After all the compromised-package noise I got a bit paranoid, so I wrote a small read-only script that checks your installed packages against the official Arch list of bad names. It only reads from pacman and the public list, it never changes anything. It does two passes, so it catches both normal AUR builds (pacman -Qmq) and packages pulled in...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3566410