TheEdgeOfRage/aur-scanner
aur-scanner
LLM-powered PKGBUILD reviewer. Hooks into yay to automatically review every PKGBUILD before it builds. Fail-closed: if the LLM server is unreachable, the install is blocked.
Dependencies
yaycurl,jq
Install
# 1. Install llama.cpp
yay -S llama-cpp
# 3. Install the review script
sudo install -m 755 pkgbuild-review $HOME/.local/bin/pkgbuild-review
# 4. Configure yay
yay --editor $HOME/.local/bin/pkgbuild-review --editmenu --answeredit all --save
How it works
yay calls $editor on each PKGBUILD before building. pkgbuild-review intercepts
this, parses the adjacent .SRCINFO, and sends the PKGBUILD plus every declared
local source and install file to a local llama-server instance. The prompt requires
the model to ask about network fetches not declared in .SRCINFO. Allowed PKGBUILDs
are cached by the SHA-256 of the complete PKGBUILD.
yay -S <pkg>
└─ pkgbuild-review /path/to/PKGBUILD
├─ parse adjacent .SRCINFO and declared local files
├─ cache hit (same PKGBUILD SHA-256) → proceed
├─ cache miss → POST to llama-server
├─ print VERDICT / FLAGS / SUMMARY
└─ prompt: [c]ontinue / [e]dit / [a]bort
ALLOW verdict: The package continues automatically. ASK verdict: Review the findings and select continue, edit, or abort. The reviewer never rejects a package automatically.
Environment variables
| Variable | Default | Description |
| ----------------------- | ----------------------- | ------------------------------------------------- |
| PKGBUILD_REVIEW_URL | http://cuprum.wg:9931 | llama-server base URL |
| PKGBUILD_REVIEW_MODEL | qwen35-4b | model name (must match [section] in models.ini) |
| REAL_EDITOR | $EDITOR / vi | editor launched on 'e' |
| PKGBUILD_REVIEW_CACHE | ~/.cache/aur-review | reviewed-hash cache dir |
Exit codes
| Code | Meaning | | ---- | ------------------------------------------------------ | | 0 | Approved | | 1 | Aborted by user | | 2 | llama-server unreachable or bad response (fail-closed) | | 3 | PKGBUILD not found (fail-closed) |