grok-bot-desktop

MEDIUM
maintainer slyfox1186 0 votes scanned 2026-10-07 14:14:59.268871
View on AUR
Why flagged

Downloads a prebuilt proprietary binary .deb from downloads.cursor.com (Cursor's infrastructure, not xAI's official domain) rather than any official xAI/Grok distribution channel, making it unverifiable as an authentic xAI release; a single SHA256 checksum is present but the binary is a closed-source Electron app from a potentially unrelated host that could be silently swapped.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:51 source=("${_debname}_${pkgver}_amd64.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/${_debname}_${pkgver}_amd64.deb")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): Downloads a prebuilt proprietary binary .deb from downloads.cursor.com (Cursor's infrastructure, not xAI's official domain) rather than any official xAI/Grok distribution channel, making it unverifiable as an authentic xAI release; a single SHA256 checksum is present but the binary is a closed-source Electron app from a potentially unrelated host that could be silently swapped.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: slyfox1186 <jhollis.ga at gmail dot com>
2
3pkgname=grok-bot-desktop
4_debname=grok-bot
5pkgver=0.68.1
6pkgrel=1
7_commit=33103062f95061ccf9c81c5b365d37ab152c3b66
8pkgdesc='Desktop agent app from xAI (official .deb, app files unmodified)'
9arch=('x86_64')
10url='https://x.ai/bot'
11license=('LicenseRef-Proprietary')
12depends=(
13 alsa-lib
14 at-spi2-core
15 cairo
16 dbus
17 expat
18 glib2
19 glibc
20 gtk3
21 hicolor-icon-theme
22 libcups
23 libdrm
24 libgcc
25 libnotify
26 libsecret
27 libstdc++
28 libx11
29 libxcb
30 libxcomposite
31 libxdamage
32 libxext
33 libxfixes
34 libxkbcommon
35 libxrandr
36 libxss
37 libxtst
38 mesa
39 nspr
40 nss
41 pango
42 systemd-libs
43 util-linux-libs
44 xdg-utils
45)
46optdepends=('libappindicator: tray icon (GNOME also needs the AppIndicator extension)')
47provides=('grok-bot' 'sand')
48conflicts=('grok-bot' 'sand' 'grok-bot-bin' 'grokbot-linux-port' 'grokbot-linux-port-bin')
49options=('!strip' '!debug')
50install=${pkgname}.install
51source=("${_debname}_${pkgver}_amd64.deb::https://downloads.cursor.com/grokbot/stable/${_commit}/linux/x64/${_debname}_${pkgver}_amd64.deb")
52sha256sums=('b2be8106d2b3eae07d983d5f1ca77b657accde666dc440db2a409421ecff3359')
53noextract=("${_debname}_${pkgver}_amd64.deb")
54
55package() {
56 bsdtar -O -xf "${_debname}_${pkgver}_amd64.deb" data.tar.xz | bsdtar -C "${pkgdir}" -xJf -
57
58 # The Debian postinst creates this link; pacman does not run postinst.
59 install -dm755 "${pkgdir}/usr/bin"
60 ln -s "/opt/Grok Bot/grok-bot" "${pkgdir}/usr/bin/grok-bot"
61
62 install -dm755 "${pkgdir}/usr/share/licenses/${pkgname}"
63 ln -s "/opt/Grok Bot/LICENSE.electron.txt" "${pkgdir}/usr/share/licenses/${pkgname}/"
64 ln -s "/opt/Grok Bot/LICENSES.chromium.html" "${pkgdir}/usr/share/licenses/${pkgname}/"
65}
66

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 14:14:59 Medium 3
2026-10-07 14:05:47 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion