quotabox-bin

MEDIUM
maintainer sademir 0 votes scanned 2026-10-08 14:11:03.532860
View on AUR
Why flagged

Prebuilt binary tarball downloaded from a personal/project domain (quotabox.sademir.com) that is not official upstream infrastructure verifiable by a third party; a silent swap of the tarball would deliver arbitrary code execution, though the checksum is present and non-SKIP which partially mitigates the risk.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source=("https://quotabox.sademir.com/linux/quotabox-${pkgver}-x86_64.tar.gz")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): Prebuilt binary tarball downloaded from a personal/project domain (quotabox.sademir.com) that is not official upstream infrastructure verifiable by a third party; a silent swap of the tarball would deliver arbitrary code execution, though the checksum is present and non-SKIP which partially mitigates the risk.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Samet Demir <dev at sademir dot com>
2# Generated by linux/packaging/publish.sh from PKGBUILD.in — edit the template, not this file.
3pkgname=quotabox-bin
4pkgver=0.1.0
5pkgrel=1
6pkgdesc="Claude Code, ChatGPT / Codex and GitHub Copilot usage limits in your tray"
7arch=('x86_64')
8url="https://quotabox.sademir.com"
9license=('MIT')
10depends=('gtk4' 'libadwaita' 'hicolor-icon-theme')
11optdepends=('gnome-shell-extension-appindicator: tray icon on GNOME'
12 'waybar: usage in the bar via `quotabox waybar`')
13provides=('quotabox')
14conflicts=('quotabox')
15source=("https://quotabox.sademir.com/linux/quotabox-${pkgver}-x86_64.tar.gz")
16sha256sums=('16375b9fd3e25caba67465f223a2e016117ab2f7e3dc13f46d08309368cc8b34')
17
18package() {
19 cp -a "quotabox-${pkgver}-x86_64/usr" "$pkgdir/"
20}
21

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 14:11:03 Medium 3
2026-10-08 14:08:57 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion