Automated way to check R package for anything malicious or suspicious?

Viewed 267

I've found myself perusing some obscure parts of github and finding some real gems written in R. However, given some packages have zero vetting (unlike those on CRAN), I am a little uneasy about installing and using them (i.e. devtools::install_github("user/repo"))

One way to address the issue could be to write a function that reads an R package as text, and flags anything suspicious. An extremely crude version look like:

e.g.

flag_sus <- function(r_file) {
  file <- readLines(r_file)
  flag <- file %>% str_detect("system")
  if(length(flag) > 0) { print("Contains suspicious code") }
  }

But I wonder if there's a (much) better way?

Note

  • One quick way of reducing risk is to use a CRAN version of the package where possible, but obviously this is not always helpful (as many packages only exist outside of CRAN)
0 Answers
Related