aimp-skin-sambakati

LOW
maintainer badcast 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Downloads an AIMP skin archive from aimp.ru (the official AIMP website) and installs it as pure data (skin files) into /opt/aimp/Skins; no code is executed from the download, and the source is the project's own official catalog, making this a normal skin-packaging pattern with minimal risk.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): Downloads an AIMP skin archive from aimp.ru (the official AIMP website) and installs it as pure data (skin files) into /opt/aimp/Skins; no code is executed from the download, and the source is the project's own official catalog, making this a normal skin-packaging pattern with minimal risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source=('aimp-skin-sambakati-689.archive::https://aimp.ru/?do=catalog.download&id=689')

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: badcast <lmecomposer@gmail.com>
2# Generated by csv2pkgbuild.py - https://github.com/badcast/aimpskins
3
4pkgname='aimp-skin-sambakati'
5pkgdesc='AIMP skin: Sambakati 1.0 (by amdpastrana)'
6pkgver=20261001
7pkgrel=2
8arch=('any')
9url='https://github.com/badcast/aimpskins'
10license=('custom')
11groups=('AIMP_Skins')
12depends=('aimp')
13makedepends=('libarchive')
14options=('!strip' '!debug')
15_skinsdir='/opt/aimp/Skins'
16
17source=('aimp-skin-sambakati-689.archive::https://aimp.ru/?do=catalog.download&id=689')
18noextract=("${source[@]%%::*}")
19sha256sums=('bc793cc468e610d6593991a9115389838064251a37ec7545bff4dd4eee5d2365')
20
21package() {
22 local dest="$pkgdir$_skinsdir"
23 install -dm755 "$dest"
24 bsdtar -xf "$srcdir/aimp-skin-sambakati-689.archive" -C "$dest"
25 find "$dest" -mindepth 2 -type f -exec mv -t "$dest" {} +
26 find "$dest" -mindepth 1 -type d -empty -delete
27 find "$dest" -type d -exec chmod 755 {} +
28 find "$dest" -type f -exec chmod 644 {} +
29}
30

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion