I've found myself perusing some obscure parts of github and finding some real gems written in R. However, given some packages have zero vetting (unlike those on CRAN), I am a little uneasy about installing and using them (i.e. devtools::install_github("user/repo"))
One way to address the issue could be to write a function that reads an R package as text, and flags anything suspicious. An extremely crude version look like:
e.g.
flag_sus <- function(r_file) {
file <- readLines(r_file)
flag <- file %>% str_detect("system")
if(length(flag) > 0) { print("Contains suspicious code") }
}
But I wonder if there's a (much) better way?
Note
- One quick way of reducing risk is to use a CRAN version of the package where possible, but obviously this is not always helpful (as many packages only exist outside of CRAN)