katawa-shoujo-bin
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:20
"ks.tar.zst::https://cdn.fhs.sh/ks/bin/${pkgver}/%5B4ls%5D_katawa_shoujo_${pkgver}-%5Blinux-x86%5D%5BBA993979%5D.tar.zst"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The package downloads a prebuilt binary archive (containing a Ren'Py engine binary and Python libraries that are executed at runtime) from cdn.fhs.sh, which is not the official upstream host (katawa-shoujo.com). The official KS Linux download is distributed directly from the Four Leaf Studios site or mirrors like itch.io/lemmasoft, not cdn.fhs.sh. This is a personal/unofficial CDN operated by the maintainer or a third party, meaning the binary could be substituted without upstream's knowledge. A sha256 checksum is present, which mitigates tampering after the fact but does not establish trust in the source host itself — if the CDN is compromised or the maintainer rotates the file, the checksum would need to be updated. The installed content includes a native Linux x86_64 binary (the Ren'Py launcher) and Python libraries, all of which are executed on the user's system. This is a genuine supply-chain concern: executed binaries from an unofficial host. The piracy flag does not apply since Katawa Shoujo is a free, legally distributed game under CC-BY-NC-ND-3.0.
PKGBUILD
1 offending line(s) highlighted# Maintainer: snit <snit@cock.li>
# Contributor: Alice Jenkinson <virtual.aur at zero-x dot nz>
_pkgname="katawa-shoujo"
pkgname="$_pkgname-bin"
pkgver=1.3.2
pkgrel=1
pkgdesc="A bishoujo-style visual novel by Four Leaf Studios"
url="https://www.katawa-shoujo.com"
license=("CC-BY-NC-ND-3.0")
arch=("x86_64")
provides=("$_pkgname=$pkgver")
conflicts=("$_pkgname")
options=("!strip")
_pkgsrc="Katawa Shoujo-$pkgver-linux"
source=(
"ks.tar.zst::https://cdn.fhs.sh/ks/bin/${pkgver}/%5B4ls%5D_katawa_shoujo_${pkgver}-%5Blinux-x86%5D%5BBA993979%5D.tar.zst"
"katawa-shoujo.png"
)
sha256sums=(
'c76b644b9d7582b20c50d0a984e426b6a85d8c564325e73ad29637210e31e0af'
'dcd08ef958f785ac52b88a255680e385051d6b6a9626e57f00acb44021d7c0ee'
)
package() {
cd "$_pkgsrc"
# main files
install -dm755 "$pkgdir/usr/share/$_pkgname"
cp --reflink=auto -a game renpy "Katawa Shoujo.py" "$pkgdir/usr/share/$_pkgname/"
install -dm755 "$pkgdir/usr/share/$_pkgname/lib"
cp --reflink=auto -a lib/linux-x86_64 lib/pythonlib2.7 "$pkgdir/usr/share/$_pkgname/lib/"
# script
install -Dm755 /dev/stdin "$pkgdir/usr/bin/$_pkgname" << END
#!/bin/sh
BASE="/usr/share/katawa-shoujo"
LIB="\$BASE/lib/linux-x86_64"
BASEFILE="Katawa Shoujo"
exec "\$LIB/\$BASEFILE" \$RENPY_PYARGS -EO "\$BASE/\$BASEFILE.py" "\$@"
END
install -Dm644 /dev/stdin "$pkgdir/usr/share/applications/$_pkgname.desktop" << END
[Desktop Entry]
Name=Katawa Shoujo
Comment=$pkgdesc
Exec=$_pkgname
Icon=$_pkgname
Type=Application
Categories=Game;
END
# icon
install -Dm644 "$srcdir/$_pkgname.png" -t "$pkgdir/usr/share/pixmaps/"
# license
install -Dm644 LICENSE.txt "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
# manual
install -Dm644 'Game Manual.pdf' "$pkgdir/usr/share/doc/$pkgname/gamemanual.pdf"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |