gnome-mode-shift-git

LOW
maintainer orphaned 0 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

Package builds from its own GitHub repo, installs systemd user units and shell scripts to standard system paths, and the .install hook only prints informational messages; the flagged 'privileged install' is just placing a NetworkManager dispatcher script (normal for such utilities) with no actual sudo/setuid/self-update logic present.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): Package builds from its own GitHub repo, installs systemd user units and shell scripts to standard system paths, and the .install hook only prints informational messages; the flagged 'privileged install' is just placing a NetworkManager dispatcher script (normal for such utilities) with no actual sudo/setuid/self-update logic present.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium Privileged / out-of-pacman install (sudoers, setuid, or self-update) privileged_install

The package grants elevated privileges or installs an update path outside pacman: a /etc/sudoers.d rule (often passwordless), a setuid/setgid binary, or a self-update script/service that can fetch and run future code with no checksum verification. The initial install may be verified, but the ongoing privilege + update surface is a real supply-chain / privilege-escalation risk.

  • PKGBUILD:30 install -Dm644 $srcdir/$pkgname/app/home/config/systemd/user/auto-update-gnome-theme.path "$pkgdir/usr/lib/systemd/user/auto-update-gnome-theme.path"
  • PKGBUILD:31 install -Dm644 $srcdir/$pkgname/app/home/config/systemd/user/auto-update-gnome-theme.service "$pkgdir/usr/lib/systemd/user/auto-update-gnome-theme.service"
  • PKGBUILD:39 install -Dm755 $srcdir/$pkgname/app/home/local/bin/auto-update-gnome-theme.sh "$pkgdir/usr/lib/gnome-mode-shift/bin/auto-update-gnome-theme.sh"
  • .install:4 echo -e "\`systemctl --user enable --now gnome-mode-shift.service gnome-mode-shift.timer auto-update-gnome-theme.path auto-update-gnome-theme.service stop-mode-shift-timer.service\`"

PKGBUILD

3 offending line(s) highlighted
1# Maintainer: Christopher McAdams <mca.christopher@gmail.com>
2pkgname="gnome-mode-shift-git"
3pkgver=r14.6d27b63
4pkgrel=1
5pkgdesc="::Rolling release:: A Small utility to switch the selected preferred mode."
6arch=('any')
7url="https://github.com/christophermca/gnome-mode-shift/"
8license=('GPL-1.0-or-later')
9makedepends=('git')
10provides=('gnome-mode-shift.service' 'auto-update-gnome-theme.path' 'auto-update-gnome-theme.service' 'stop-mode-shift-timer.service')
11conflicts=( 'alacritty-use-theme-with-redshift'
12 'alacritty-use-theme-with-redshift-git')
13source=("$pkgname::git+https://github.com/christophermca/gnome-mode-shift.git/")
14sha256sums=('SKIP')
15depends=( 'bash'
16 'redshift')
17
18pkgver() {
19 cd "$pkgname"
20 printf "r%s.%s" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
21}
22
23 package() {
24 cd "$pkgname"
25 # options and directives that can be overridden
26 pkgdesc="::Rolling release:: Changes gnomes perferred mode based on sunrise/sunset"
27 install=gnome-mode-shift-git.install
28
29 # systemd units
30 install -Dm644 $srcdir/$pkgname/app/home/config/systemd/user/auto-update-gnome-theme.path "$pkgdir/usr/lib/systemd/user/auto-update-gnome-theme.path"
31 install -Dm644 $srcdir/$pkgname/app/home/config/systemd/user/auto-update-gnome-theme.service "$pkgdir/usr/lib/systemd/user/auto-update-gnome-theme.service"
32 install -Dm644 $srcdir/$pkgname/app/home/config/systemd/user/gnome-mode-shift.service "$pkgdir/usr/lib/systemd/user/gnome-mode-shift.service"
33 install -Dm644 $srcdir/$pkgname/app/home/config/systemd/user/gnome-mode-shift.timer "$pkgdir/usr/lib/systemd/user/gnome-mode-shift.timer"
34 install -Dm644 $srcdir/$pkgname/app/home/config/systemd/user/stop-mode-shift-timer.service "$pkgdir/usr/lib/systemd/user/stop-mode-shift-timer.service"
35
36 # scripts
37 install -Dm755 $srcdir/$pkgname/app/home/local/bin/get-sunrise-sunset.sh "$pkgdir/usr/lib/gnome-mode-shift/bin/get-sunrise-sunset.sh"
38 install -Dm755 $srcdir/$pkgname/app/home/local/bin/test-network-connection.sh "$pkgdir/usr/lib/gnome-mode-shift/bin/test-network-connection.sh"
39 install -Dm755 $srcdir/$pkgname/app/home/local/bin/auto-update-gnome-theme.sh "$pkgdir/usr/lib/gnome-mode-shift/bin/auto-update-gnome-theme.sh"
40
41 # NetworkManager requires all dispatcher scripts to be owned by root
42 install -Dm755 $srcdir/$pkgname/app/home/local/bin/revive-gnome-mode-shift.sh "$pkgdir/usr/lib/NetworkManager/dispatcher.d/revivie-gnome-mode-shift.sh"
43
44 # vars
45 install -Dm644 $srcdir/$pkgname/app/home/local/gnome-mode-shift/shared-variables.sh "$pkgdir/usr/lib/gnome-mode-shift/shared-variables.sh"
46
47 # Create directory with 755 permissins
48
49 # Includes vars file
50 # install -Dm755 -o $USER $srcdir/$pkgname/app/home/local/gnome-mode-shift/is-day-or-night "$pkgdir/$XDG_STATE_HOME/gnome-mode-shift/is-day-or-night"
51 }
52
53

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion