aurscan
Blocks malicious Arch AUR packages before they build, with Claude Code or Codex reading the PKGBUILD on your existing subscription.

About aurscan
aurscan reads an AUR package's PKGBUILD, install scriptlets, .SRCINFO and helper scripts the moment yay or paru downloads them, before makepkg runs a single line, and stops the build if the script looks malicious. It explains each finding in plain words and lets you abort, report or continue. The reviewer can be the Claude Code CLI or the Codex CLI, each on your existing subscription, an Anthropic API key or a local model, tried as a chain so a rate-limited backend falls through to the next.
Can you use your ChatGPT plan in aurscan?
Yes. Your Codex subscription (ChatGPT plan), through the logged-in Codex CLI. aurscan's own page says: "uses your existing Claude subscription and reports exact cost per scan."
How to connect your plan
Claude Pro or Max
- Install aurscan from its pacman repo and use yay or paru as usual.
- Have the Claude Code CLI (
claude) on your PATH and logged in; aurscan uses your existing Claude subscription.
ChatGPT Plus or Pro
- Install aurscan from its pacman repo and use yay or paru as usual.
- Have the Codex CLI (
codex) on your PATH and logged in; aurscan uses your existing Codex subscription.


