capture-studio-bin
Installs a prebuilt proprietary binary (Electron/Flatpak bundle) downloaded from downloads.tenzen.studio, which is the project's own domain but is a small/new vendor with few AUR votes; the binary is not independently verifiable beyond the provided sha256sum, making it a medium-risk prebuilt from a plausible but unestablished official source.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:21
source=("${_bundle}::https://downloads.tenzen.studio/desktop/stable/linux/${pkgver}/${_bundle}")
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 65%): Installs a prebuilt proprietary binary (Electron/Flatpak bundle) downloaded from downloads.tenzen.studio, which is the project's own domain but is a small/new vendor with few AUR votes; the binary is not independently verifiable beyond the provided sha256sum, making it a medium-risk prebuilt from a plausible but unestablished official source.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Felitendo
# This PKGBUILD is updated automatically:
# https://git.felo.gg/Felitendo/PKGBUILDS
pkgname=capture-studio-bin
_pkgname=tenzen
pkgver=0.1.32
pkgrel=1
pkgdesc="Record and edit product demos: cut pauses, add zooms and captions (upstream Flatpak bundle)"
arch=('x86_64')
url="https://tenzen.studio"
license=('LicenseRef-proprietary')
depends=('gtk3' 'nss' 'alsa-lib' 'ffmpeg' 'python-xlib')
optdepends=('libpulse: record system audio')
makedepends=('ostree' 'asar')
provides=('capture-studio')
# called tenzen-studio-bin on the AUR before
conflicts=('capture-studio' 'tenzen-studio-bin')
options=('!strip' '!debug')
_bundle="Capture-Studio-${pkgver}-linux-x64.flatpak"
source=("${_bundle}::https://downloads.tenzen.studio/desktop/stable/linux/${pkgver}/${_bundle}")
noextract=("${_bundle}")
sha256sums=('80958f46ebcec4197ca77e759f98ca7e6f496205070be57c487c1fa463624e3b')
prepare() {
# A Flatpak bundle is an OSTree static delta carrying a single commit:
# apply it to a throwaway repository and check that commit out.
rm -rf repo flatpak
ostree init --repo=repo --mode=bare-user-only
ostree static-delta apply-offline --repo=repo "${_bundle}"
local _commit
_commit="$(find repo/objects -name '*.commit')"
_commit="$(basename "$(dirname "${_commit}")")$(basename "${_commit}" .commit)"
ostree checkout --repo=repo --user-mode "${_commit}" flatpak
# the bundle exports no icon - the app's own is only inside app.asar
asar extract-file flatpak/files/lib/com.tenzen.desktop/resources/app.asar \
dist/assets/brand/icon.png
}
package() {
install -d "${pkgdir}/opt/${pkgname}"
cp -a "${srcdir}/flatpak/files/lib/com.tenzen.desktop/." "${pkgdir}/opt/${pkgname}/"
install -d "${pkgdir}/usr/bin"
ln -s "/opt/${pkgname}/${_pkgname}" "${pkgdir}/usr/bin/${_pkgname}"
# named after the app's desktopName, so windows are matched to the entry
install -Dm644 "${srcdir}/flatpak/files/share/applications/com.tenzen.desktop.desktop" \
"${pkgdir}/usr/share/applications/${_pkgname}.desktop"
sed -i \
-e "s|^Exec=.*|Exec=${_pkgname} %U|" \
-e "s|^Icon=.*|Icon=${_pkgname}|" \
"${pkgdir}/usr/share/applications/${_pkgname}.desktop"
# 1024x1024, which the hicolor theme has no directory for
install -Dm644 "${srcdir}/icon.png" "${pkgdir}/usr/share/pixmaps/${_pkgname}.png"
# A custom licence has to ship its terms. Upstream publishes none as a file,
# so what goes in is the reference to the terms it is used under, next to
# the notices for everything bundled with it, which the app dir does carry.
install -Dm644 /dev/stdin "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE" <<'EOF'
Capture Studio is proprietary software, distributed by Tenzen Studio.
It is not covered by a free-software licence: use is governed by the terms
of service the vendor publishes, and redistribution of the build this
package installs is not granted by them.
Terms of service: https://tenzen.studio/legal/terms-of-service/
EOF
ln -s "/opt/${pkgname}/resources/THIRD_PARTY_NOTICES.txt" \
"${pkgdir}/usr/share/licenses/${pkgname}/THIRD_PARTY_NOTICES.txt"
ln -s "/opt/${pkgname}/LICENSE.electron.txt" \
"${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.electron.txt"
ln -s "/opt/${pkgname}/LICENSES.chromium.html" \
"${pkgdir}/usr/share/licenses/${pkgname}/LICENSES.chromium.html"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Medium | 3 |
| 2026-10-06 00:13:36 | Low | 3 |
| 2026-10-05 23:40:58 | Medium | 2 |