clownfish
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
"$pkgname-$pkgver.zip::https://clownfish-translator.com/voicechanger/download/ClownfishConsole/linux64/ClownfishConsole(v${pkgver}z).zip"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): The PKGBUILD downloads a prebuilt binary (ClownfishConsole) from clownfish-translator.com, which is the official vendor website for Clownfish Voice Changer. However, both checksums are set to SKIP, meaning there is no integrity verification of the downloaded binary. The binary is then installed directly to /usr/bin and made executable. While the host appears to be the legitimate upstream vendor site, the combination of an unverified prebuilt binary from a third-party host with SKIP checksums constitutes a real supply-chain risk: if the host is compromised or the download is intercepted, arbitrary code would execute with user privileges. This is a textbook medium-severity concern — not clearly malicious, but a genuine code-execution risk due to lack of integrity verification of an executed binary from a non-distro-official source.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Mylloon <aur@mylloon.fr>
# shellcheck disable=SC2034,SC2148,SC2154
pkgname='clownfish'
pkgver=0.1
pkgrel=1
pkgdesc="Clownfish Voice Changer"
arch=('x86_64')
url=https://clownfish-translator.com/voicechanger/
license=('Clownfish''s License')
provides=("$pkgname")
conflicts=("$pkgname")
source_x86_64=(
"$pkgname-$pkgver.zip::https://clownfish-translator.com/voicechanger/download/ClownfishConsole/linux64/ClownfishConsole(v${pkgver}z).zip"
"pipewire.conf"
)
sha256sums_x86_64=("SKIP" "SKIP")
package() {
install -d "$pkgdir/usr/bin"
cp "$srcdir/ClownfishConsole" "$pkgdir/usr/bin/$pkgname"
install -Dm755 "$srcdir/ClownfishConsole" "$pkgdir/usr/bin/$pkgname"
# Optional pipewire nodes
if [[ -d /etc/pipewire ]]; then
loc="usr/share/pipewire/pipewire.conf.d/clownfish.conf"
install -Dm644 "pipewire.conf" "$pkgdir/$loc"
echo "Optional PipeWire configuration installed to /$loc"
echo "To apply it, restart PipeWire"
fi
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |