discrete rejection differences against a fixed deterministic profile
- Uses exact observation equivalence and content hashes for traceable reports
- Separates completed audit failures from incomplete infrastructure runs
- Includes runner, mutation, reporting and CLI regression tests
PROJECT STATUS / AUDIT TOOL
Where it stands
Focused v1 audit tool
- No timing or side-channel analysis
- Generated candidates are presumed invalid; no grammar or coverage-guided fuzzing
- Does not prove exploitability, cryptographic correctness or security; target execution is not sandboxed
Source & resources
Documentation behind this project page
Reviewed October 1, 2026. Project descriptions reflect a source review; repository validation claims were not independently reproduced.