evox

MEDIUM
maintainer duanluan 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Downloads and installs a prebuilt proprietary binary from res.evomap.ai, a non-whitelisted vendor CDN that cannot be independently verified as the project's official release infrastructure; checksums are present but the binary is closed-source and unauditable, making it a medium supply-chain risk if the host were compromised or swapped.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source_x86_64=("${_pkgname}-linux-v${_upstream_ver}-x86_64-unknown-linux-gnu.tar.gz::https://res.evomap.ai/downloads/evox-linux/releases/1.1.0-beta.21/evox-linux-v1.1.0-beta.21-x86_64-unknown-linux-gnu.tar.gz")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 60%): Downloads and installs a prebuilt proprietary binary from res.evomap.ai, a non-whitelisted vendor CDN that cannot be independently verified as the project's official release infrastructure; checksums are present but the binary is closed-source and unauditable, making it a medium supply-chain risk if the host were compromised or swapped.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: duanluan <duanluan@outlook.com>
2
3pkgname=evox
4_pkgname=evox
5pkgver=1.1.0.beta.21
6pkgrel=3
7_upstream_ver=1.1.0-beta.21
8pkgdesc='EvoMap EvoX self-evolving swarm coding agent (beta channel)'
9arch=('x86_64' 'aarch64')
10url='https://evomap.ai/zh/evox/beta'
11license=('LicenseRef-Proprietary')
12depends=('glibc')
13options=('!strip')
14source_x86_64=("${_pkgname}-linux-v${_upstream_ver}-x86_64-unknown-linux-gnu.tar.gz::https://res.evomap.ai/downloads/evox-linux/releases/1.1.0-beta.21/evox-linux-v1.1.0-beta.21-x86_64-unknown-linux-gnu.tar.gz")
15source_aarch64=("${_pkgname}-linux-v${_upstream_ver}-aarch64-unknown-linux-gnu.tar.gz::https://res.evomap.ai/downloads/evox-linux/releases/1.1.0-beta.21/evox-linux-v1.1.0-beta.21-aarch64-unknown-linux-gnu.tar.gz")
16sha256sums_x86_64=('56c8c51d098e0f91bbd05bc36b3d5cb58e334ef98660531d2ec3e997a38ade24')
17sha256sums_aarch64=('8ae200eb0621cfedd9dcd2fa471e527b09e2a3a7f93dfd7cb83a5b7f2ad4cd74')
18
19package() {
20 local bundle_dir
21
22 case "${CARCH}" in
23 x86_64)
24 bundle_dir="${srcdir}/${_pkgname}-linux-v${_upstream_ver}-x86_64-unknown-linux-gnu"
25 ;;
26 aarch64)
27 bundle_dir="${srcdir}/${_pkgname}-linux-v${_upstream_ver}-aarch64-unknown-linux-gnu"
28 ;;
29 *)
30 printf 'unsupported architecture: %s\n' "${CARCH}" >&2
31 return 1
32 ;;
33 esac
34
35 # The release archive is an installer transport, not a runnable layout:
36 # the binary reads its release-bound entitlement from <agent-dir> and
37 # never looks next to itself, so keep the payload under /usr/lib and let
38 # the /usr/bin launcher provision ~/.evox/agent per user.
39 install -Dm755 "${bundle_dir}/evox" "${pkgdir}/usr/lib/${_pkgname}/evox"
40 install -Dm644 "${bundle_dir}/entitlement.json" "${pkgdir}/usr/lib/${_pkgname}/entitlement.json"
41 install -dm755 "${pkgdir}/usr/lib/${_pkgname}/extensions"
42 install -m644 "${bundle_dir}/extensions/"* "${pkgdir}/usr/lib/${_pkgname}/extensions/"
43 printf '%s\n' "${pkgver}" > "${pkgdir}/usr/lib/${_pkgname}/version"
44
45 install -Dm755 /dev/stdin "${pkgdir}/usr/bin/${_pkgname}" <<'SCRIPT'
46#!/bin/sh
47# evox package launcher: provisions the per-user EvoX agent directory
48# (~/.evox/agent by default) with the packaged entitlement and signed
49# extensions, then execs the pacman-managed binary.
50set -eu
51
52lib_dir=/usr/lib/evox
53packaged_version="$(cat "${lib_dir}/version" 2>/dev/null || printf 'unknown')"
54
55agent_dir="${EVOX_CODING_AGENT_DIR:-${EVOX_AGENT_DIR:-${HOME}/.evox/agent}}"
56case "${agent_dir}" in
57 '~') agent_dir="${HOME}" ;;
58 '~/'*) agent_dir="${HOME}/${agent_dir#~/}" ;;
59esac
60
61stamp_file="${agent_dir}/.evox-stamp"
62
63if [ "$(cat "${stamp_file}" 2>/dev/null)" != "${packaged_version}" ]; then
64 mkdir -p "${agent_dir}/extensions"
65
66 # drop extensions copied from an older packaged release
67 for f in "${agent_dir}/extensions"/libevox_ext_*.so \
68 "${agent_dir}/extensions"/libevox_ext_*.so.sig; do
69 if [ -e "${f}" ]; then
70 rm -f "${f}"
71 fi
72 done
73
74 # install this release's signed extensions
75 for f in "${lib_dir}/extensions"/libevox_ext_*.so; do
76 if [ -e "${f}" ]; then
77 name="${f##*/}"
78 install -m 0644 "${f}" "${agent_dir}/extensions/${name}"
79 if [ -e "${f}.sig" ]; then
80 install -m 0644 "${f}.sig" "${agent_dir}/extensions/${name}.sig"
81 fi
82 fi
83 done
84
85 # the entitlement is release-bound; upstream installs it 0600
86 install -m 0600 "${lib_dir}/entitlement.json" "${agent_dir}/entitlement.json"
87 printf '%s\n' "${packaged_version}" > "${stamp_file}"
88fi
89
90exec "${lib_dir}/evox" "$@"
91SCRIPT
92}
93

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Medium 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion