mc-malilib-116-fabric
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 85%): The PKGBUILD fetches a manifest JSON from masa.dy.fi with 'SKIP' checksum, then dynamically resolves and downloads a JAR file URL from that manifest at build time using wget — also with no integrity verification. This is a two-stage supply-chain risk: (1) the manifest itself has no checksum, so its contents can change arbitrarily, and (2) the JAR URL and filename are entirely controlled by whatever the manifest returns at build time, meaning a compromise of masa.dy.fi could serve a malicious JAR that gets installed as a Minecraft mod. The host masa.dy.fi is Masa's personal/unofficial distribution site, not an official Maven/Modrinth/CurseForge mirror. The executed artifact (a JAR loaded by Minecraft's classloader) is effectively arbitrary code execution in the user's game context. This is a genuine supply-chain concern: no pinned version in the source URL, no checksum on the downloaded JAR, and the actual download happens inside build() via wget rather than through makepkg's verified source mechanism. The cheaper model's MEDIUM rating is correct.
PKGBUILD
1 offending line(s) highlighted# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
_modname=malilib
_mcver="1.16.4"
pkgname=mc-malilib-116-fabric
pkgver="0.10.0.dev.21.arne.2"
pkgrel=1
pkgdesc="Library mod containing shared code for masas client-side mods."
arch=('any')
url="https://masa.dy.fi/mcmods/client_mods/"
license=('LGPL')
makedepends=('wget' 'jq')
source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
sha1sums=('SKIP')
pkgver() {
cd $srcdir
cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
}
build() {
wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"url\"]")
}
package() {
install -d -m 755 "${pkgdir}/usr/share/minecraft"
cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"fabric\"][\"${_modname}\"][\"filename\"]") \
"${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.jar"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |