gentics

maintainer Connor · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged A prebuilt AppImage binary is downloaded from a personal/project-owned but non-official-forge host (repo.agentics.co.za) that could be silently swapped; the AppImage runs arbitrary code at launch and there is no way to verify its contents beyond the provided checksum, making this a supply-chain risk typical of unverifiable prebuilt executables from non-established infrastructure.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:12 source=("gentics-0.1.66-x86_64.AppImage::https://repo.agentics.co.za/x86_64/gentics-0.1.66-x86_64.AppImage")
MEDIUM AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 75%): A prebuilt AppImage binary is downloaded from a personal/project-owned but non-official-forge host (repo.agentics.co.za) that could be silently swapped; the AppImage runs arbitrary code at launch and there is no way to verify its contents beyond the provided checksum, making this a supply-chain risk typical of unverifiable prebuilt executables from non-established infrastructure.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Connor Etherington <connor@agentics.co.za>
2# ---
3pkgname=gentics
4pkgver=0.1.66
5pkgrel=1
6pkgdesc="Agentics - the voice-driven AI platform launcher, the desktop front door for the entire Agentics ecosystem"
7arch=('x86_64')
8url="https://agentics.co.za"
9license=('custom')
10depends=()
11options=('!strip' '!debug')
12source=("gentics-0.1.66-x86_64.AppImage::https://repo.agentics.co.za/x86_64/gentics-0.1.66-x86_64.AppImage")
13sha512sums=('019ce49342cc553c1b2a0ee4a79a228340b2db48f809217238cee7713294abef955833525de68980ae152ef9d9421fffc47065986bc88d300b865b92a8340669')
14
15package() {
16 install -Dm755 "$srcdir/gentics-0.1.66-x86_64.AppImage" "$pkgdir/opt/agentics/Agentics.AppImage"
17 install -dm755 "$pkgdir/usr/bin"
18 printf '%s\n' '#!/bin/sh' 'exec /opt/agentics/Agentics.AppImage "$@"' > "$pkgdir/usr/bin/agentics"
19 chmod 755 "$pkgdir/usr/bin/agentics"
20 ln -s agentics "$pkgdir/usr/bin/gentics"
21 install -dm755 "$pkgdir/usr/share/applications"
22 printf '%s\n' \
23 '[Desktop Entry]' 'Type=Application' 'Name=Agentics' \
24 'Comment=Voice-driven AI platform' 'Exec=/usr/bin/agentics %U' \
25 'Icon=agentics' 'Categories=Utility;Network;AudioVideo;' 'Terminal=false' \
26 > "$pkgdir/usr/share/applications/agentics.desktop"
27}
28

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 3
2026-07-28 00:07:28 MEDIUM 3
2026-07-27 00:24:32 MEDIUM 3
2026-07-26 00:07:32 MEDIUM 3
2026-07-25 00:13:44 MEDIUM 3
2026-07-24 00:02:28 MEDIUM 3
2026-07-23 00:14:47 MEDIUM 3
2026-07-22 00:29:32 MEDIUM 3
2026-07-21 00:24:15 MEDIUM 3
2026-07-20 00:19:49 MEDIUM 3
2026-07-19 00:17:08 MEDIUM 3
2026-07-18 00:14:48 MEDIUM 3
2026-07-17 00:06:16 MEDIUM 3
2026-07-16 00:05:41 MEDIUM 3
2026-07-15 05:49:33 MEDIUM 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion