grok-bot-bin
The package downloads a prebuilt .deb binary from a non-whitelisted host (downloads.cursor.com), which is not a standard code forge or vendor domain, creating a supply-chain risk if the host were compromised or the download redirected.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:33
"grok-bot_${pkgver}_amd64.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/grok-bot_${pkgver}_amd64.deb"
llm_review
An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is MEDIUM (confidence 90%): The package downloads a prebuilt .deb binary from a non-whitelisted host (downloads.cursor.com), which is not a standard code forge or vendor domain, creating a supply-chain risk if the host were compromised or the download redirected.
PKGBUILD
1 offending line(s) highlighted# Maintainer: falser <zjf_0731@163.com>
# Co-Maintainer: rafaeloledo <rafaeloliveiraledo@gmail.com>
pkgname=grok-bot-bin
pkgver=0.59.1
pkgrel=1
pkgdesc='Grok Bot desktop agent'
arch=('x86_64')
url='https://cursor.com'
license=('LicenseRef-Proprietary')
depends=(
gtk3
libnotify
nss
libxss
libxtst
xdg-utils
at-spi2-core
util-linux-libs
libsecret
hicolor-icon-theme
alsa-lib
libappindicator
)
makedepends=('python')
optdepends=('apparmor: load the shipped userns profile')
provides=('sand' 'grok-bot')
conflicts=('sand' 'grok-bot' 'grokbot-linux-port' 'grokbot-linux-port-bin')
replaces=('grok-bot')
options=('!strip' '!debug')
_commit=1d382f86e90289af505e2ce87b6be681aa8d2660
source=(
"grok-bot_${pkgver}_amd64.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/grok-bot_${pkgver}_amd64.deb"
grok-bot.sh
linux-tray.cjs
extract-asar.py
)
sha256sums=(
'2a9155c257d9fa78ab30d2e66977391a3c3afd2f3a06a8f4843918f055a05292'
'9b3cccfada1dbe44ce794177181515aaf328603484327ef72a914234544bfbf8'
'9ea1f1939677ec7364bc024ec4b87f8873ef41e6b1b5cec407d0a022ca3678f6'
'86e6a9d2ce60f974c002a0187fdca7f111744ff4a1187dc70ba415fe6c715942'
)
noextract=("grok-bot_${pkgver}_amd64.deb")
package() {
bsdtar -O -xf "grok-bot_${pkgver}_amd64.deb" data.tar.xz \
| bsdtar -C "${pkgdir}" -xJf -
# Keep app.asar packed. Unpacking makes the renderer load Vite chunks
# over file://, which Chromium rejects as failed dynamic imports.
# Inject a StatusNotifierItem wrapper (Omarchy/Hyprland tray) into the asar.
local _res="${pkgdir}/opt/Grok Bot/resources"
python "${srcdir}/extract-asar.py" inject-tray \
"${_res}/app.asar" "${_res}/app.asar.unpacked" \
"${srcdir}/linux-tray.cjs"
# electron-builder now ships an unconfined userns profile. Debian
# postinst copies it to /etc/apparmor.d; pacman never runs that.
install -Dm644 "${_res}/apparmor-profile" \
"${pkgdir}/etc/apparmor.d/${pkgname%-bin}"
# Debian postinst uses update-alternatives; pacman never runs it.
install -Dm755 grok-bot.sh "${pkgdir}/usr/bin/grok-bot"
ln -s grok-bot "${pkgdir}/usr/bin/sand"
sed -i 's|^Exec=.*|Exec=grok-bot %U|' \
"${pkgdir}/usr/share/applications/grok-bot.desktop"
install -Dm644 "${pkgdir}/opt/Grok Bot/LICENSE.electron.txt" \
"${pkgdir}/usr/share/licenses/${pkgname}/LICENSE.electron.txt"
install -Dm644 "${pkgdir}/opt/Grok Bot/LICENSES.chromium.html" \
"${pkgdir}/usr/share/licenses/${pkgname}/LICENSES.chromium.html"
rm -rf "${pkgdir}/usr/share/doc"
# SUID chrome-sandbox is only needed when user namespaces are unavailable
# (e.g. linux-hardened). Stock Arch kernels already provide them.
if ! { [[ -L /proc/self/ns/user ]] && unshare --user true; }; then
chmod 4755 "${pkgdir}/opt/Grok Bot/chrome-sandbox"
fi
}
Changes since previous scan
--- PKGBUILD @ 2026-09-26 00:12+++ PKGBUILD @ 2026-10-04 00:18@@ -2,7 +2,7 @@ # Co-Maintainer: rafaeloledo <rafaeloliveiraledo@gmail.com> pkgname=grok-bot-bin-pkgver=0.57.1+pkgver=0.59.1 pkgrel=1 pkgdesc='Grok Bot desktop agent' arch=('x86_64')@@ -28,7 +28,7 @@ conflicts=('sand' 'grok-bot' 'grokbot-linux-port' 'grokbot-linux-port-bin') replaces=('grok-bot') options=('!strip' '!debug')-_commit=c4074f405d36a56b406f11cc6485404ff8b395eb+_commit=1d382f86e90289af505e2ce87b6be681aa8d2660 source=( "grok-bot_${pkgver}_amd64.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/grok-bot_${pkgver}_amd64.deb" grok-bot.sh@@ -36,7 +36,7 @@ extract-asar.py ) sha256sums=(- 'ca034cc1db2526ea8727bce232818434057caca9e5a0a737721ad0bf2a5f4bf3'+ '2a9155c257d9fa78ab30d2e66977391a3c3afd2f3a06a8f4843918f055a05292' '9b3cccfada1dbe44ce794177181515aaf328603484327ef72a914234544bfbf8' '9ea1f1939677ec7364bc024ec4b87f8873ef41e6b1b5cec407d0a022ca3678f6' '86e6a9d2ce60f974c002a0187fdca7f111744ff4a1187dc70ba415fe6c715942'Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-04 00:18:08 | Medium | 2 |
| 2026-10-03 00:23:04 | Medium | 2 |
| 2026-10-02 00:00:32 | Medium | 2 |
| 2026-10-01 00:02:06 | Medium | 2 |
| 2026-09-30 00:20:07 | Medium | 2 |
| 2026-09-29 00:07:46 | Medium | 2 |
| 2026-09-28 00:28:32 | Medium | 2 |
| 2026-09-27 01:16:09 | Medium | 2 |
| 2026-09-27 00:07:07 | Medium | 2 |
| 2026-09-26 07:14:17 | Medium | 2 |
| 2026-09-26 00:12:15 | Medium | 2 |
| 2026-09-25 00:03:36 | Medium | 2 |
| 2026-09-24 05:42:19 | Medium | 2 |
| 2026-09-24 00:24:14 | Medium | 2 |
| 2026-09-23 00:28:13 | Medium | 2 |
| 2026-09-22 00:15:14 | Medium | 2 |
| 2026-09-21 00:26:32 | Medium | 2 |
| 2026-09-20 19:33:19 | Medium | 2 |
| 2026-09-20 00:25:31 | Medium | 2 |
| 2026-09-19 00:25:36 | Medium | 2 |