Skip to content

Rules Reference

TrustSight uses rules to detect structural signals in PKGBUILD diffs. Each rule contributes to the final score based on its severity weight, match target, and scope.

This page is the map. The rule system reference explains how the engine works and holds everything that is not an individual rule: the rules.toml field table, the severity weights, the FATAL short-circuit, the measured fire rates, the series taxonomy, and the reserved identifier ranges. Each rule's own definition lives on the page for its category.

Categories

A rule's category is the kind of claim it makes. There is exactly one per rule and the set is closed, so every rule has exactly one page. This is not the same axis as the per-rule category field in rules.toml, which names the capability a match touched (network, persistence, obfuscation) and is what R072 counts when it looks for capability density. A rule can be category = "meta" and still be a composition rule.

The taxonomy is defined in src/trustsight/categories.py as RuleCategory, and tests/test_docs.py fails the build if a rule's documentation drifts to the wrong page. The two tables on this page are generated from it by scripts/build_rules_index.py.

Category Slug Rules What a rule here claims

| Fetch and Execution | fetch-and-execution | 34 | Code reaches the machine and runs: a fetch, an execution, or the path between the two. | | Obfuscation | obfuscation | 8 | The recipe hides what it does from a reader by encoding, indirection, or runtime assembly. | | Deception and Anti-Analysis | deception | 5 | The recipe targets whoever reviews it rather than the shell that runs it, or checks whether it is being watched. | | Install and Persistence | install-and-persist | 13 | Something survives the build: a root-time hook, a unit, a privileged bit, a file in the user's profile. | | Staging and Reconnaissance | staging-and-recon | 8 | The build steps outside its staging roots, hides a drop, or profiles the host it is running on. | | Integrity and Verification | integrity | 21 | A verification the recipe used to carry is weakened, removed, or cannot cover what it claims to. | | Naming and Dependencies | naming-and-dependency | 10 | A name is claimed or a dependency set changes in a way that redirects what gets installed. | | Maintainer and Metadata | maintainer-and-metadata | 11 | Who owns the package, or a long-stable declared property, changed. | | Temporal Context | temporal | 3 | How recently the package or this revision appeared, independent of any diff content. | | Composition | composition | 2 | Distinct kinds of finding co-occurred; the combination is the signal, and the points are already scored elsewhere. | | Count-Based | count-based | 5 | A count of indicators crossed a fixed threshold within one artifact or one cluster. | | Corpus Behavioral | corpus-behavioral | 7 | The package's position in, or deviation from, the corpus baseline - silent without prior observations. | | Crossfire | crossfire | 0 | Proposed: signals that only exist when two packages are compared against each other rather than against the corpus. |

Crossfire ships nothing yet. It is listed because the category is defined and reserved, not because rules exist under it; see crossfire.md for what it is for and why nothing is implemented.

Reading a rule entry

Each entry states the same facts in the same order:

  • Target: resolved (post-variable-expansion command strings), raw_line (the literal diff line), or programmatic (emitted from code in analysis/, because the condition needs more than one line).
  • Severity: FATAL, CRITICAL, HIGH, MEDIUM, LOW or INFO, with the weight it contributes. See severity weights.
  • Category: the capability field described above, not the page.
  • Pattern or Condition: what makes the rule fire. Quoted patterns are checked against the shipped rules.toml on every test run, so a pattern here cannot drift from the one that runs.
  • Fire rate, where measured: hits on the 3,246-diff benign corpus. These are false-positive rates. The full table is in measured fire rates.

Quick reference

Every documented rule, with the page that defines it. The identifier space is deliberately non-contiguous; see reserved identifiers.

Id Name Severity Category

| C001 | Checksum Changed Without Source Change With Stable Version | HIGH | Integrity and Verification | | C002 | Checksum Updated With Version Bump | INFO | Integrity and Verification | | C003 | Source URL Changed Without Version Bump | INFO | Integrity and Verification | | C004 | Checksum Removed For Unchanged Source | CRITICAL | Integrity and Verification | | C005 | Binary Artifact From Untrusted Source | MEDIUM | Integrity and Verification | | C006 | Maintainer Change With New Source Domain | HIGH | Maintainer and Metadata | | C007 | Command Substitution In Source Array | CRITICAL | Fetch and Execution | | D001 | Novel Dependency Added | HIGH | Naming and Dependencies | | D002 | Typosquatted Dependency | HIGH | Naming and Dependencies | | D003 | New Network-Using Makedepends | MEDIUM | Naming and Dependencies | | D004 | Dependency Hijack Via Provides | HIGH | Naming and Dependencies | | R001 | Remote Script Execution | CRITICAL | Fetch and Execution | | R002 | Wget Pipe to Shell | CRITICAL | Fetch and Execution | | R003 | Base64 Decode and Execute | CRITICAL | Obfuscation | | R004 | Checksum Disabled | HIGH | Integrity and Verification | | R005 | Checksum Emptied | HIGH | Integrity and Verification | | R006 | Insecure Download Protocol | MEDIUM | Fetch and Execution | | R007 | Install File Modification | MEDIUM | Install and Persistence | | R008 | Unexpected File Download | HIGH | Fetch and Execution | | R009 | Privilege Escalation | CRITICAL | Fetch and Execution | | R010 | Uses curl in PKGBUILD | LOW | Fetch and Execution | | R011 | Uses wget in PKGBUILD | LOW | Fetch and Execution | | R012 | Prompt Injection Detection | FATAL | Deception and Anti-Analysis | | R013 | Unicode Bidi Override | FATAL | Deception and Anti-Analysis | | R014 | validpgpkeys Added | HIGH | Integrity and Verification | | R016 | New Make/Opt/Check Dependency | INFO | Naming and Dependencies | | R017 | Setuid/Setgid Permission | HIGH | Install and Persistence | | R018 | Symlink Redirect | MEDIUM | Staging and Reconnaissance | | R019 | Suspicious Environment Variable | MEDIUM | Integrity and Verification | | R020 | Network connection attempt | CRITICAL | Fetch and Execution | | R021 | Suspicious file write | HIGH | Staging and Reconnaissance | | R022 | Sensitive binary execution | HIGH | Fetch and Execution | | R023 | Strace detection attempt (TracerPid check) | CRITICAL | Deception and Anti-Analysis | | R024 | Strace log truncated (possible flood evasion) | HIGH | Deception and Anti-Analysis | | R025 | Eval or Exec Usage | MEDIUM | Obfuscation | | R039 | Eval With Dynamic Content | CRITICAL | Obfuscation | | R040 | Shell -c With Dynamic Payload | CRITICAL | Obfuscation | | R041 | Shell Network Redirection | CRITICAL | Fetch and Execution | | R042 | Download Then Execute | CRITICAL | Fetch and Execution | | R043 | Base64 Blob Decode | CRITICAL | Obfuscation | | R044 | Interpreter One-Liner With Network | HIGH | Fetch and Execution | | R045 | Binary Encoding Pipe | MEDIUM | Obfuscation | | R046 | Source URL Uses IP Address | MEDIUM | Fetch and Execution | | R047 | Source URL Uses Non-Standard Port | LOW | Fetch and Execution | | R048 | Source URL On Free Registrar TLD | LOW | Fetch and Execution | | R049 | Compiler Plugin Or Loader Override | MEDIUM | Integrity and Verification | | R050 | Compiler Hardening Disabled | MEDIUM | Integrity and Verification | | R051 | Network Access In pkgver | HIGH | Fetch and Execution | | R052 | Dotfile Written To User Profile | HIGH | Install and Persistence | | R053 | Setuid Or Setgid Bit Set In Package Root | MEDIUM | Install and Persistence | | R054 | Persistence Unit Outside Package Root | HIGH | Install and Persistence | | R055 | Git Clone With Variable Branch | MEDIUM | Fetch and Execution | | R056 | Download Then Source | CRITICAL | Fetch and Execution | | R057 | TLS Verification Disabled | HIGH | Fetch and Execution | | R058 | Write Outside Package Root | HIGH | Staging and Reconnaissance | | R059 | Setuid Or Setgid Bit Set Outside Package Root | HIGH | Install and Persistence | | R060 | Critical Build Function Modified | INFO | Fetch and Execution | | R061 | Hidden Network Fetch In Build | HIGH | Fetch and Execution | | R062 | Install Hook Fetches Or Executes | HIGH | Install and Persistence | | R063 | Patch Applied From Outside The Build Tree | HIGH | Integrity and Verification | | R064 | Source URL Downgraded To HTTP | MEDIUM | Integrity and Verification | | R065 | Very Recent Update | INFO | Temporal Context | | R066 | Brand New Package | INFO | Temporal Context | | R067 | Stale Package Revived | MEDIUM | Temporal Context | | R068 | Install Hook Present | INFO | Install and Persistence | | R069 | GPG Verification Removed | HIGH | Integrity and Verification | | R070 | Build Environment Subversion | HIGH | Integrity and Verification | | R071 | Untrusted Maintainer Takeover | HIGH | Maintainer and Metadata | | R071 | Untrusted Maintainer Takeover (corpus path) | HIGH | Maintainer and Metadata | | R072 | Capability Density Anomaly | INFO | Composition | | R073 | Accelerated Release Cadence | - | Corpus Behavioral | | R074 | Package-Name Typosquat | HIGH | Naming and Dependencies | | R075 | Dependency-Set Expansion | MEDIUM | Count-Based | | R076 | Version-In-URL Injection | MEDIUM | Fetch and Execution | | R077 | Write To User Home Or RC | HIGH | Install and Persistence | | R079 | Moved Git Ref | HIGH | Integrity and Verification | | R080 | Exotic Source Protocol | MEDIUM | Fetch and Execution | | R081 | Foreign Package Manager In Install Hook | HIGH | Install and Persistence | | R082 | Shell Obfuscation Density | MEDIUM | Count-Based | | R083 | Long-Stable Property Changed | MEDIUM | Maintainer and Metadata | | R084 | World-Writable Staging | HIGH | Staging and Reconnaissance | | R085 | Systemd ExecStart From Runtime-Writable Path | HIGH | Install and Persistence | | R086 | Host Reconnaissance | INFO | Staging and Reconnaissance | | R087 | Upload To Paste Or File-Drop Host | HIGH | Fetch and Execution | | R088 | Hidden Drop | HIGH | Staging and Reconnaissance | | R089 | Attack-Chain Composition | INFO | Composition | | R090 | Ownership Transition | MEDIUM | Maintainer and Metadata | | R092 | Mass Adoption | HIGH | Count-Based | | R093 | Orphan/Adoption Dependency | MEDIUM | Corpus Behavioral | | R094 | Security-Relevant Build Flag Change | HIGH | Integrity and Verification | | R095 | Dependency Vendored Into Source | HIGH | Naming and Dependencies | | R096 | Source Host Changed | MEDIUM | Maintainer and Metadata | | R097 | Version Scheme Changed | INFO | Maintainer and Metadata | | R098 | Package Description Changed | MEDIUM | Maintainer and Metadata | | R100 | Shared Source Repository | HIGH | Count-Based | | R101 | Name/Host Consensus Divergence | MEDIUM | Naming and Dependencies | | R102 | Build System Changed | MEDIUM | Maintainer and Metadata | | R105 | Attribute Burst | MEDIUM | Count-Based | | R106 | Known Indicator of Compromise | FATAL | Corpus Behavioral | | R107 | Transitive Exposure | INFO | Corpus Behavioral | | R108 | Maintainer Baseline Deviation | MEDIUM | Maintainer and Metadata | | R110 | Name/Repo Divergence | MEDIUM | Naming and Dependencies | | R111 | Transitive Orphan Exposure | INFO | Corpus Behavioral | | R112 | Dependency Centrality | INFO | Corpus Behavioral | | R114 | Pacman Hook Installed | MEDIUM | Install and Persistence | | R115 | Epoch Introduced | MEDIUM | Maintainer and Metadata | | R116 | Provides/Replaces Scope Expansion | HIGH | Naming and Dependencies | | R117 | Obfuscated Literal Reconstructed | INFO | Obfuscation | | R118 | Embedded Binary In Tree | HIGH | Integrity and Verification | | R119 | Anti-Analysis Check | HIGH | Deception and Anti-Analysis | | R120 | Reconstructed Executable Payload | HIGH | Fetch and Execution | | R121 | Build-time Generation Then Execution | HIGH | Fetch and Execution | | R122 | Archive Trailer Anomaly | HIGH | Integrity and Verification | | R123 | Covert Egress | HIGH | Fetch and Execution | | R124 | Write Then Execute | HIGH | Fetch and Execution | | R125 | Introduction Rate Deviation | MEDIUM | Corpus Behavioral | | R126 | Adopt-then-Modify | MEDIUM | Maintainer and Metadata | | R127 | Indirect Remote Execution | CRITICAL | Fetch and Execution | | R128 | Build Writes Outside Staging Root | HIGH | Staging and Reconnaissance | | R129 | Parse-time Network Fetch | HIGH | Fetch and Execution | | R130 | Signing Key Set Changed | HIGH | Integrity and Verification | | R131 | Build Flags Weakened | HIGH | Integrity and Verification | | R132 | Indirect Command Expansion | CRITICAL | Obfuscation | | R136 | Committed File Executed Without Declaration | HIGH | Fetch and Execution | | R137 | Fetch Then Execute | CRITICAL | Fetch and Execution | | R138 | Downloaded Source File Executed | HIGH | Fetch and Execution | | R139 | Service ExecStart Targets Undeclared Binary | HIGH | Install and Persistence | | R140 | PATH Injection With Undeclared Directory | HIGH | Staging and Reconnaissance |

Weight-0 declared-practice findings (P001 to P007) are not detections and have no category. They are documented in the system reference.