aimp-skin-sophie

LOW
maintainer badcast 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Downloads an AIMP skin archive from aimp.ru (the official AIMP website) and installs it as pure data (skin files) into /opt/aimp/Skins; the content is never executed, so even if the source were swapped the worst case is cosmetic, and the checksum is present for verification.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 85%): Downloads an AIMP skin archive from aimp.ru (the official AIMP website) and installs it as pure data (skin files) into /opt/aimp/Skins; the content is never executed, so even if the source were swapped the worst case is cosmetic, and the checksum is present for verification.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:17 source=('aimp-skin-sophie-364.archive::https://aimp.ru/?do=catalog.download&id=364')

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: badcast <lmecomposer@gmail.com>
2# Generated by csv2pkgbuild.py - https://github.com/badcast/aimpskins
3
4pkgname='aimp-skin-sophie'
5pkgdesc='AIMP skin: Sophie 1.2 (by Hayo Tee (aka HX722))'
6pkgver=20261001
7pkgrel=2
8arch=('any')
9url='https://github.com/badcast/aimpskins'
10license=('custom')
11groups=('AIMP_Skins')
12depends=('aimp')
13makedepends=('libarchive')
14options=('!strip' '!debug')
15_skinsdir='/opt/aimp/Skins'
16
17source=('aimp-skin-sophie-364.archive::https://aimp.ru/?do=catalog.download&id=364')
18noextract=("${source[@]%%::*}")
19sha256sums=('fcbaa6770b29b89f0a0a5bdc0822eb3d60117a987b383b2198b4e2b8ae92416d')
20
21package() {
22 local dest="$pkgdir$_skinsdir"
23 install -dm755 "$dest"
24 bsdtar -xf "$srcdir/aimp-skin-sophie-364.archive" -C "$dest"
25 find "$dest" -mindepth 2 -type f -exec mv -t "$dest" {} +
26 find "$dest" -mindepth 1 -type d -empty -delete
27 find "$dest" -type d -exec chmod 755 {} +
28 find "$dest" -type f -exec chmod 644 {} +
29}
30

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion