mirage-realms
The PKGBUILD downloads a prebuilt binary ZIP (Mirage-LinuxX64.zip) from the official upstream domain (miragerealms.co.uk) and installs it as an executable. The source host is the game's own website, not a personal or unofficial host, which reduces but does not eliminate risk. However, all three checksums are 'SKIP', meaning there is no integrity verification whatsoever — if the upstream host is compromised or the file changes, users would silently receive and execute arbitrary code. The binary is a closed-source game client executed directly on the user's system. This is a real supply-chain concern (no checksum pinning on an executed binary) but not clearly malicious, consistent with a medium rating.
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
"https://www.miragerealms.co.uk/files/clients/legacy/Mirage-LinuxX64.zip"
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary ZIP (Mirage-LinuxX64.zip) from the official upstream domain (miragerealms.co.uk) and installs it as an executable. The source host is the game's own website, not a personal or unofficial host, which reduces but does not eliminate risk. However, all three checksums are 'SKIP', meaning there is no integrity verification whatsoever — if the upstream host is compromised or the file changes, users would silently receive and execute arbitrary code. The binary is a closed-source game client executed directly on the user's system. This is a real supply-chain concern (no checksum pinning on an executed binary) but not clearly malicious, consistent with a medium rating.
PKGBUILD
1 offending line(s) highlightedpkgname=mirage-realms
pkgver=1.0.0
pkgrel=1
pkgdesc="Free to play indie MMORPG for Android and PC"
arch=("x86_64")
url="https://www.miragerealms.co.uk"
license=("custom")
depends=("java-runtime>=11")
makedepends=("unzip")
source=(
"https://www.miragerealms.co.uk/files/clients/legacy/Mirage-LinuxX64.zip"
"mirage-realms.desktop"
"https://www.miragerealms.co.uk/wp-content/uploads/2017/01/favicon.png"
)
sha256sums=("SKIP" "SKIP" "SKIP")
package() {
install -dm755 "$pkgdir/opt/$pkgname"
unzip Mirage-LinuxX64.zip -d "$srcdir/_mr"
gamefolder="$(find "$srcdir/_mr" -mindepth 1 -maxdepth 1 -type d | head -n 1)"
cp -r "$gamefolder"/* "$pkgdir/opt/$pkgname/"
chmod +x "$pkgdir/opt/$pkgname/Mirage Realms"
install -dm755 "$pkgdir/usr/bin"
ln -s "/opt/$pkgname/Mirage Realms" "$pkgdir/usr/bin/mirage-realms"
install -Dm644 "$srcdir/mirage-realms.desktop" \
"$pkgdir/usr/share/applications/mirage-realms.desktop"
install -Dm644 "$srcdir/favicon.png" \
"$pkgdir/usr/share/pixmaps/mirage-realms.png"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Medium | 2 |
| 2026-09-16 00:03:17 | Medium | 2 |
| 2026-09-15 00:25:31 | Medium | 2 |
| 2026-09-14 00:27:57 | Medium | 2 |
| 2026-09-13 00:19:54 | Medium | 2 |
| 2026-09-12 00:25:17 | Medium | 2 |
| 2026-09-11 00:19:22 | Medium | 2 |
| 2026-09-10 00:22:44 | Medium | 2 |
| 2026-09-09 00:04:09 | Medium | 2 |
| 2026-09-08 00:18:08 | Medium | 2 |
| 2026-09-07 00:30:15 | Medium | 2 |
| 2026-09-06 00:17:06 | Medium | 2 |
| 2026-09-05 00:16:27 | Medium | 2 |
| 2026-09-04 00:03:13 | Medium | 2 |
| 2026-09-03 00:15:47 | Medium | 2 |
| 2026-09-02 00:02:31 | Medium | 2 |
| 2026-09-01 00:11:19 | Medium | 2 |
| 2026-08-31 00:19:57 | Medium | 2 |
| 2026-08-30 00:04:14 | Medium | 2 |
| 2026-08-29 00:29:17 | Medium | 2 |