grok-bot-desktop
Downloads a prebuilt proprietary binary .deb from downloads.cursor.com (Cursor's infrastructure, not xAI's official domain) rather than any official xAI/Grok distribution channel, making it unverifiable as an authentic xAI release; a single SHA256 checksum is present but the binary is a closed-source Electron app from a potentially unrelated host that could be silently swapped.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:51
source=("${_debname}_${pkgver}_amd64.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/${_debname}_${pkgver}_amd64.deb")
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): Downloads a prebuilt proprietary binary .deb from downloads.cursor.com (Cursor's infrastructure, not xAI's official domain) rather than any official xAI/Grok distribution channel, making it unverifiable as an authentic xAI release; a single SHA256 checksum is present but the binary is a closed-source Electron app from a potentially unrelated host that could be silently swapped.
PKGBUILD
1 offending line(s) highlighted# Maintainer: slyfox1186 <jhollis.ga at gmail dot com>
pkgname=grok-bot-desktop
_debname=grok-bot
pkgver=0.68.1
pkgrel=1
_commit=33103062f95061ccf9c81c5b365d37ab152c3b66
pkgdesc='Desktop agent app from xAI (official .deb, app files unmodified)'
arch=('x86_64')
url='https://x.ai/bot'
license=('LicenseRef-Proprietary')
depends=(
alsa-lib
at-spi2-core
cairo
dbus
expat
glib2
glibc
gtk3
hicolor-icon-theme
libcups
libdrm
libgcc
libnotify
libsecret
libstdc++
libx11
libxcb
libxcomposite
libxdamage
libxext
libxfixes
libxkbcommon
libxrandr
libxss
libxtst
mesa
nspr
nss
pango
systemd-libs
util-linux-libs
xdg-utils
)
optdepends=('libappindicator: tray icon (GNOME also needs the AppIndicator extension)')
provides=('grok-bot' 'sand')
conflicts=('grok-bot' 'sand' 'grok-bot-bin' 'grokbot-linux-port' 'grokbot-linux-port-bin')
options=('!strip' '!debug')
install=${pkgname}.install
source=("${_debname}_${pkgver}_amd64.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/${_debname}_${pkgver}_amd64.deb")
sha256sums=('b2be8106d2b3eae07d983d5f1ca77b657accde666dc440db2a409421ecff3359')
noextract=("${_debname}_${pkgver}_amd64.deb")
package() {
bsdtar -O -xf "${_debname}_${pkgver}_amd64.deb" data.tar.xz | bsdtar -C "${pkgdir}" -xJf -
# The Debian postinst creates this link; pacman does not run postinst.
install -dm755 "${pkgdir}/usr/bin"
ln -s "/opt/Grok Bot/grok-bot" "${pkgdir}/usr/bin/grok-bot"
install -dm755 "${pkgdir}/usr/share/licenses/${pkgname}"
ln -s "/opt/Grok Bot/LICENSE.electron.txt" "${pkgdir}/usr/share/licenses/${pkgname}/"
ln -s "/opt/Grok Bot/LICENSES.chromium.html" "${pkgdir}/usr/share/licenses/${pkgname}/"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-07 14:14:59 | Medium | 3 |
| 2026-10-07 14:05:47 | Medium | 3 |