agentics-desktop

MEDIUM
maintainer Connor 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads a prebuilt AppImage from a non-standard, non-whitelisted host (repo.agentics.co.za), which is an unverifiable executable artifact that could be silently replaced, posing a supply-chain risk.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("agentics-desktop-0.1.46-x86_64.AppImage::https://repo.agentics.co.za/x86_64/agentics-desktop-0.1.46-x86_64.AppImage")
Medium AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt AppImage from a non-standard, non-whitelisted host (repo.agentics.co.za), which is an unverifiable executable artifact that could be silently replaced, posing a supply-chain risk.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Connor Etherington <connor@agentics.co.za>
2# ---
3pkgname=agentics-desktop
4pkgver=0.1.46
5pkgrel=1
6pkgdesc="Agentics Desktop - the PowerBoard wallpaper companion and desktop agent host"
7arch=('x86_64')
8url="https://agentics.co.za"
9license=('custom')
10depends=()
11options=('!strip' '!debug')
12source=("agentics-desktop-0.1.46-x86_64.AppImage::https://repo.agentics.co.za/x86_64/agentics-desktop-0.1.46-x86_64.AppImage")
13sha512sums=('14b6770bbec241fbb6f537f3b6938a6498f15919701e597fa4ad4aa54e5524eff0bb120e1c2be0cb0fc7917e2272490b6ebef44b30a58ae7e3f2b28eddbb13bb')
14
15package() {
16 install -Dm755 "$srcdir/agentics-desktop-0.1.46-x86_64.AppImage" "$pkgdir/opt/agentics/AgenticsDesktop.AppImage"
17 install -dm755 "$pkgdir/usr/bin"
18 printf '%s\n' '#!/bin/sh' 'exec /opt/agentics/AgenticsDesktop.AppImage "$@"' > "$pkgdir/usr/bin/agentics-desktop"
19 chmod 755 "$pkgdir/usr/bin/agentics-desktop"
20}
21

Changes since previous scan

--- PKGBUILD @ 2026-08-30 00:04
+++ PKGBUILD @ 2026-09-17 00:27
@@ -1,7 +1,7 @@
# Maintainer: Connor Etherington <connor@agentics.co.za>
# ---
pkgname=agentics-desktop
-pkgver=0.1.45
+pkgver=0.1.46
pkgrel=1
pkgdesc="Agentics Desktop - the PowerBoard wallpaper companion and desktop agent host"
arch=('x86_64')
@@ -9,11 +9,11 @@
license=('custom')
depends=()
options=('!strip' '!debug')
-source=("agentics-desktop-0.1.45-x86_64.AppImage::https://repo.agentics.co.za/x86_64/agentics-desktop-0.1.45-x86_64.AppImage")
-sha512sums=('6c5e1b054c7b1277f91648a804693aae5aa579ee5c493c0a39ad30b89849ec0c775250bcc160e5cb34dcfe734fd08ac96e9c609e6e11d540577664dfeceb3af0')
+source=("agentics-desktop-0.1.46-x86_64.AppImage::https://repo.agentics.co.za/x86_64/agentics-desktop-0.1.46-x86_64.AppImage")
+sha512sums=('14b6770bbec241fbb6f537f3b6938a6498f15919701e597fa4ad4aa54e5524eff0bb120e1c2be0cb0fc7917e2272490b6ebef44b30a58ae7e3f2b28eddbb13bb')
package() {
- install -Dm755 "$srcdir/agentics-desktop-0.1.45-x86_64.AppImage" "$pkgdir/opt/agentics/AgenticsDesktop.AppImage"
+ install -Dm755 "$srcdir/agentics-desktop-0.1.46-x86_64.AppImage" "$pkgdir/opt/agentics/AgenticsDesktop.AppImage"
install -dm755 "$pkgdir/usr/bin"
printf '%s\n' '#!/bin/sh' 'exec /opt/agentics/AgenticsDesktop.AppImage "$@"' > "$pkgdir/usr/bin/agentics-desktop"
chmod 755 "$pkgdir/usr/bin/agentics-desktop"

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Medium 2
2026-09-16 00:03:17 Medium 2
2026-09-15 00:25:31 Medium 2
2026-09-14 00:27:57 Medium 2
2026-09-13 00:19:54 Medium 2
2026-09-12 00:25:17 Medium 2
2026-09-11 00:19:22 Medium 2
2026-09-10 00:22:44 Medium 2
2026-09-09 00:04:09 Medium 2
2026-09-08 00:18:08 Medium 2
2026-09-07 00:30:15 Medium 2
2026-09-06 00:17:06 Medium 2
2026-09-05 00:16:27 Medium 2
2026-09-04 00:03:13 Medium 2
2026-09-03 00:15:47 Medium 2
2026-09-02 00:02:31 Medium 2
2026-09-01 00:11:19 Medium 2
2026-08-31 00:19:57 Medium 2
2026-08-30 01:41:08 Medium 2
2026-08-30 00:04:14 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion