testdata/corpus/ in the repository is two things at once: the tests that stop Aspex from regressing, and a benchmark other tools can run against.
explain verdicts, and fail on anything listed under must_not_report. Writing the first six found one wrong expectation (a shell-only server is remote control, not a separate file-read exfiltration path); the corpus now pins that.
The format, both vocabularies, and how to contribute a scenario or an anonymized real-world configuration are in testdata/corpus/README.md. A scenario where Aspex disagrees with truth: is a welcome pull request: it is a bug report with a test attached.