chayuan-wps-addon-bin

MEDIUM
maintainer pika02 0 votes scanned 2026-10-08 20:12:27.795946
View on AUR
Why flagged

Installs a prebuilt binary .deb from aidooo.com (a non-standard, unverifiable personal/commercial host unrelated to any major project infrastructure), extracts and executes bundled binaries and shell scripts from it; while checksums are present, the host is not official/auditable infrastructure and the package runs arbitrary prebuilt executables and sidecar binaries at install/runtime.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source=("https://aidooo.com/downloads/chayuan/addon/linux-amd64/chayuan-${pkgver}-linux-x64.deb"
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 72%): Installs a prebuilt binary .deb from aidooo.com (a non-standard, unverifiable personal/commercial host unrelated to any major project infrastructure), extracts and executes bundled binaries and shell scripts from it; while checksums are present, the host is not official/auditable infrastructure and the package runs arbitrary prebuilt executables and sidecar binaries at install/runtime.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: pika02
2
3pkgname=chayuan-wps-addon-bin
4_pkgname=chayuan-wps-addon
5pkgver=5.1.4
6pkgrel=1
7pkgdesc="Chayuan AI WPS Writer JS add-in & MCP sidecar"
8arch=('x86_64')
9url="https://aidooo.com/products/chayuan"
10license=('unknown')
11depends=('python' 'bash')
12optdepends=('wps-office: WPS 基础依赖'
13 'wps-office-cn: WPS 国内版体验更好')
14options=('!strip')
15source=("https://aidooo.com/downloads/chayuan/addon/linux-amd64/chayuan-${pkgver}-linux-x64.deb"
16 "arch-user-init.sh"
17 "chayuan-mcp.service")
18sha256sums=('c93adddf7331d5baf18acdafc6f486ac996f2242155275c4df7700329597a1f8'
19 '601cf125bb287b1417f37d6626b1e71853b307a42474d7c946162a5ec07e6f24'
20 '83818411f25f7c0b910897fb7062039946233b3690622f0a2026e38b9b89a720')
21
22install=${pkgname}.install
23
24package() {
25 # 解压 deb 数据包到打包目录
26 bsdtar -xf "${srcdir}/data.tar.xz" -C "${pkgdir}"
27
28 # 修复官方包中可能丢失的执行权限
29 chmod -R a+rX "${pkgdir}/opt/${_pkgname}"
30 chmod +x "${pkgdir}/opt/${_pkgname}/chayuan_${pkgver}/mcp-sidecar/bin/"*
31 chmod +x "${pkgdir}/opt/${_pkgname}/chayuan_${pkgver}/mcp-sidecar/"*.sh
32
33 # 安装自定义初始化脚本,并动态注入版本号
34 install -d "${pkgdir}/opt/${_pkgname}"
35 sed "s/@PKGVER@/${pkgver}/g" "${srcdir}/arch-user-init.sh" > "${pkgdir}/opt/${_pkgname}/arch-user-init.sh"
36 chmod 755 "${pkgdir}/opt/${_pkgname}/arch-user-init.sh"
37
38 # 安装 Systemd User Service 模板
39 install -Dm644 "${srcdir}/chayuan-mcp.service" \
40 "${pkgdir}/usr/lib/systemd/user/chayuan-mcp.service"
41}
42

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 20:12:27 Medium 3
2026-10-08 20:09:40 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion