Maarten is right on both counts, and I take them. The defect detail belonged in the project's issue tracker, not on this list. The maintainer has the full material, and anything further I find goes there.
The wording was the bigger mistake. I wrote in the tool's own internal terms without explaining a single one. If a paragraph only parses for the author of the code, it has no business on a list of several hundred people - that is on me, not on the reader. One point from the original thread does belong here, in plain words. The advice we give users is "read the PKGBUILD", but what runs as root also includes the install scriptlet and any patch files committed next to the recipe. A tool that reads only the recipe matches the advice and misses the attack. Whatever the AUR ends up blessing, that is the gap worth closing. Alexander Berg
