tnt-bio
The package downloads a source archive from a project-specific academic host (lillo.org.ar) which is plausibly the official source; the binary is built locally and installed as intended, with no evidence of malicious or remote code execution, though the skipped checksum reduces verifiability.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source archive from a project-specific academic host (lillo.org.ar) which is plausibly the official source; the binary is built locally and installed as intended, with no evidence of malicious or remote code execution, though the skipped checksum reduces verifiability.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:17
source=("http://www.lillo.org.ar/phylogeny/tnt/tnt-linux.zip")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Malacology <guoyizhang at malacology dot net>
# Contributor: Malacology <guoyizhang at malacology dot net>
pkgbase=tnt-bio
pkgname=('tnt-bio'
'tnt-mpi'
'tnt-gui'
'tnt-extra')
pkgver=1.6
pkgrel=1
pkgdesc="Tree analysis using New Technology. https://doi.org/10.1111/cla.12160"
arch=('x86_64')
url="http://www.lillo.org.ar/phylogeny/tnt/"
license=('custom')
makedepends=('unzip')
depends=('ncurses5-compat-libs')
source=("http://www.lillo.org.ar/phylogeny/tnt/tnt-linux.zip")
sha256sums=('SKIP')
prepare () {
cd $srcdir/TNT-Docs_n_Datasets
chmod a+r $srcdir/TNT-Docs_n_Datasets -R
unzip tnt_scripts.zip -d ./tnt_scripts
}
package_tnt-bio () {
depends=('ncurses5-compat-libs' 'glibc')
cd ${srcdir}/TNT-bin
chmod +x tnt
install -Dm 755 tnt ${pkgdir}/usr/bin/tnt
}
package_tnt-mpi () {
depends=('ncurses5-compat-libs' 'pvm' 'openmpi' 'glibc')
cd ${srcdir}/TNT-bin
chmod +x mpitnt
install -Dm 755 mpitnt ${pkgdir}/usr/bin/mpitnt
}
package_tnt-gui () {
depends=('ncurses5-compat-libs' 'gtk3' 'glibc')
optdepends=('pvm')
cd ${srcdir}/TNT-bin
chmod +x gTNT
install -Dm 755 gTNT ${pkgdir}/usr/bin/gTNT
}
package_tnt-extra () {
install -dm755 $pkgdir/usr/share/tnt/
cd $srcdir/
# PDF
install -Dm 755 README_FIRST.pdf $pkgdir/usr/share/tnt/
cd $srcdir/TNT-Docs_n_Datasets
# script
mv $srcdir/TNT-Docs_n_Datasets/tnt_scripts $pkgdir/usr/share/tnt/
# font
install -Dm 755 Tred.ttf ${pkgdir}/usr/share/fonts/Tred/Tred.ttf
# html
mv $srcdir/TNT-Docs_n_Datasets/*.htm $pkgdir/usr/share/tnt/
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |