xcursor-hacked-white

maintainer Fulmene · 2 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged This PKGBUILD installs a cursor theme (pure data: cursor images and metadata files) from a Dropbox link. The content is never executed — it is installed as icon/cursor data under /usr/share/icons with 644 permissions. Dropbox is an unofficial host and the URL could theoretically be swapped, but the sha256sum provides integrity verification, and cursor theme archives contain no executable code. The risk profile is the same as any other theme package hosted on a personal file host: sloppy but not a security concern. The cheaper model's concern about host substitution is mitigated by the checksum, and even without it, cursor data is not executed code.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 85%): This PKGBUILD installs a cursor theme (pure data: cursor images and metadata files) from a Dropbox link. The content is never executed — it is installed as icon/cursor data under /usr/share/icons with 644 permissions. Dropbox is an unofficial host and the URL could theoretically be swapped, but the sha256sum provides integrity verification, and cursor theme archives contain no executable code. The risk profile is the same as any other theme package hosted on a personal file host: sloppy but not a security concern. The cheaper model's concern about host substitution is mitigated by the checksum, and even without it, cursor data is not executed code.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:9 source=("https://www.dropbox.com/s/d3a4ne5fcrdjkva/Hacked-White.tgz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Ada Joule <ada dot fulmina at gmail dot com>
2pkgname=xcursor-hacked-white
3pkgver=1.0.0
4pkgrel=1
5pkgdesc="Hacked White cursor theme."
6arch=('any')
7url="https://www.gnome-look.org/p/1102526/"
8license=('GPL')
9source=("https://www.dropbox.com/s/d3a4ne5fcrdjkva/Hacked-White.tgz")
10makedepends=('gzip')
11
12sha256sums=('5e96ca316b389bba924d74cbfe64e5400ba19cd9ee75ce65f4b98acdf588a06a')
13
14package() {
15 cd $srcdir/Hacked-White
16 install -d $pkgdir/usr/share/icons/Hacked-White
17 cp -rf * $pkgdir/usr/share/icons/Hacked-White
18 chmod -R 644 $pkgdir/usr/share/icons/Hacked-White/*
19 chmod 755 $pkgdir/usr/share/icons/Hacked-White
20 chmod 755 $pkgdir/usr/share/icons/Hacked-White/cursors
21}
22

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion