luski-beta-bin
This PKGBUILD downloads a prebuilt binary tarball from a personal/vendor domain (jacobtech.com) via a dynamic API endpoint with SKIP checksum verification, meaning there is no integrity check on the downloaded binary. The binary is a .NET executable that gets installed and executed directly. The combination of: (1) a dynamic URL that can return different content at any time, (2) SKIP md5sums providing zero integrity guarantee, and (3) the pkgver() function making a live network call to determine the version — all from a personal domain — constitutes a genuine supply-chain risk. Any compromise of jacobtech.com or a MITM attack would result in arbitrary code execution on the user's system. This is not clearly malicious, but it is a real medium-severity supply-chain concern: an executed binary from an unofficial/personal host with no checksum verification.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
source=("luski-beta.tar.gz::https://www.jacobtech.com/Updater/GetPKG?directory=Luski&branch=Beta&selfcontained=false&platform=linux-x64")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads a prebuilt binary tarball from a personal/vendor domain (jacobtech.com) via a dynamic API endpoint with SKIP checksum verification, meaning there is no integrity check on the downloaded binary. The binary is a .NET executable that gets installed and executed directly. The combination of: (1) a dynamic URL that can return different content at any time, (2) SKIP md5sums providing zero integrity guarantee, and (3) the pkgver() function making a live network call to determine the version — all from a personal domain — constitutes a genuine supply-chain risk. Any compromise of jacobtech.com or a MITM attack would result in arbitrary code execution on the user's system. This is not clearly malicious, but it is a real medium-severity supply-chain concern: an executed binary from an unofficial/personal host with no checksum verification.
PKGBUILD
1 offending line(s) highlighted# Maintainer: JacobTech <Jacob@JacobTech.com>
pkgname='luski-beta-bin'
pkgver=0.0.0.1
pkgrel=2
pkgdesc="Simple open source chat app"
arch=('x86_64')
url="https://www.jacobtech.com/Luski"
license=('GPL')
depends=('dotnet-runtime-8.0' 'curl')
provides=('luski-beta')
conflicts=('luski-beta-contained-bin')
source=("luski-beta.tar.gz::https://www.jacobtech.com/Updater/GetPKG?directory=Luski&branch=Beta&selfcontained=false&platform=linux-x64")
md5sums=('SKIP')
pkgver() {
printf "$(curl -s https://www.jacobtech.com/Updater/GetProgramVersion\?directory\=Luski\&branch\=Beta\&selfcontaind\=false\&platform\=linux-x64)"
}
package() {
cd "${srcdir}"
install -dm 755 "$pkgdir"/usr/lib/luski-beta
install -dm 755 "$pkgdir"/usr/share/applications
install -dm 755 "$pkgdir"/usr/bin
cp -r ${srcdir}/* "$pkgdir"/usr/lib/luski-beta/
touch "$pkgdir"/usr/bin/luski-beta.sh
cd "$pkgdir"/usr/bin
echo -n "#!/bin/sh
exec /usr/lib/luski-beta/Luski \"\$@\"" >> "$pkgdir"/usr/bin/luski-beta.sh
ln -s luski-beta.sh luski-beta
touch "$pkgdir/usr/share/applications/luski beta.desktop"
cd "$pkgdir"/usr/share/applications
echo -n "[Desktop Entry]
Name=Luski Beta
Version=1.0
GenericName=Luski Beta
Comment=Luski is a free opensource chat app
Exec=luski-beta %f
Terminal=false
Type=Application" >> "$pkgdir/usr/share/applications/luski beta.desktop"
chmod 755 "$pkgdir"/usr/bin/luski-beta
chmod 755 "$pkgdir"/usr/lib/luski-beta/Luski
chmod 755 "$pkgdir"/usr/bin/luski-beta.sh
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |