A pre-install security gate for the AUR. Before NeoArch builds a package from the AUR, it statically scans the PKGBUILD for risky patterns — and shows you exactly what it found.
Arch's AUR is a community-run repository: anyone can upload a PKGBUILD. To close the gap between "it's on the AUR" and "it's safe to build", NeoArch ships a static scanner (exposed as neo scan) that inspects a PKGBUILD before installation and blocks or warns on dangerous behavior.
The scanner is a port of the rules from ArchCanary (MIT, by musqz) and is part of NeoArch's normal install pipeline — see Install & Quick start.
| Category | What it flags |
|---|---|
| Risky post-install tools | scripts that call pkexec, sudo, gksu, or write to system paths during post_install |
| Elevation | privilege escalation within the PKGBUILD |
| Dynamic shell | eval, runtime-generated commands, or shell injection patterns ($(...), backticks) |
| Local binaries | shipping or fetching and executing binaries (./something, direct exec) |
| Unicode homograph spoofing | package names/pkgver/scripts that mix look-alike characters to impersonate well-known tools |
| Supply-chain evasion | (newer GitHub-provider rules) obfuscation and evasion tricks that hide the above |
Automatic (GUI) — AUR installs and neo build/neo install --aur run the scan first. If it finds a critical issue, it stops before anything touches your system and shows the flagged lines so you can judge.
Manual (CLI) — scan any PKGBUILD file, including ones from a cloned git repo:
neo scan ./PKGBUILD # static security scan (exit code reflects findings)
neo scan --help # all flags (json output, severity levels)
Automation — combine with the --json flag to feed findings into your own scripts or CI:
neo scan ./PKGBUILD --json
neo scan syntax.