Thanks, and AFAIK this should be the most reliable tool of its type on Linux, and the only one that also hashes executables which makes it a lot harder to bypass.
I mentioned some caveats under the limitations section of the readme such as hashing fails for AppImages because they use FUSE but they're still detected, or noting that scripts are only identified by their interpreter and arguments used. However nothing should be able to bypass picosnitch completely (i.e. silently) without a Linux vulnerability to hide from the kernel itself, or if something were to replace picosnitch with a modified copy.