charles
The source is a prebuilt tarball from the official project's domain (charlesproxy.com), which is not on the analyzer's whitelist but is plausibly legitimate; the package installs only data and scripts from that source without executing arbitrary remote code.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a prebuilt tarball from the official project's domain (charlesproxy.com), which is not on the analyzer's whitelist but is plausibly legitimate; the package installs only data and scripts from that source without executing arbitrary remote code.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=(http://www.charlesproxy.com/assets/release/${pkgver}/charles-proxy-${pkgver}_$arch.tar.gz)
PKGBUILD
1 offending line(s) highlighted# Maintainer: Luis Aranguren <pizzaman@hotmail.com>
# Contributor: Jiabao Lin <me at leolin dot cn>
# Contributor: Jan-Erik Rediger <badboy at archlinux dot us>
# Contributor: Alexander Baldeck <lex@tentriplenine.com>
pkgname=charles
_name=charles-proxy5
pkgver=5.2.1
pkgrel=1
pkgdesc="Web debugging proxy application"
arch=(x86_64)
url="http://www.charlesproxy.com"
license=('LicenseRef-Charles-EULA')
depends=('java-runtime>=8' 'hicolor-icon-theme')
provides=('charles')
conflicts=('charles-bin')
source=(http://www.charlesproxy.com/assets/release/${pkgver}/charles-proxy-${pkgver}_$arch.tar.gz)
md5sums=('f2e03db5ff4445e14387bfbbc8bfaab9')
build() {
cd "$srcdir/$pkgname"
}
package() {
cd "$srcdir/$pkgname"
install -D -m755 ${srcdir}/${pkgname}/bin/charles \
${pkgdir}/usr/bin/charles
for fn in ${srcdir}/${pkgname}/lib/*.jar; do
install -D -m644 ${fn} \
${pkgdir}/usr/share/java/${pkgname}/$(basename ${fn})
done
for dim in 16x16 32x32 64x64 128x128 256x256 512x512; do
install -D -m644 ${srcdir}/${pkgname}/icon/${dim}/apps/$_name.png \
${pkgdir}/usr/share/icons/hicolor/${dim}/apps/charles.png
for mimetype in $_name-har.png $_name-pcap.png $_name-savedsession.png $_name-trace.png; do
install -D -m644 ${srcdir}/${pkgname}/icon/${dim}/mimetypes/$mimetype \
${pkgdir}/usr/share/icons/hicolor/${dim}/mimetypes/$mimetype
done
done
install -D -m644 ${srcdir}/${pkgname}/icon/128x128/apps/$_name.png \
${pkgdir}/usr/share/icons/charles128.png
install -D -m644 ${srcdir}/${pkgname}/etc/$_name.desktop \
${pkgdir}/usr/share/applications/$_name.desktop
sed -i 's/Icon=\.\..\+/Icon=charles/' ${pkgdir}/usr/share/applications/$_name.desktop
#Stop ^- from appearing in home directory
sed -i 's/\^-/\/dev\/null/' ${pkgdir}/usr/bin/charles
#Use XDG_CONFIG_HOME and if unset use ~/.config/charles rather than ~/ for .charles.config
sed -i 's/\~\/\.charles\.config\"/$\{XDG\_CONFIG\_HOME\:\-\~\/\.config\/charles\}\"\/\.charles\.config/' ${pkgdir}/usr/bin/charles
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |