luski-beta-bin
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("luski-beta.tar.gz::https://www.jacobtech.com/Updater/GetPKG?directory=Luski&branch=Beta&selfcontained=false&platform=linux-x64")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads a prebuilt binary tarball from a personal/vendor domain (jacobtech.com) via a dynamic API endpoint with SKIP checksum verification, meaning there is no integrity check on the downloaded binary. The binary is a .NET executable that gets installed and executed directly. The combination of: (1) a dynamic URL that can return different content at any time, (2) SKIP md5sums providing zero integrity guarantee, and (3) the pkgver() function making a live network call to determine the version — all from a personal domain — constitutes a genuine supply-chain risk. Any compromise of jacobtech.com or a MITM attack would result in arbitrary code execution on the user's system. This is not clearly malicious, but it is a real medium-severity supply-chain concern: an executed binary from an unofficial/personal host with no checksum verification.
PKGBUILD
1 offending line(s) highlighted# Maintainer: JacobTech <Jacob@JacobTech.com>
pkgname='luski-beta-bin'
pkgver=0.0.0.1
pkgrel=2
pkgdesc="Simple open source chat app"
arch=('x86_64')
url="https://www.jacobtech.com/Luski"
license=('GPL')
depends=('dotnet-runtime-8.0' 'curl')
provides=('luski-beta')
conflicts=('luski-beta-contained-bin')
source=("luski-beta.tar.gz::https://www.jacobtech.com/Updater/GetPKG?directory=Luski&branch=Beta&selfcontained=false&platform=linux-x64")
md5sums=('SKIP')
pkgver() {
printf "$(curl -s https://www.jacobtech.com/Updater/GetProgramVersion\?directory\=Luski\&branch\=Beta\&selfcontaind\=false\&platform\=linux-x64)"
}
package() {
cd "${srcdir}"
install -dm 755 "$pkgdir"/usr/lib/luski-beta
install -dm 755 "$pkgdir"/usr/share/applications
install -dm 755 "$pkgdir"/usr/bin
cp -r ${srcdir}/* "$pkgdir"/usr/lib/luski-beta/
touch "$pkgdir"/usr/bin/luski-beta.sh
cd "$pkgdir"/usr/bin
echo -n "#!/bin/sh
exec /usr/lib/luski-beta/Luski \"\$@\"" >> "$pkgdir"/usr/bin/luski-beta.sh
ln -s luski-beta.sh luski-beta
touch "$pkgdir/usr/share/applications/luski beta.desktop"
cd "$pkgdir"/usr/share/applications
echo -n "[Desktop Entry]
Name=Luski Beta
Version=1.0
GenericName=Luski Beta
Comment=Luski is a free opensource chat app
Exec=luski-beta %f
Terminal=false
Type=Application" >> "$pkgdir/usr/share/applications/luski beta.desktop"
chmod 755 "$pkgdir"/usr/bin/luski-beta
chmod 755 "$pkgdir"/usr/lib/luski-beta/Luski
chmod 755 "$pkgdir"/usr/bin/luski-beta.sh
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |