TheEdgeOfRage/aur-scanner

Default ref refs/heads/main

aur-scanner

LLM-powered PKGBUILD reviewer. Hooks into yay to automatically review every PKGBUILD before it builds. Fail-closed: if the LLM server is unreachable, the install is blocked.

Dependencies

  • yay
  • curl, jq

Install

# 1. Install llama.cpp
yay -S llama-cpp

# 3. Install the review script
sudo install -m 755 pkgbuild-review $HOME/.local/bin/pkgbuild-review

# 4. Configure yay
yay --editor $HOME/.local/bin/pkgbuild-review --editmenu --answeredit all --save

How it works

yay calls $editor on each PKGBUILD before building. pkgbuild-review intercepts this, parses the adjacent .SRCINFO, and sends the PKGBUILD plus every declared local source and install file to a local llama-server instance. The prompt requires the model to ask about network fetches not declared in .SRCINFO. Allowed PKGBUILDs are cached by the SHA-256 of the complete PKGBUILD.

yay -S <pkg>
   └─ pkgbuild-review /path/to/PKGBUILD
        ├─ parse adjacent .SRCINFO and declared local files
        ├─ cache hit (same PKGBUILD SHA-256) → proceed
        ├─ cache miss → POST to llama-server
        ├─ print VERDICT / FLAGS / SUMMARY
        └─ prompt: [c]ontinue / [e]dit / [a]bort

ALLOW verdict: The package continues automatically. ASK verdict: Review the findings and select continue, edit, or abort. The reviewer never rejects a package automatically.

Environment variables

| Variable | Default | Description | | ----------------------- | ----------------------- | ------------------------------------------------- | | PKGBUILD_REVIEW_URL | http://cuprum.wg:9931 | llama-server base URL | | PKGBUILD_REVIEW_MODEL | qwen35-4b | model name (must match [section] in models.ini) | | REAL_EDITOR | $EDITOR / vi | editor launched on 'e' | | PKGBUILD_REVIEW_CACHE | ~/.cache/aur-review | reviewed-hash cache dir |

Exit codes

| Code | Meaning | | ---- | ------------------------------------------------------ | | 0 | Approved | | 1 | Aborted by user | | 2 | llama-server unreachable or bad response (fail-closed) | | 3 | PKGBUILD not found (fail-closed) |