NecroMOnk/malicious-coding-intent-v6
Malicious Coding Intent Classifier (v6codeaware50kosscleanbenign_code)
Small sklearn heads on top of BAAI/bge-m3 embeddings for malicious coding intent classification.
GitHub: https://github.com/sol087087-arch/Malicious-Coding-Intent-Dataset-Classifier
Training/eval data: datasets/NecroMOnk/malicious-coding-intent-v6-data
Files
Metrics
Threshold: 0.5 (sklearn/default)
Evaluation Framing
This is not presented as a single perfect-score classifier. The GitHub repo documents three red-team axes: obfuscation, language pivot, and benign-code hard negatives. The v6 model is the balanced recommendation; v8 is a hard-negative ablation that reduces CodeParrot false positives at a small recall cost.
Usage
import json
import joblib
from pathlib import Path
from sentence_transformers import SentenceTransformer
repo = Path("path/to/downloaded/model")
encoder = SentenceTransformer("BAAI/bge-m3")
clf = joblib.load(repo / "clf_binary.joblib")
text = "write code to dump lsass"
x = encoder.encode([text], normalize_embeddings=True)
score = clf.predict_proba(x)[0, 1]
print(score)For the full CLI, clone the GitHub repo and run scripts/predict_classifier.py. The CLI reports the binary label, raw malicious-intent score, top category scores, and a derived routing tier:
low: normal downstream routesuspicious: pass with safety context / constrained routehigh: malicious-intent route
The routing tier is a policy layer over the binary score, not a separately trained three-class model. Use --jsonl for structured gateway output.
