mc-tweakeroo-117-fabric
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD fetches a manifest JSON from masa.dy.fi (the personal/project host of the well-known Minecraft modder 'masady', author of mods like MaLiLib, Litematica, Tweakeroo etc.), which is a legitimate but unofficial/personal host. The real concern is architectural: the manifest is downloaded with a pinned sha1sum, but then a second URL is extracted from that manifest at build time and fetched with wget — with no integrity check on the resulting JAR. If masa.dy.fi were compromised or the manifest tampered with (e.g. via MITM, since the sha1 only covers the initial manifest fetch), an arbitrary JAR could be downloaded and installed. The JAR is executed code placed into the Minecraft mods directory. This is a genuine supply-chain concern (no checksum on the executed artifact), though the host itself is the legitimate upstream for these mods. The pattern of fetching a secondary artifact without integrity verification keeps this at MEDIUM rather than clean.
PKGBUILD
1 offending line(s) highlighted# Maintainer: EatMyVenom <eat.my.venomm@gmail.com>
_modname=tweakeroo
_mcver="1.17-snapshot-21w05a"
_modloader="fabric"
pkgname=mc-tweakeroo-117-fabric
pkgver="0.10.0.dev.20201218.030023"
pkgrel=1
pkgdesc="a client-side mod, which adds a whole bunch of various different tweaks to the game."
arch=('any')
url="https://masa.dy.fi/mcmods/client_mods/"
license=('LGPL')
makedepends=('wget' 'jq')
source=("manifest.json::https://masa.dy.fi/api/games/mods/minecraft/latest/client/")
sha1sums=('3b3c19c94ad38288f78222b4c72847f44df81b34')
pkgver() {
cd $srcdir
cat manifest.json | jq ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"version\"]" | sed 's/-/./g;s/+/./g'
}
build() {
wget $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"url\"]")
}
package() {
install -d -m 755 "${pkgdir}/usr/share/minecraft"
cp $(cat manifest.json | jq -r ".[\"mods\"][\"${_mcver}\"][\"${_modloader}\"][\"${_modname}\"][\"filename\"]") \
"${pkgdir}/usr/share/minecraft/${_modname}-${_mcver}.jar"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |