Not sure 100% how this works, but sounds cool. In terms of an application being able to bypass it, can it?
I mentioned some caveats under the limitations section of the readme such as hashing fails for AppImages because they use FUSE but they're still detected, or noting that scripts are only identified by their interpreter and arguments used. However nothing should be able to bypass picosnitch completely (i.e. silently) without a Linux vulnerability to hide from the kernel itself, or if something were to replace picosnitch with a modified copy.