lingxi-ai-bin

MEDIUM
maintainer pika02 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

Prebuilt binary tarball (including a Node.js runtime and shell scripts) downloaded from a personal/unofficial Alibaba OSS bucket (llteac-file.oss-cn-hangzhou.aliyuncs.com) unrelated to any official WPS/Kingsoft infrastructure, with no way to verify authenticity beyond a single SHA256 checksum; the bucket owner could silently swap the tarball, and the package installs and executes the bundled binaries and scripts at install time.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source=("https://llteac-file.oss-cn-hangzhou.aliyuncs.com/wps-ai/releases/${pkgver}/${_pkgname}-${pkgver}-linux-x64.tar.gz")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 75%): Prebuilt binary tarball (including a Node.js runtime and shell scripts) downloaded from a personal/unofficial Alibaba OSS bucket (llteac-file.oss-cn-hangzhou.aliyuncs.com) unrelated to any official WPS/Kingsoft infrastructure, with no way to verify authenticity beyond a single SHA256 checksum; the bucket owner could silently swap the tarball, and the package installs and executes the bundled binaries and scripts at install time.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: pika02
2
3pkgname=lingxi-ai-bin
4_pkgname=lingxi-ai
5pkgver=1.4.7
6pkgrel=1
7pkgdesc="WPS Office AI Agent 插件(灵犀AI),支持多种大模型、MCP与本地化部署"
8arch=('x86_64')
9url="https://wps-ai.llteac.cn"
10license=('unknown')
11depends=('bash' 'rsync')
12optdepends=('wps-office: 国际版基础依赖'
13 'wps-office-cn: 国内版体验更好,支持更多API')
14options=('!strip')
15source=("https://llteac-file.oss-cn-hangzhou.aliyuncs.com/wps-ai/releases/${pkgver}/${_pkgname}-${pkgver}-linux-x64.tar.gz")
16sha256sums=('415e73b0b19ae02dfae646ac426e5164410b0dc072180aa4a1435ded679e07dd')
17install=${pkgname}.install
18
19package() {
20 install -d "${pkgdir}/opt/${_pkgname}"
21 cd "${srcdir}/${_pkgname}-${pkgver}" || exit
22 cp -a * "${pkgdir}/opt/${_pkgname}/"
23 chmod +x "${pkgdir}/opt/${_pkgname}/install.sh"
24 chmod +x "${pkgdir}/opt/${_pkgname}/uninstall.sh"
25 chmod +x "${pkgdir}/opt/${_pkgname}/plugin/runtime/node-linux-x64/bin/node"
26 find "${pkgdir}/opt/${_pkgname}/plugin/tools/" -name "*.sh" -exec chmod +x {} \;
27}
28

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Medium 3
2026-10-06 00:13:36 Medium 3
2026-10-05 23:40:58 Medium 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion