AGENTS.md
1870 bytes
aur-scanner
pkgbuild-review is a Bash editor wrapper for yay --editmenu. yay invokes it with
a PKGBUILD path before building an AUR package. The script sends the package files
to a local OpenAI-compatible LLM endpoint and fails closed when review cannot finish.
Review Boundary
- Never execute, source, or evaluate a
PKGBUILD,.SRCINFO, or declared file. - Parse the adjacent
.SRCINFOwith text tools only. - Pass the PKGBUILD, declared local
sourcefiles, andinstallscripts to the LLM. - Pass all declared source entries to the LLM so it can identify PKGBUILD network
access that was not declared in
.SRCINFO. - Do not download remote source archives during review. They are not present when yay opens the edit menu; their declared URLs are included in the review prompt instead.
- Reject a declared local file that is missing, non-regular, or resolves outside the package directory.
- Treat every package artifact and all LLM-provided text as untrusted.
Cache Contract
- The cache key is the SHA-256 of the complete PKGBUILD only.
- Keep this behavior unless the user explicitly changes it. Changes to
.SRCINFOor bundled files do not invalidate an existing review cache entry.
LLM Contract
- Keep the system prompt strict and retain its exact response format.
- The parser accepts plain verdicts and Markdown-emphasized verdicts such as
VERDICT: **SAFE**. - Unknown verdicts remain suspicious and require user confirmation; do not default them to safe.
Development
- Keep the script dependency-light and compatible with Bash on Arch Linux.
- Update
tests/pkgbuild-reviewfor behavioral changes. It mockscurland verifies prompt contents,.SRCINFOmetadata, and cache behavior. - Validate changes with:
bash -n pkgbuild-review && bash -n tests/pkgbuild-review
bash tests/pkgbuild-review