captureage-bin
The binary is downloaded from captureage.com, which is the project's own official domain, with a pinned sha256 checksum; the only concern is that it is a prebuilt Windows executable run via Proton, but it comes from the vendor's own infrastructure rather than an unrelated swappable host.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The binary is downloaded from captureage.com, which is the project's own official domain, with a pinned sha256 checksum; the only concern is that it is a prebuilt Windows executable run via Proton, but it comes from the vendor's own infrastructure rather than an unrelated swappable host.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:20
"${_archive}::https://captureage.com/api/cade/download/prod/${_archive}"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Firstpick <firstpick1992@proton.me>
pkgname=captureage-bin
pkgver=1.26.0
pkgrel=6
pkgdesc='Advanced spectating for Age of Empires II: Definitive Edition (Windows binary via Proton)'
arch=('x86_64')
url='https://captureage.com/cade'
license=('LicenseRef-CaptureAge')
depends=('bash' 'python' 'protontricks' 'steam')
makedepends=('libarchive')
options=('!strip' '!debug')
provides=("captureage=$pkgver")
conflicts=('captureage')
_archive="CaptureAge-${pkgver}-x64.nsis.7z"
# The API supplies a fresh signed CDN redirect for this exact release.
# Do not replace this with /latest or persist the expiring CDN URL.
source=(
"${_archive}::https://captureage.com/api/cade/download/prod/${_archive}"
'captureage'
'configure_game.py'
'captureage.desktop'
'captureage.png'
'captureage.reg'
'LICENSE'
'README.md'
)
noextract=("$_archive")
sha256sums=('5b3b4765f4d9df06dd5cb614f0467a0212efd8b47f5dc60919fd8716745e3510'
'ae494feccf07742fca18f174e4bf32c07b44ced812e0f408bf2d139583b22acb'
'001b62f8af99bb64c11002b011842cdbd46beddf56019730a7c3f3ce479d7c9a'
'6ecc0cf6936dca8552492114051bfe173df3bcf86b98d111ed1eda8c474b2f91'
'bcf898c2e3f7949ac72ca04706b3941db4532167ff3bd27363baa8e675c99c8e'
'3c17f11425e8e62166a9a278622173f5f2479c2f7ef9f732a4b9d4acbd22814e'
'35599267d69f141d105a99e22a11d9cd65a0ea263a97fefe092366987071c25f'
'5bc9b6343373f5a441571f0c6f76c31d86f53e3b5311a562b9ed1dec7485c19f')
prepare() {
mkdir -p "$srcdir/captureage-app"
bsdtar -xf "$srcdir/$_archive" -C "$srcdir/captureage-app"
# Confirm the downloaded payload agrees with the package version.
grep -Fq "\"version\": \"$pkgver\"" \
"$srcdir/captureage-app/resources/app/package.json"
}
package() {
install -d "$pkgdir/opt/captureage"
cp -a "$srcdir/captureage-app/." "$pkgdir/opt/captureage/"
install -Dm755 "$srcdir/captureage" "$pkgdir/usr/bin/captureage"
install -Dm644 "$srcdir/configure_game.py" \
"$pkgdir/usr/share/captureage/configure_game.py"
install -Dm644 "$srcdir/captureage.desktop" \
"$pkgdir/usr/share/applications/captureage.desktop"
install -Dm644 "$srcdir/captureage.png" \
"$pkgdir/usr/share/pixmaps/captureage.png"
install -Dm644 "$srcdir/captureage.reg" \
"$pkgdir/usr/share/captureage/captureage.reg"
install -Dm644 "$srcdir/LICENSE" \
"$pkgdir/usr/share/licenses/$pkgname/LICENSE"
install -Dm644 "$srcdir/README.md" \
"$pkgdir/usr/share/doc/$pkgname/README.md"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Low | 3 |
| 2026-10-06 00:13:36 | Low | 3 |
| 2026-10-05 23:40:58 | Medium | 2 |