echeai-cli-git
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:35
"https://echeai.chimmie.k.vu/packages/zst/pkg.tar.gz"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): This PKGBUILD downloads a prebuilt binary tarball (pkg.tar.gz) from a personal/unofficial domain (echeai.chimmie.k.vu) with 'SKIP' for the checksum, meaning no integrity verification is performed. The tarball is extracted and its contents are installed directly into the system, including executables placed in /usr/bin/. This is a genuine supply-chain concern: the host is a personal domain with no verifiable trust anchor, the checksum is skipped so any substitution would go undetected, and the installed artifacts are executed binaries. The pkgver() function uses the SHA256 of the downloaded tarball as a version string, which is a creative but insufficient substitute for a proper integrity check since it only records what was downloaded, not what was expected. The package also uses 'any' architecture despite installing binaries, which is suspicious. These factors combine to a real medium-severity supply-chain risk.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Chimmie Firefly <gameplayer2019pl (at) tutamail (dot) com>
pkgname=echeai-cli-git
_pkgname=echeai-cli-git
pkgver=0
pkgrel=1
pkgdesc='Provides a CLI access to Echedey ChatAI Service.'
arch=(
'any'
)
url="https://echeai.chimmie.k.vu"
license=('MIT')
depends=(
'sed'
'curl'
'coreutils'
'jq'
)
makedepends=(
'pacman'
)
provides=(
'echeai-cli'
)
conflicts=(
'echeai-cli'
)
source=(
"https://echeai.chimmie.k.vu/packages/zst/pkg.tar.gz"
)
noextract=("pkg.tar.gz")
sha256sums=(
'SKIP'
)
pkgver() {
cd "${srcdir}"
echo 'r'"$(sha256sum pkg.tar.gz | cut -d ' ' -f 1)"
}
build() {
cd "${srcdir}"
tar -xvf pkg.tar.gz
mv default-fs "${pkgname}"
}
package() {
cd "${srcdir}"
cd "${srcdir}/${pkgname}"
mkdir -p "${pkgdir}" 2>/dev/null 3>&2
cp -rv * "${pkgdir}/"
chmod +x "${pkgdir}"/usr/bin/*
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |