moondust-configpack-smbx13
maintainer chiyuki0325
· 0 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads a configuration pack from the project maintainer's own domain, which is not on a standard whitelist but hosts legitimate project files; the content is non-executable data, so the worst case of a swapped source is limited to data tampering, not code execution.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 90%): The package downloads a configuration pack from the project maintainer's own domain, which is not on a standard whitelist but hosts legitimate project files; the content is non-executable data, so the worst case of a swapped source is limited to data tampering, not code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:12
"http://wohlsoft.ru/projects/Moondust/_laboratory/config_packs/SMBX_13_compatible.zip"
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Kirikaze Chiyuki <me@chyk.ink>
2
pkgname=moondust-configpack-smbx13
3
pkgver=2024feb02
4
pkgrel=1
5
pkgdesc="Moondust Project's game configuration pack - Super Mario Brothers X 1.3 Compatible"
6
arch=('any')
7
url="http://wohlsoft.ru/config_packs/"
8
license=('custom')
9
makedepends=('gawk' 'sed' 'curl')
10
provides=('moondust-configpack')
11
source=(
12
"http://wohlsoft.ru/projects/Moondust/_laboratory/config_packs/SMBX_13_compatible.zip"
13
)
14
sha512sums=(
15
"SKIP"
16
)
17
18
pkgver() {
19
curl 'http://wohlsoft.ru/projects/Moondust/_laboratory/' | grep "Last update" | tail -1 | awk -F'update: ' '{print $2}' | awk -F' ' '{print $3$2$1}' | sed 's/,//' | sed 's/[A-Z]/\l&/g'
20
}
21
22
package() {
23
mkdir -p "${pkgdir}/opt/moondust/configs/"
24
mv "${srcdir}/SMBX" "${pkgdir}/opt/moondust/configs/SMBX"
25
}
26
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 00:29:32 | LOW | 2 |
| 2026-07-21 00:24:15 | LOW | 2 |
| 2026-07-20 00:19:49 | LOW | 2 |
| 2026-07-19 00:17:08 | LOW | 2 |
| 2026-07-18 00:14:48 | LOW | 2 |
| 2026-07-17 00:06:16 | LOW | 2 |
| 2026-07-16 00:05:41 | LOW | 2 |
| 2026-07-15 00:09:25 | LOW | 2 |