captureage-bin

LOW
maintainer Firstpick 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

The binary is downloaded from captureage.com, which is the project's own official domain, with a pinned sha256 checksum; the only concern is that it is a prebuilt Windows executable run via Proton, but it comes from the vendor's own infrastructure rather than an unrelated swappable host.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The binary is downloaded from captureage.com, which is the project's own official domain, with a pinned sha256 checksum; the only concern is that it is a prebuilt Windows executable run via Proton, but it comes from the vendor's own infrastructure rather than an unrelated swappable host.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:20 "${_archive}::https://captureage.com/api/cade/download/prod/${_archive}"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Firstpick <firstpick1992@proton.me>
2
3pkgname=captureage-bin
4pkgver=1.26.0
5pkgrel=6
6pkgdesc='Advanced spectating for Age of Empires II: Definitive Edition (Windows binary via Proton)'
7arch=('x86_64')
8url='https://captureage.com/cade'
9license=('LicenseRef-CaptureAge')
10depends=('bash' 'python' 'protontricks' 'steam')
11makedepends=('libarchive')
12options=('!strip' '!debug')
13provides=("captureage=$pkgver")
14conflicts=('captureage')
15
16_archive="CaptureAge-${pkgver}-x64.nsis.7z"
17# The API supplies a fresh signed CDN redirect for this exact release.
18# Do not replace this with /latest or persist the expiring CDN URL.
19source=(
20 "${_archive}::https://captureage.com/api/cade/download/prod/${_archive}"
21 'captureage'
22 'configure_game.py'
23 'captureage.desktop'
24 'captureage.png'
25 'captureage.reg'
26 'LICENSE'
27 'README.md'
28)
29noextract=("$_archive")
30sha256sums=('5b3b4765f4d9df06dd5cb614f0467a0212efd8b47f5dc60919fd8716745e3510'
31 'ae494feccf07742fca18f174e4bf32c07b44ced812e0f408bf2d139583b22acb'
32 '001b62f8af99bb64c11002b011842cdbd46beddf56019730a7c3f3ce479d7c9a'
33 '6ecc0cf6936dca8552492114051bfe173df3bcf86b98d111ed1eda8c474b2f91'
34 'bcf898c2e3f7949ac72ca04706b3941db4532167ff3bd27363baa8e675c99c8e'
35 '3c17f11425e8e62166a9a278622173f5f2479c2f7ef9f732a4b9d4acbd22814e'
36 '35599267d69f141d105a99e22a11d9cd65a0ea263a97fefe092366987071c25f'
37 '5bc9b6343373f5a441571f0c6f76c31d86f53e3b5311a562b9ed1dec7485c19f')
38
39prepare() {
40 mkdir -p "$srcdir/captureage-app"
41 bsdtar -xf "$srcdir/$_archive" -C "$srcdir/captureage-app"
42 # Confirm the downloaded payload agrees with the package version.
43 grep -Fq "\"version\": \"$pkgver\"" \
44 "$srcdir/captureage-app/resources/app/package.json"
45}
46
47package() {
48 install -d "$pkgdir/opt/captureage"
49 cp -a "$srcdir/captureage-app/." "$pkgdir/opt/captureage/"
50 install -Dm755 "$srcdir/captureage" "$pkgdir/usr/bin/captureage"
51 install -Dm644 "$srcdir/configure_game.py" \
52 "$pkgdir/usr/share/captureage/configure_game.py"
53 install -Dm644 "$srcdir/captureage.desktop" \
54 "$pkgdir/usr/share/applications/captureage.desktop"
55 install -Dm644 "$srcdir/captureage.png" \
56 "$pkgdir/usr/share/pixmaps/captureage.png"
57 install -Dm644 "$srcdir/captureage.reg" \
58 "$pkgdir/usr/share/captureage/captureage.reg"
59 install -Dm644 "$srcdir/LICENSE" \
60 "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
61 install -Dm644 "$srcdir/README.md" \
62 "$pkgdir/usr/share/doc/$pkgname/README.md"
63}
64

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion