aimp-skin-lp

LOW
maintainer badcast 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Downloads an AIMP skin archive from aimp.ru (the official AIMP website) with a pinned sha256 checksum; the extracted content is pure theme/skin data installed as non-executable files, so even if the source were swapped the worst case is cosmetic, not code execution.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): Downloads an AIMP skin archive from aimp.ru (the official AIMP website) with a pinned sha256 checksum; the extracted content is pure theme/skin data installed as non-executable files, so even if the source were swapped the worst case is cosmetic, not code execution.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source=('aimp-skin-lp-368.archive::https://aimp.ru/?do=catalog.download&id=368')

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: badcast <lmecomposer@gmail.com>
2# Generated by csv2pkgbuild.py - https://github.com/badcast/aimpskins
3
4pkgname='aimp-skin-lp'
5pkgdesc='AIMP skin: LP 1.0 (by Loran)'
6pkgver=20261001
7pkgrel=2
8arch=('any')
9url='https://github.com/badcast/aimpskins'
10license=('custom')
11groups=('AIMP_Skins')
12depends=('aimp')
13makedepends=('libarchive')
14options=('!strip' '!debug')
15_skinsdir='/opt/aimp/Skins'
16
17source=('aimp-skin-lp-368.archive::https://aimp.ru/?do=catalog.download&id=368')
18noextract=("${source[@]%%::*}")
19sha256sums=('6a9ed890594905834a9793cbe00db07dd1b85091962ab0bd48fcc8b4f8ade09d')
20
21package() {
22 local dest="$pkgdir$_skinsdir"
23 install -dm755 "$dest"
24 bsdtar -xf "$srcdir/aimp-skin-lp-368.archive" -C "$dest"
25 find "$dest" -mindepth 2 -type f -exec mv -t "$dest" {} +
26 find "$dest" -mindepth 1 -type d -empty -delete
27 find "$dest" -type d -exec chmod 755 {} +
28 find "$dest" -type f -exec chmod 644 {} +
29}
30

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion