stickempires
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:11
source=('https://aya1.top/https://github.com/Brx86/yun/releases/download/2/stickempires.tar.gz')
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The source URL uses 'https://aya1.top/https://github.com/...' which is a URL-prefixing proxy/mirror pattern (aya1.top prepended before the GitHub URL). This means the actual tarball is served by a third-party host (aya1.top) rather than GitHub directly, making the content unverifiable beyond the md5sum (which is weak). The underlying GitHub repo (Brx86/yun) is also a personal user repository, not an official upstream. The package installs a Flash game binary (stickempires) via a tarball from this double-indirection source. Since this is executed code (a Flash application with launcher scripts under /opt and /usr) sourced from an unofficial personal host through a proxy, this is a genuine supply-chain concern: the proxy operator or the personal GitHub repo owner could substitute the tarball at any time, and md5 provides minimal integrity assurance. The 'broken' flag is not warranted as the PKGBUILD appears structurally functional. The 'piracy' flag is borderline (Stick Empires is a proprietary online game), but without clear evidence this circumvents licensing/DRM it is not flagged. Overall: medium severity due to executed binary from unofficial/proxied personal host.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Ayatale <ayatale@qq.com>
pkgname=stickempires
pkgver=2.29
pkgrel=1
pkgdesc="Play Online as One of The Greatest Empires of Inamorta"
arch=('x86_64')
url="http://www.stickwar.com/"
license=('custom')
depends=('flashplayer-standalone')
source=('https://aya1.top/https://github.com/Brx86/yun/releases/download/2/stickempires.tar.gz')
md5sums=('464509cfa2106488980305922c15ecab')
noextract=()
prepare() {
mkdir "$pkgname-$pkgver"
cp -r opt "$pkgname-$pkgver"/opt
cp -r usr "$pkgname-$pkgver"/usr
}
package() {
cd "$pkgname-$pkgver"
cp -r opt ${pkgdir}
cp -r usr ${pkgdir}
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |