AUR Sleuth

Supply-chain audits of AUR packages
Anything malicious?

Independent models read every file an AUR maintainer committed — the PKGBUILD, the .install hooks, the patches — looking for one thing: code injected into the packaging. They vote, and a stronger model rules on anything they flag. The application itself is never judged.

Every package audited

How a verdict is reached

Cheap models read every committed file and vote; a stronger one rules on anything they flag.
The pipeline: the AUR repository is read and upstream sources are not; each model on the audit seat reads every file and votes, and advisory models are read but never counted; a judge rules on flags; escalation adds a fresh audit and ruling up to twice; every verdict is published. The AUR repository PKGBUILD, .install hooks, patches, helper scripts: every committed file is read Upstream what makepkg downloads is theirs, and is never read The reports one verdict per voting model, with the lines that earned it ↻ second look: any accusing verdict is asked again, kept only if it softens clean every vote said safe no verdict no answer either way they disagree, or agree on a warning Judge a stronger model reads every report there is, and rules clean the judge cleared it still flagged worth a closer look not settled yet Escalation a fresh audit by a stronger model that has not read it, then a fresh ruling ↻ two rounds at most, then it stops confirmed malicious 2 models + judge agree models disagree split after two rounds every report, ruling and quoted line is published here
  1. The boundary. Only the files in the package’s AUR repository are read — every one of them, wherever it sits, whatever it is called. What makepkg downloads from upstream is upstream’s and is never read: a malicious upstream is not an AUR attack, and an AUR maintainer cannot inject into it.
  2. The audits. Cheap models — two or more, so they can disagree — each read every file on their own and return a verdict with the lines that earned it. Free models add advisory reads: the same audit, but the judge only reads it and it counts toward nothing. Any verdict that accuses is asked once more against the rules and kept only if it softens — a pass that can undo a false alarm and never create one.
  3. The judge. When the audits disagree, or agree on a warning, a stronger model reads every report and rules. Most flags end here, cleared.
  4. Escalation. A package still flagged gets a fresh audit from a stronger model that has not read it, then a fresh ruling — twice at most. Two distinct models saying unsafe with the judge agreeing is confirmed; still split after two rounds is models disagree.
  5. Published. Every report, every ruling and every quoted line lands on this page. Nothing is edited by hand: a package the pipeline gets wrong is audited again, or the code is fixed.

Recent audits

All packages →

Open source, one private instance

Everything that decides a verdict is public; one private instance runs it.
The auditor, the pipeline and the container are open source; one private instance holds the schedule, budget, credentials and operations page, and publishes its results back to the same public repository. OPEN SOURCE · github.com/mgalgs/aur-sleuth the auditor aur-sleuth, and its prompts the pipeline audit, judge, escalate, publish the container one image, built from this repository the code, as an image PRIVATE · the one instance that runs it schedule when it runs, and the daily budget credentials API keys and the deploy key operations page start runs, review, publish the results, after a review OPEN SOURCE · the same repository every report, and this page: mgalgs.io/aur-sleuth

Everything that decides a verdict is open source: the auditor, its prompts, the pipeline and the container image are all in github.com/mgalgs/aur-sleuth, and so are the reports, on its audit-reports branch.

What is private is the one instance that runs them: its schedule and daily budget, its API keys and deploy key, and the operations page that starts runs, reviews what a run produced, and publishes. A publish pushes the reviewed reports and the page rebuilt from them back to the same public repository. The results are inspectable even though the machine that produced them is not.

clean flagged confirmed no verdict overridden second audit advisory
Package Version Audits Judge Files Cost Date