stickempires

maintainer ayatale · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The source URL uses 'https://aya1.top/https://github.com/...' which is a URL-prefixing proxy/mirror pattern (aya1.top prepended before the GitHub URL). This means the actual tarball is served by a third-party host (aya1.top) rather than GitHub directly, making the content unverifiable beyond the md5sum (which is weak). The underlying GitHub repo (Brx86/yun) is also a personal user repository, not an official upstream. The package installs a Flash game binary (stickempires) via a tarball from this double-indirection source. Since this is executed code (a Flash application with launcher scripts under /opt and /usr) sourced from an unofficial personal host through a proxy, this is a genuine supply-chain concern: the proxy operator or the personal GitHub repo owner could substitute the tarball at any time, and md5 provides minimal integrity assurance. The 'broken' flag is not warranted as the PKGBUILD appears structurally functional. The 'piracy' flag is borderline (Stick Empires is a proprietary online game), but without clear evidence this circumvents licensing/DRM it is not flagged. Overall: medium severity due to executed binary from unofficial/proxied personal host.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=('https://aya1.top/https://github.com/Brx86/yun/releases/download/2/stickempires.tar.gz')
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The source URL uses 'https://aya1.top/https://github.com/...' which is a URL-prefixing proxy/mirror pattern (aya1.top prepended before the GitHub URL). This means the actual tarball is served by a third-party host (aya1.top) rather than GitHub directly, making the content unverifiable beyond the md5sum (which is weak). The underlying GitHub repo (Brx86/yun) is also a personal user repository, not an official upstream. The package installs a Flash game binary (stickempires) via a tarball from this double-indirection source. Since this is executed code (a Flash application with launcher scripts under /opt and /usr) sourced from an unofficial personal host through a proxy, this is a genuine supply-chain concern: the proxy operator or the personal GitHub repo owner could substitute the tarball at any time, and md5 provides minimal integrity assurance. The 'broken' flag is not warranted as the PKGBUILD appears structurally functional. The 'piracy' flag is borderline (Stick Empires is a proprietary online game), but without clear evidence this circumvents licensing/DRM it is not flagged. Overall: medium severity due to executed binary from unofficial/proxied personal host.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Ayatale <ayatale@qq.com>
2
3pkgname=stickempires
4pkgver=2.29
5pkgrel=1
6pkgdesc="Play Online as One of The Greatest Empires of Inamorta"
7arch=('x86_64')
8url="http://www.stickwar.com/"
9license=('custom')
10depends=('flashplayer-standalone')
11source=('https://aya1.top/https://github.com/Brx86/yun/releases/download/2/stickempires.tar.gz')
12md5sums=('464509cfa2106488980305922c15ecab')
13noextract=()
14
15prepare() {
16 mkdir "$pkgname-$pkgver"
17 cp -r opt "$pkgname-$pkgver"/opt
18 cp -r usr "$pkgname-$pkgver"/usr
19}
20
21package() {
22 cd "$pkgname-$pkgver"
23 cp -r opt ${pkgdir}
24 cp -r usr ${pkgdir}
25}
26

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion