Skip to main content

TrustSight

TrustSight

Audits AUR PKGBUILD updates before you install: detects structural changes, suspicious commands, typosquatting, and novelty signals, then produces a deterministic risk score with a plain-English explanation.

Python License DeepWiki Tests PyPI


Setup

# 1. Install
git clone https://github.com/emiliano-go/trustsight.git
cd trustsight/packaging/aur
makepkg -si

# 2. Scan your outdated AUR packages
trustsight review

Requires Python 3.10+ and Arch Linux (the tool reads pacman -Qm to discover AUR packages).

The score is always deterministic and calculated locally. Verdicts are template-based, describing each finding in plain English — for example "Version bump. modified PKGBUILD, .SRCINFO. Signals: checksum disabled; novel dependency 'pyfoo' added in depends."

Not published to the AUR yet. Build from the PKGBUILD in this repository. Also installable via pip install trustsight.


What it detects

Attack / Risk How TrustSight catches it
Piped shell scripts (curl | bash, base64 | sh) Scans every new or changed line for command-subprocess pipelines (R001, ~100% recall on known cases)
Obfuscated commands (encoded strings, environment subversion like LD_PRELOAD) Resolves variables and decodes known obfuscation patterns; flags build-environment tampering (R007, R070)
Checksum disabled or removed Compares old vs new sha256sums / md5sums arrays (R004, R005)
Source URL typosquatting (githab.com instead of github.com) Character-level edit distance against known forge domains (R008)
Package-name typosquatting (e.g. libuvc resembling libuv) Edit-distance comparison against more popular packages in the seed database (R074)
URL swapped without a version bump Tracks source URL changes that are not accompanied by a new version (C003)
Novel / never-before-seen URLs or maintainers Compares against a bundled seed of 178,491 known AUR source URLs; flags first-seen domains and maintainers (novelty tier)
Unicode bidi override attacks (invisible characters that change how text displays) Detects directionality overrides and homoglyph codepoints in PKGBUILD content (R013)
LLM prompt injection in package metadata Pattern-matches common injection templates; primary defense is structural (the LLM cannot change the score) (R012)
GPG verification removed Detects when validpgpkeys was populated and is now empty (R069)
Untrusted maintainer takeover A maintainer change to someone never seen before (R071)
Stale package revived A package with no updates for over a year suddenly gets one (R067)
Accelerated release cadence 3+ commits in the last 24 hours (R073, informational)

What it cannot detect

Limitation Why
Malicious upstream release tarballs TrustSight audits the PKGBUILD, not the binaries it downloads. A clean build file can point to a compromised tarball.
Deliberately unremarkable attacks If no commands are added, no URLs change, and no checksums are disabled, there is no diff signal. The update is invisible to this kind of analysis.
Build-dependency attacks A malicious makedepends or depends entry is outside TrustSight's scope. It audits the recipe, not the second-order supply chain.
Runtime attacks The tool never executes the PKGBUILD, never runs extracted commands, and never modifies your system.
Zero-day structural attacks Rules are pattern-based and calibrated against a known corpus. A novel attack that leaves no matching pattern will not fire.

The output is a risk assessment, not a proof of safety. A clean score means no known risk signals fired, not that the package is safe. See the trust model for details.


The 30-second example

trustsight review
                        TrustSight Review
┏━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Package         ┃ Risk Score   ┃ Verdict                                   ┃
┃                 ┃              ┃                                           ┃
┡━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┩
│ chez-scheme-bin │   0/100      │ Version bump. No structural changes.      │
├─────────────────┼──────────────┼───────────────────────────────────────────┤
│ sketchy-pkg     │  35/100      │ R004 HIGH  Checksum disabled (SKIP).      │
│                 │              │ C003 INFO  Source URL changed without     │
│                 │              │            version bump.                  │
│                 │              │ SOURCE_BUCKET MEDIUM  New domain:         │
│                 │              │   sketchy-cdn.invalid (unknown).          │
│                 │              │ NOVELTY HIGH  Source URL first seen       │
│                 │              │   globally.                               │
│                 │              │ PINNING INFO  Source pinning: unpinned.   │
│                 │              │ Verdict: Checksum disabled; sources       │
│                 │              │   replaced with content from an unknown,  │
│                 │              │   never-before-seen domain.               │
├─────────────────┼──────────────┼───────────────────────────────────────────┤
│ obsidian-beta   │  15/100      │ INCONCLUSIVE. Only 2 prior observations;  │
│                 │              │ no high-severity signals from a cold DB.  │
└─────────────────┴──────────────┴───────────────────────────────────────────┘

The tiered evidence display is the differentiator: every signal (rule, bucket, novelty, pinning, verification) is shown with its contribution and severity. You see why the score is what it is.


Commands

Command What it does
trustsight review Scan outdated AUR packages and produce a scored table with tiered evidence. Supports --repo, --foreign, --all-repos, --verbose flags.
trustsight inspect <package> Deep-dive on a single package: full score breakdown, source URLs, resolved commands, novelty context.
trustsight history <package> Show past analysis results for a package.
trustsight config set Set individual config keys.
trustsight seed-db Import the bundled URL database for novelty detection. Runs automatically on first review.
trustsight list List all packages tracked in the database.
trustsight status Show database and system health statistics.
trustsight db Database maintenance (check, vacuum, backup).
trustsight override Suppress a rule that misfires on your packages.
trustsight lint-rules Check rules.toml for unreachable or malformed rules.

How scoring works

Scoring is fully deterministic: same input always produces the same score. The pipeline is:

  1. Diff the old and new PKGBUILD
  2. Apply rules to detect structural changes, suspicious commands, typosquatting, etc.
  3. Classify URLs into trust buckets (official, self-hosted, unknown, homograph)
  4. Check novelty against the local database of known URLs and maintainers
  5. Calculate score from 0-100 by summing weighted contributions across four evidence tiers

Signals come from 13 detection rules (R001-R013), 21 expanded rules (R039-R059) calibrated against a 3,322-diff corpus of benign AUR updates, and 7 code-structure rules (C001-C007).

Verdicts are template-based, describing each triggered finding in plain English. The score is never influenced by the verdict text.

See scoring-philosophy.md.


Security model

TrustSight is evidence-producing, not proof-of-safety. It audits and does not install. The tool never runs the PKGBUILD, never executes extracted commands, and never modifies your system. Every finding is traceable to a specific diff line, URL, or novelty record. The output is a structured risk assessment to inform your decision, not a gate. See trust-model.md.


License

MIT


Documentation hub

Section Description
Getting Started One-tutorial path from install to first review
Full documentation Docs landing page
Contributing How to report bugs, contribute code, improve docs
Security Vulnerability disclosure policy
License MIT full text

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

trustsight-0.9.0.tar.gz (24.2 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

trustsight-0.9.0-py3-none-any.whl (21.0 MB view details)

Uploaded Python 3

File details

Details for the file trustsight-0.9.0.tar.gz.

File metadata

  • Download URL: trustsight-0.9.0.tar.gz
  • Upload date:
  • Size: 24.2 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for trustsight-0.9.0.tar.gz
Algorithm Hash digest
SHA256 5b8c436e4a2f318e595f29488cf96b51eeca5d768bcbc31adf526212020844fc
MD5 0f58a37d981512be525ca3790d8e3ea6
BLAKE2b-256 fb52cae65290df00a80ac92a9d1740b84f494be5dae2dd19c09779b9e023d957

See more details on using hashes here.

Provenance

The following attestation bundles were made for trustsight-0.9.0.tar.gz:

Publisher: publishing.yml on emiliano-go/trustsight

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file trustsight-0.9.0-py3-none-any.whl.

File metadata

  • Download URL: trustsight-0.9.0-py3-none-any.whl
  • Upload date:
  • Size: 21.0 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for trustsight-0.9.0-py3-none-any.whl
Algorithm Hash digest
SHA256 7fe04205c578156e3beb1eacb02057751ea9b468183c97abfa60b5ae90502b7e
MD5 57d50553fe1123b27539aaefd3c8ceec
BLAKE2b-256 f3c8aa5b7440af76bb823c82ccf87d3ef6d45053b11de810eae17cd4d2737d42

See more details on using hashes here.

Provenance

The following attestation bundles were made for trustsight-0.9.0-py3-none-any.whl:

Publisher: publishing.yml on emiliano-go/trustsight

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.15.7

2 files

0.15.6

2 files

0.15.5

2 files

0.15.4

2 files

0.15.3

2 files

0.15.2

2 files

0.15.1

2 files

0.13.1

2 files

0.13.0

2 files

0.12.1

2 files

0.12.0

2 files

0.11.0

2 files

0.10.1

2 files

0.10.0

2 files

This release

0.9.0 This release

2 files

0.8.0

2 files

0.7.2

2 files

0.7.1

2 files

0.7.0

2 files

0.6.1

2 files

0.6.0

2 files

0.5.1

2 files

0.5.0

2 files

0.4.1

2 files

0.4.0

2 files

0.3.1

2 files

0.3.0

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page