An external my-kuhbs repository is trusted code. It can contain hooks that run in dom0 and scripts that run as root inside Qubes OS VMs. An AI review can help you find risky behavior, but it cannot prove that a repository is safe.
Review one exact commit
Audit the repository outside KUHBS before adding it. Give the AI reviewer the repository URL, branch, and full commit ID you intend to use. Ask it to read files without editing or running them.
Do not submit passwords, private keys, tokens, personal files, or private repository contents to an AI service you do not trust.
Use a read-only audit prompt
Read-only audit of this KUHBS repository. Do not edit or run files. Read README-AUDIT.md first if present, then every tracked kuhb.yml, hook, setup script, template, launcher, firewall rule, and README. Explain each KUHB and every generated KUH. List every dom0/root command, device or network change, download source, secret-handling path, persistent and backup path, and Remove cleanup. Cite exact files and lines. End with the commit reviewed, files reviewed, concrete blockers, and a manual checklist. Do not claim the repository is safe merely because no issue was found.
Verify the report yourself
Confirm that the report names the exact commit and every tracked file. Follow its file and line references, inspect downloads and privileged commands yourself, and resolve every blocker before continuing. If the repository changes, audit the new full commit again.
Use AI as one review step, not as the final trust decision. The repository owner, the AI service, or both can miss malicious or unsafe code.
Next: Adding a Repository .