Skip to content

Rules Reference

TrustSight uses rules to detect structural signals in PKGBUILD diffs. The inventory is the R-series regex rules, the H-series heuristics, sabotage rules S001-S008, crossfire rules X001-X025, integrity-change rules C001-C009, dependency rules D001-D004, declared-practice rules P001-P008, and unverifiable rules W001-W006.

Each rule contributes according to its severity weight, match target and scope, except the P and W series, which are weight 0 and report rather than score.

This page is the map. The rule system reference explains how the engine works and holds everything that is not an individual rule: the rules.toml field table, the severity weights, the FATAL short-circuit, the measured fire rates, the series taxonomy, and the reserved identifier ranges. Each rule's own definition lives on the page for its category.

Categories

A rule's category is the kind of claim it makes. There is exactly one per rule and the set is closed, so every rule has exactly one page. This is not the same axis as the per-rule category field in rules.toml, which names the capability a match touched (network, persistence, obfuscation) and is what H027 counts when it looks for capability density. A rule can be category = "meta" and still be a composition rule.

The taxonomy is defined in src/trustsight/categories.py as RuleCategory, and tests/test_docs.py fails the build if a rule's documentation drifts to the wrong page. The two tables on this page are generated from it by scripts/build_rules_index.py.

Category Slug Rules What a rule here claims
Fetch and Execution fetch-and-execution 36 Code reaches the machine and runs: a fetch, an execution, or the path between the two.
Obfuscation obfuscation 8 The recipe hides what it does from a reader by encoding, indirection, or runtime assembly.
Deception and Anti-Analysis deception 5 The recipe targets whoever reviews it rather than the shell that runs it, or checks whether it is being watched.
Install and Persistence install-and-persist 17 Something survives the build: a root-time hook, a unit, a privileged bit, a file in the user's profile.
Staging and Reconnaissance staging-and-recon 8 The build steps outside its staging roots, hides a drop, or profiles the host it is running on.
Integrity and Verification integrity 32 A verification the recipe used to carry is weakened, removed, or cannot cover what it claims to.
Naming and Dependencies naming-and-dependency 10 A name is claimed or a dependency set changes in a way that redirects what gets installed.
Maintainer and Metadata maintainer-and-metadata 13 Who owns the package, or a long-stable declared property, changed.
Temporal Context temporal 3 How recently the package or this revision appeared, independent of any diff content.
Composition composition 2 Distinct kinds of finding co-occurred; the combination is the signal, and the points are already scored elsewhere.
Count-Based count-based 5 A count of indicators crossed a fixed threshold within one artifact or one cluster.
Corpus Behavioral corpus-behavioral 7 The package's position in, or deviation from, the corpus baseline - silent without prior observations.
Crossfire crossfire 25 The evasion technique itself, not the payload it hides: a rule here fires on how a thing was written rather than on what it does.
Sabotage sabotage 8 A payload aimed at the operator's machine rather than at getting something out of it: resource exhaustion, deletion, permission sabotage, service disruption, resource theft.
Unverifiable unverifiable 6 Not a claim about the recipe but about the analysis: something the package will run that this run could not read. Weight 0 always, and always shown.

Crossfire is the anti-evasion family introduced in the current ruleset. Its 25 rules detect tokenizer defeat and command reconstruction; see crossfire.md for the family boundary and rule descriptions.

Reading a rule entry

Each entry states the same facts in the same order:

  • Target: resolved (post-variable-expansion command strings), raw_line (the literal diff line), or programmatic (emitted from code in analysis/, because the condition needs more than one line).
  • Severity: FATAL, CRITICAL, HIGH, MEDIUM, LOW or INFO, with the weight it contributes. See severity weights.
  • Category: the capability field described above, not the page.
  • Pattern or Condition: what makes the rule fire. Quoted patterns are checked against the shipped rules.toml on every test run, so a pattern here cannot drift from the one that runs.
  • Fire rate, where measured: hits on the current 3,246-diff benign corpus, unless a page explicitly identifies a historical measurement. These are false-positive rates. The full table is in measured fire rates.

Quick reference

Every documented rule, with the page that defines it. The identifier space is deliberately non-contiguous; see reserved identifiers.

Id Name Series Severity Category
C001 Checksum Changed Without Source Change With Stable Version Integrity-change HIGH Integrity and Verification
C002 Checksum Updated With Version Bump Integrity-change INFO Integrity and Verification
C003 Source URL Changed Without Version Bump Integrity-change INFO Integrity and Verification
C004 Checksum Removed For Unchanged Source Integrity-change CRITICAL Integrity and Verification
C005 Binary Artifact From Untrusted Source Integrity-change MEDIUM Integrity and Verification
C006 Maintainer Change With New Source Domain Integrity-change HIGH Maintainer and Metadata
C007 Command Substitution In Source Array Integrity-change CRITICAL Fetch and Execution
C008 Unread Content Moved Under A Stable Version Integrity-change HIGH Integrity and Verification
C009 Unread Content Moved With The Version Integrity-change INFO Integrity and Verification
D001 Novel Dependency Added Dependency HIGH Naming and Dependencies
D002 Typosquatted Dependency Dependency HIGH Naming and Dependencies
D003 New Network-Using Makedepends Dependency MEDIUM Naming and Dependencies
D004 Dependency Hijack Via Provides Dependency HIGH Naming and Dependencies
H001 Checksum Disabled Heuristic HIGH Integrity and Verification
H002 Checksum Emptied Heuristic HIGH Integrity and Verification
H003 Insecure Download Protocol Heuristic LOW Fetch and Execution
H004 Privilege Escalation Heuristic CRITICAL Fetch and Execution
H005 validpgpkeys Added Heuristic MEDIUM Integrity and Verification
H006 New Make/Opt/Check Dependency Heuristic INFO Naming and Dependencies
H007 Symlink Redirect Heuristic MEDIUM Staging and Reconnaissance
H008 Suspicious Environment Variable Heuristic MEDIUM Integrity and Verification
H009 Network connection attempt Heuristic CRITICAL Fetch and Execution
H010 Suspicious file write Heuristic HIGH Staging and Reconnaissance
H011 Sensitive binary execution Heuristic HIGH Fetch and Execution
H012 Strace detection attempt (TracerPid check) Heuristic CRITICAL Deception and Anti-Analysis
H013 Strace log truncated (possible flood evasion) Heuristic HIGH Deception and Anti-Analysis
H014 Eval or Exec Usage Heuristic MEDIUM Obfuscation
H015 Critical Build Function Modified Heuristic INFO Fetch and Execution
H016 Hidden Network Fetch In Build Heuristic HIGH Fetch and Execution
H017 Install Hook Fetches Or Executes Heuristic HIGH Install and Persistence
H018 Patch Applied From Outside The Build Tree Heuristic HIGH Integrity and Verification
H019 Source URL Downgraded To HTTP Heuristic MEDIUM Integrity and Verification
H020 Very Recent Update Heuristic INFO Temporal Context
H021 Brand New Package Heuristic INFO Temporal Context
H022 Stale Package Revived Heuristic MEDIUM Temporal Context
H023 Install Hook Present Heuristic INFO Install and Persistence
H024 GPG Verification Removed Heuristic HIGH Integrity and Verification
H025 Build Environment Subversion Heuristic HIGH Integrity and Verification
H026 Untrusted Maintainer Takeover Heuristic HIGH Maintainer and Metadata
H026 Untrusted Maintainer Takeover (corpus path) Heuristic HIGH Maintainer and Metadata
H027 Capability Density Anomaly Heuristic INFO Composition
H028 Accelerated Release Cadence Heuristic - Corpus Behavioral
H029 Package-Name Typosquat Heuristic HIGH Naming and Dependencies
H030 Dependency-Set Expansion Heuristic MEDIUM Count-Based
H031 Version-In-URL Injection Heuristic MEDIUM Fetch and Execution
H032 Write To User Home Or RC Heuristic HIGH Install and Persistence
H033 Moved Git Ref Heuristic HIGH Integrity and Verification
H034 Exotic Source Protocol Heuristic MEDIUM Fetch and Execution
H035 Foreign Package Manager In Install Hook Heuristic HIGH Install and Persistence
H036 Shell Obfuscation Density Heuristic MEDIUM Count-Based
H037 Long-Stable Property Changed Heuristic MEDIUM Maintainer and Metadata
H038 World-Writable Staging Heuristic HIGH Staging and Reconnaissance
H039 Systemd ExecStart From Runtime-Writable Path Heuristic HIGH Install and Persistence
H040 Host Reconnaissance Heuristic INFO Staging and Reconnaissance
H041 Upload To Paste Or File-Drop Host Heuristic HIGH Fetch and Execution
H042 Hidden Drop Heuristic HIGH Staging and Reconnaissance
H043 Attack-Chain Composition Heuristic INFO Composition
H044 Ownership Transition Heuristic MEDIUM Maintainer and Metadata
H045 Mass Adoption Heuristic HIGH Count-Based
H046 Orphan/Adoption Dependency Heuristic MEDIUM Corpus Behavioral
H047 Security-Relevant Build Flag Change Heuristic HIGH Integrity and Verification
H048 Dependency Vendored Into Source Heuristic HIGH Naming and Dependencies
H049 Source Host Changed Heuristic MEDIUM Maintainer and Metadata
H050 Version Scheme Changed Heuristic INFO Maintainer and Metadata
H051 Package Description Changed Heuristic MEDIUM Maintainer and Metadata
H052 Shared Source Repository Heuristic HIGH Count-Based
H053 Name/Host Consensus Divergence Heuristic MEDIUM Naming and Dependencies
H054 Build System Changed Heuristic MEDIUM Maintainer and Metadata
H055 Attribute Burst Heuristic MEDIUM Count-Based
H056 Known Indicator of Compromise Heuristic FATAL Corpus Behavioral
H057 Transitive Exposure Heuristic INFO Corpus Behavioral
H058 Maintainer Baseline Deviation Heuristic MEDIUM Maintainer and Metadata
H059 Name/Repo Divergence Heuristic MEDIUM Naming and Dependencies
H060 Transitive Orphan Exposure Heuristic INFO Corpus Behavioral
H061 Dependency Centrality Heuristic INFO Corpus Behavioral
H062 Pacman Hook Installed Heuristic MEDIUM Install and Persistence
H063 Epoch Introduced Heuristic MEDIUM Maintainer and Metadata
H064 Provides/Replaces Scope Expansion Heuristic HIGH Naming and Dependencies
H065 Obfuscated Literal Reconstructed Heuristic INFO Obfuscation
H066 Embedded Binary In Tree Heuristic HIGH Integrity and Verification
H067 Anti-Analysis Check Heuristic HIGH Deception and Anti-Analysis
H068 Reconstructed Executable Payload Heuristic HIGH Fetch and Execution
H069 Build-time Generation Then Execution Heuristic HIGH Fetch and Execution
H070 Archive Trailer Anomaly Heuristic HIGH Integrity and Verification
H071 Covert Egress Heuristic HIGH Fetch and Execution
H072 Write Then Execute Heuristic HIGH Fetch and Execution
H073 Introduction Rate Deviation Heuristic MEDIUM Corpus Behavioral
H074 Adopt-then-Modify Heuristic MEDIUM Maintainer and Metadata
H075 Indirect Remote Execution Heuristic CRITICAL Fetch and Execution
H076 Build Writes Outside Staging Root Heuristic HIGH Staging and Reconnaissance
H077 Parse-time Network Fetch Heuristic HIGH Fetch and Execution
H078 Signing Key Set Changed Heuristic HIGH Integrity and Verification
H079 Build Flags Weakened Heuristic HIGH Integrity and Verification
H080 Indirect Command Expansion Heuristic CRITICAL Obfuscation
H081 Committed File Executed Without Declaration Heuristic HIGH Fetch and Execution
H082 Fetch Then Execute Heuristic CRITICAL Fetch and Execution
H083 Downloaded Source File Executed Heuristic HIGH Fetch and Execution
H084 Service ExecStart Targets Undeclared Binary Heuristic HIGH Install and Persistence
H085 PATH Injection With Undeclared Directory Heuristic HIGH Staging and Reconnaissance
H086 Adopted From Orphan Heuristic MEDIUM Maintainer and Metadata
H087 Recipe Changed Without Upstream Heuristic MEDIUM Integrity and Verification
H088 Adopted, Recipe Rewritten, Unpinned Fetch Heuristic HIGH Maintainer and Metadata
H089 Packaged File Names A Build-Only Path Heuristic HIGH Install and Persistence
H090 Committed Companion Carries A Fetch-Execute Payload Heuristic CRITICAL Fetch and Execution
H091 Checksum Array Shorter Than Source Array Heuristic HIGH Integrity and Verification
H092 Metadata Names A Source The Recipe Does Not Heuristic HIGH Integrity and Verification
H093 Committed Config Points At A Build-Only Path Heuristic HIGH Install and Persistence
H094 Unread Script Executed During Packaging Heuristic HIGH Fetch and Execution
H095 Boot Or Image Artifact Built From The Source Tree Heuristic HIGH Install and Persistence
H096 Download Agent Override Heuristic MEDIUM Integrity and Verification
H097 Function Shadowing Heuristic HIGH Integrity and Verification
R001 Remote Script Execution Regex CRITICAL Fetch and Execution
R002 Wget Pipe to Shell Regex CRITICAL Fetch and Execution
R003 Base64 Decode and Execute Regex CRITICAL Obfuscation
R007 Install File Modification Regex MEDIUM Install and Persistence
R008 Unexpected File Download Regex HIGH Fetch and Execution
R010 Uses curl in PKGBUILD Regex LOW Fetch and Execution
R011 Uses wget in PKGBUILD Regex LOW Fetch and Execution
R012 Prompt Injection Detection Regex FATAL Deception and Anti-Analysis
R013 Unicode Bidi Override Regex FATAL Deception and Anti-Analysis
R017 Setuid/Setgid Permission Regex HIGH Install and Persistence
R039 Eval With Dynamic Content Regex CRITICAL Obfuscation
R040 Shell -c With Dynamic Payload Regex CRITICAL Obfuscation
R041 Shell Network Redirection Regex CRITICAL Fetch and Execution
R042 Download Then Execute Regex CRITICAL Fetch and Execution
R043 Base64 Blob Decode Regex CRITICAL Obfuscation
R044 Interpreter One-Liner With Network Regex HIGH Fetch and Execution
R045 Binary Encoding Pipe Regex MEDIUM Obfuscation
R046 Source URL Uses IP Address Regex MEDIUM Fetch and Execution
R047 Source URL Uses Non-Standard Port Regex LOW Fetch and Execution
R048 Source URL On Free Registrar TLD Regex LOW Fetch and Execution
R049 Compiler Plugin Or Loader Override Regex MEDIUM Integrity and Verification
R050 Compiler Hardening Disabled Regex MEDIUM Integrity and Verification
R051 Network Access In pkgver Regex HIGH Fetch and Execution
R052 Dotfile Written To User Profile Regex HIGH Install and Persistence
R053 Setuid Or Setgid Bit Set In Package Root Regex MEDIUM Install and Persistence
R054 Persistence Unit Outside Package Root Regex HIGH Install and Persistence
R055 Git Clone With Variable Branch Regex MEDIUM Fetch and Execution
R056 Download Then Source Regex CRITICAL Fetch and Execution
R057 TLS Verification Disabled Regex HIGH Fetch and Execution
R058 Write Outside Package Root Regex HIGH Staging and Reconnaissance
R059 Setuid Or Setgid Bit Set Outside Package Root Regex HIGH Install and Persistence
R078 Compression Command Override Regex MEDIUM Integrity and Verification
R091 Privilege Escalation Override Regex HIGH Integrity and Verification
R099 Trap Statement Regex MEDIUM Integrity and Verification
R104 Error Handling Suppressed Regex HIGH Integrity and Verification
R144 Packaged File Points At A World-Writable Path Regex HIGH Install and Persistence
S001 Recursive Self-Spawn Sabotage CRITICAL Sabotage
S002 Recursive Deletion Outside The Build Tree Sabotage CRITICAL Sabotage
S003 Raw Block Device Write Sabotage CRITICAL Sabotage
S004 Secure Deletion Of User Data Sabotage HIGH Sabotage
S005 Permission Change On A System Path Sabotage HIGH Sabotage
S006 System Service Disruption Sabotage HIGH Sabotage
S007 Cryptocurrency Miner Sabotage HIGH Sabotage
S008 Shell History Or Log Destruction Sabotage MEDIUM Sabotage
W001 Executes Code This Analysis Did Not Read Unverifiable INFO Unverifiable
W002 Build Resolves Dependencies From A Registry Unverifiable INFO Unverifiable
W003 Applies A Patch This Analysis Did Not Read Unverifiable INFO Unverifiable
W004 Build Engine Runs A Manifest This Analysis Did Not Read Unverifiable INFO Unverifiable
W005 Build Runs A Target Whose Recipe Was Not Read Unverifiable INFO Unverifiable
W006 Generated File Names A Build-Only Path Unverifiable INFO Unverifiable
X001 Encoded Payload Decoded And Executed Crossfire CRITICAL Crossfire
X002 Non-Literal Executable Name Crossfire CRITICAL Crossfire
X003 Obfuscated Command Argument Crossfire HIGH Crossfire
X004 Build Output Suppressed Crossfire MEDIUM Crossfire
X005 Home Reached By An Alternative Spelling Crossfire HIGH Crossfire
X006 Source Points Somewhere Unexpected Crossfire HIGH Crossfire
X007 Multiple Evasion Techniques Crossfire CRITICAL Crossfire
X008 Whitespace A Shell Does Not Split On Crossfire MEDIUM Crossfire
X009 Fetch Through An Uncatalogued Client Crossfire CRITICAL Crossfire
X010 Interpreter One-Liner Reaches The Network Crossfire HIGH Crossfire
X011 Package Manager Runs Fetched Code At Build Time Crossfire HIGH Crossfire
X012 Build Toolchain Redirected Into The Source Tree Crossfire HIGH Crossfire
X013 Fetch Redirected Or Trust Root Replaced Crossfire HIGH Crossfire
X014 Environment Variable Names Code To Run Crossfire HIGH Crossfire
X015 Work Scheduled To Run After The Build Crossfire HIGH Crossfire
X016 Fetch Piped Into An Unrecognised Consumer Crossfire HIGH Crossfire
X017 Tool Flag Or Builtin Carries A Command Crossfire HIGH Crossfire
X018 Interpreter One-Liner Assembles A Name Crossfire HIGH Crossfire
X019 Host Material Sent Or Packaged Crossfire HIGH Crossfire
X020 Recipe Writes The Build Steps The Engine Runs Crossfire HIGH Crossfire
X021 Executor Runs A File Chosen At Runtime Crossfire HIGH Crossfire
X022 Generated Config Handed To The Tool That Reads It Crossfire HIGH Crossfire
X023 Command Output Executed As A Script Crossfire HIGH Crossfire
X024 Indirect Sensitive Assignment Crossfire HIGH Crossfire
X025 Multi-Line Function Shadow Crossfire HIGH Crossfire

Weight-0 declared-practice findings (P001 to P008) are not detections and have no category. They are documented in the system reference.