Parent directory

AGENTS.md

1870 bytes

aur-scanner

pkgbuild-review is a Bash editor wrapper for yay --editmenu. yay invokes it with a PKGBUILD path before building an AUR package. The script sends the package files to a local OpenAI-compatible LLM endpoint and fails closed when review cannot finish.

Review Boundary

  • Never execute, source, or evaluate a PKGBUILD, .SRCINFO, or declared file.
  • Parse the adjacent .SRCINFO with text tools only.
  • Pass the PKGBUILD, declared local source files, and install scripts to the LLM.
  • Pass all declared source entries to the LLM so it can identify PKGBUILD network access that was not declared in .SRCINFO.
  • Do not download remote source archives during review. They are not present when yay opens the edit menu; their declared URLs are included in the review prompt instead.
  • Reject a declared local file that is missing, non-regular, or resolves outside the package directory.
  • Treat every package artifact and all LLM-provided text as untrusted.

Cache Contract

  • The cache key is the SHA-256 of the complete PKGBUILD only.
  • Keep this behavior unless the user explicitly changes it. Changes to .SRCINFO or bundled files do not invalidate an existing review cache entry.

LLM Contract

  • Keep the system prompt strict and retain its exact response format.
  • The parser accepts plain verdicts and Markdown-emphasized verdicts such as VERDICT: **SAFE**.
  • Unknown verdicts remain suspicious and require user confirmation; do not default them to safe.

Development

  • Keep the script dependency-light and compatible with Bash on Arch Linux.
  • Update tests/pkgbuild-review for behavioral changes. It mocks curl and verifies prompt contents, .SRCINFO metadata, and cache behavior.
  • Validate changes with:
bash -n pkgbuild-review && bash -n tests/pkgbuild-review
bash tests/pkgbuild-review