aimp-skin-hm-sapphire-and-hm-pure-display
Downloads an AIMP skin archive from aimp.ru (the official AIMP website) and installs it as pure data (skin files) into /opt/aimp/Skins; no code is executed from the download, and the source is the project's own official catalog, so the risk is minimal despite the non-whitelisted URL pattern.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 80%): Downloads an AIMP skin archive from aimp.ru (the official AIMP website) and installs it as pure data (skin files) into /opt/aimp/Skins; no code is executed from the download, and the source is the project's own official catalog, so the risk is minimal despite the non-whitelisted URL pattern.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=('aimp-skin-hm-sapphire-and-hm-pure-display-381.archive::https://aimp.ru/?do=catalog.download&id=381')
PKGBUILD
1 offending line(s) highlighted# Maintainer: badcast <lmecomposer@gmail.com>
# Generated by csv2pkgbuild.py - https://github.com/badcast/aimpskins
pkgname='aimp-skin-hm-sapphire-and-hm-pure-display'
pkgdesc='AIMP skin: hm_Sapphire & hm_Pure_Display 1.0 (by flon)'
pkgver=20261001
pkgrel=2
arch=('any')
url='https://github.com/badcast/aimpskins'
license=('custom')
groups=('AIMP_Skins')
depends=('aimp')
makedepends=('libarchive')
options=('!strip' '!debug')
_skinsdir='/opt/aimp/Skins'
source=('aimp-skin-hm-sapphire-and-hm-pure-display-381.archive::https://aimp.ru/?do=catalog.download&id=381')
noextract=("${source[@]%%::*}")
sha256sums=('1d4e9cc5117b536cdc8120661f752b7f15b9ce8ccc3995729fef474d32dfaf34')
package() {
local dest="$pkgdir$_skinsdir"
install -dm755 "$dest"
bsdtar -xf "$srcdir/aimp-skin-hm-sapphire-and-hm-pure-display-381.archive" -C "$dest"
find "$dest" -mindepth 2 -type f -exec mv -t "$dest" {} +
find "$dest" -mindepth 1 -type d -empty -delete
find "$dest" -type d -exec chmod 755 {} +
find "$dest" -type f -exec chmod 644 {} +
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Low | 3 |
| 2026-10-06 00:13:36 | Low | 3 |
| 2026-10-05 23:40:58 | Medium | 2 |