SECURITY / DEVELOPER TOOLS

TELL

A deterministic black-box auditor for checking whether a local command rejects presumed-invalid binary inputs uniformly.

Current state
Audit tool
Discipline
Security · Developer tools
Built with
Go / Linux process groups / SHA-256 / JSON / Go standard library

The idea

A program may reject different binary inputs through different exit codes or output. TELL makes those discrete rejection differences visible through a bounded, deterministic audit of a local command.

How it works

Starting from one accepted binary input, TELL creates a fixed set of mutations and runs a command directly with each input. It groups rejection observations by exact exit code, stdout bytes and stderr bytes, with bounded execution and deterministic reports.

What’s implemented

  • Checks discrete rejection differences against a fixed deterministic profile
  • Uses exact observation equivalence and content hashes for traceable reports
  • Separates completed audit failures from incomplete infrastructure runs
  • Includes runner, mutation, reporting and CLI regression tests

PROJECT STATUS / AUDIT TOOL

Where it stands

Focused v1 audit tool

  • No timing or side-channel analysis
  • Generated candidates are presumed invalid; no grammar or coverage-guided fuzzing
  • Does not prove exploitability, cryptographic correctness or security; target execution is not sandboxed

Source & resources

Documentation behind this project page

Reviewed October 1, 2026. Project descriptions reflect a source review; repository validation claims were not independently reproduced.