lingxi-ai-bin
Prebuilt binary tarball (including a Node.js runtime and shell scripts) downloaded from a personal/unofficial Alibaba OSS bucket (llteac-file.oss-cn-hangzhou.aliyuncs.com) unrelated to any official WPS/Kingsoft infrastructure, with no way to verify authenticity beyond a single SHA256 checksum; the bucket owner could silently swap the tarball, and the package installs and executes the bundled binaries and scripts at install time.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:15
source=("https://llteac-file.oss-cn-hangzhou.aliyuncs.com/wps-ai/releases/${pkgver}/${_pkgname}-${pkgver}-linux-x64.tar.gz")
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 75%): Prebuilt binary tarball (including a Node.js runtime and shell scripts) downloaded from a personal/unofficial Alibaba OSS bucket (llteac-file.oss-cn-hangzhou.aliyuncs.com) unrelated to any official WPS/Kingsoft infrastructure, with no way to verify authenticity beyond a single SHA256 checksum; the bucket owner could silently swap the tarball, and the package installs and executes the bundled binaries and scripts at install time.
PKGBUILD
1 offending line(s) highlighted# Maintainer: pika02
pkgname=lingxi-ai-bin
_pkgname=lingxi-ai
pkgver=1.4.7
pkgrel=1
pkgdesc="WPS Office AI Agent 插件(灵犀AI),支持多种大模型、MCP与本地化部署"
arch=('x86_64')
url="https://wps-ai.llteac.cn"
license=('unknown')
depends=('bash' 'rsync')
optdepends=('wps-office: 国际版基础依赖'
'wps-office-cn: 国内版体验更好,支持更多API')
options=('!strip')
source=("https://llteac-file.oss-cn-hangzhou.aliyuncs.com/wps-ai/releases/${pkgver}/${_pkgname}-${pkgver}-linux-x64.tar.gz")
sha256sums=('415e73b0b19ae02dfae646ac426e5164410b0dc072180aa4a1435ded679e07dd')
install=${pkgname}.install
package() {
install -d "${pkgdir}/opt/${_pkgname}"
cd "${srcdir}/${_pkgname}-${pkgver}" || exit
cp -a * "${pkgdir}/opt/${_pkgname}/"
chmod +x "${pkgdir}/opt/${_pkgname}/install.sh"
chmod +x "${pkgdir}/opt/${_pkgname}/uninstall.sh"
chmod +x "${pkgdir}/opt/${_pkgname}/plugin/runtime/node-linux-x64/bin/node"
find "${pkgdir}/opt/${_pkgname}/plugin/tools/" -name "*.sh" -exec chmod +x {} \;
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Medium | 3 |
| 2026-10-06 00:13:36 | Medium | 3 |
| 2026-10-05 23:40:58 | Medium | 3 |