Menu ▾ ▴

Security scanner

sanjaya danushka

PKGBUILD Security Scanner

A pre-install security gate for the AUR. Before NeoArch builds a package from the AUR, it statically scans the PKGBUILD for risky patterns — and shows you exactly what it found.

Overview

Arch's AUR is a community-run repository: anyone can upload a PKGBUILD. To close the gap between "it's on the AUR" and "it's safe to build", NeoArch ships a static scanner (exposed as neo scan) that inspects a PKGBUILD before installation and blocks or warns on dangerous behavior.

The scanner is a port of the rules from ArchCanary (MIT, by musqz) and is part of NeoArch's normal install pipeline — see Install & Quick start.

What it detects

Category What it flags
Risky post-install tools scripts that call pkexec, sudo, gksu, or write to system paths during post_install
Elevation privilege escalation within the PKGBUILD
Dynamic shell eval, runtime-generated commands, or shell injection patterns ($(...), backticks)
Local binaries shipping or fetching and executing binaries (./something, direct exec)
Unicode homograph spoofing package names/pkgver/scripts that mix look-alike characters to impersonate well-known tools
Supply-chain evasion (newer GitHub-provider rules) obfuscation and evasion tricks that hide the above

How to use

Automatic (GUI) — AUR installs and neo build/neo install --aur run the scan first. If it finds a critical issue, it stops before anything touches your system and shows the flagged lines so you can judge.

Manual (CLI) — scan any PKGBUILD file, including ones from a cloned git repo:

neo scan ./PKGBUILD                   # static security scan (exit code reflects findings)
neo scan --help                       # all flags (json output, severity levels)

Automation — combine with the --json flag to feed findings into your own scripts or CI:

neo scan ./PKGBUILD --json

Good to know

  • The scanner is static: it reads the PKGBUILD text, it does not download or execute anything.
  • Findings are warnings/blockers with the offending lines highlighted — a "warning" still lets you proceed after you've reviewed it; a "blocker" stops the operation.
  • Rules come from the GitHub ruleset of ArchCanary; the toolkit is extensible, so new evasion patterns can be added over time.
  • See the CLI reference for the full neo scan syntax.

↩ Back to Home


Related

Wiki: Development
Wiki: Discover
Wiki: Home