Omahub
← All plugins
B

LocalSend

by bredda

Run LocalSend headlessly and manage nearby devices, sharing, and incoming transfers from the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
52ddbdd
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
52ddbdd
Reviewed
1 month ago

This plugin is a well-engineered LocalSend integration that runs a headless controller. The only notable risk is that it downloads a prebuilt binary from GitHub releases on first use, but that binary is checksum-pinned, size-limited, and built from the repository's own source via attested CI. No obfuscation, destructive commands, hidden persistence, or credential theft were found.

  • The launcher downloads a binary from GitHub releases; while it verifies SHA-256 and size, a compromise of the repository or release could alter the pinned checksum. This is a standard supply-chain consideration for any plugin that fetches binaries.
  • The controller listens on the network (port 53317) and accepts incoming transfers, but it never auto-accepts and requires explicit user action, so exposure is limited.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/cryptobredda/omarchy-localsend --enable
Widgets #bar #quickshell

LocalSend for Omarchy

A native Omarchy Shell integration for LocalSend that runs entirely in the background. Discover devices, choose files or clipboard text, review incoming requests, and track transfers without opening the LocalSend GUI.

LocalSend panel showing a nearby device

Features

  • Theme-controlled symbolic status-bar icon
  • Official colored LocalSend icon inside the panel
  • Nearby-device discovery over LocalSend protocol v2.2
  • File, folder, and clipboard-text sharing
  • Explicit Accept and Decline controls for incoming requests
  • Desktop notifications for new requests
  • Live transfer progress, history, errors, and cancellation
  • Incoming clipboard text copied with wl-copy
  • Incoming files saved to the XDG Downloads directory
  • TLS certificate pinning and a private Unix management socket
  • No LocalSend GUI, TUI, or tray process

Install

Quit any running LocalSend GUI first because both receivers use port 53317, then run:

omarchy plugin add https://github.com/cryptobredda/omarchy-localsend --enable --yes

The plugin appears in the right side of the bar by default. On first use, its reviewed launcher downloads the checksum-pinned x86-64 controller from the repository's attested GitHub release. Rust is not required for installation, and the verified controller is reused while offline.

Runtime requirements:

  • Omarchy 4.0 or newer, which provides the shell, file picker, and notification helpers
  • x86-64 Linux with glibc 2.39 or newer
  • curl for the initial HTTPS artifact download
  • coreutils for the bounded download and size/SHA-256 verification
  • util-linux for setpriv
  • wl-clipboard for wl-copy and wl-paste
  • Local network access to TCP and UDP port 53317

The LocalSend application is not required. This plugin does not modify user configuration.

To update later:

omarchy plugin update bredda.localsend --yes

Remove

omarchy plugin remove bredda.localsend --yes

Removal stops the receiver and removes the plugin code. The persistent identity is intentionally retained so reinstalling does not change the device fingerprint. To reset that identity too, remove $XDG_STATE_HOME/omarchy/localsend-controller, or ~/.local/state/omarchy/localsend-controller when XDG_STATE_HOME is unset.

Use

  1. Open the LocalSend bar panel.
  2. Choose Files, Folder, or Clipboard.
  3. Select a nearby device.
  4. Accept or decline incoming requests directly in the panel.

Keyboard shortcuts while the panel is open:

Key Action
r Refresh nearby devices
f Choose files
d Choose a folder
c Select clipboard text

The receiver uses the alias from an existing LocalSend installation when available. Otherwise, it uses the machine hostname.

Runtime Data

  • Management socket: $XDG_RUNTIME_DIR/omarchy-localsend.sock
  • Persistent identity: $XDG_STATE_HOME/omarchy/localsend-controller/identity.pem
  • Verified controller cache: $XDG_CACHE_HOME/omarchy-localsend/controllers/
  • Incoming files: XDG Downloads directory, normally ~/Downloads

The socket and identity are created with mode 0600. Incoming transfers are never accepted automatically.

Build From Source

Requirements:

  • Current stable Rust toolchain
  • qmllint for QML validation
  • Omarchy for manifest validation and runtime testing

Build the controller and SHA-256 checksum into dist/:

./scripts/build-controller

Run all local checks:

./scripts/check

Cargo output is kept under $XDG_CACHE_HOME/omarchy-localsend/target by default, outside the plugin tree. This avoids triggering Omarchy's recursive plugin watcher for every Cargo artifact.

Release Verification

No compiled executable is committed to this repository. bin/localsend-controller is a readable Bash launcher, and controller-release.env pins one release tag, asset name, expected byte size, source commit, and SHA-256 digest. The launcher applies that byte ceiling while downloading, then verifies the exact size and digest before every execution and rejects modified or unexpected artifacts.

.github/workflows/release-controller.yml builds releases from tagged source using Rust 1.97.1 and actions pinned by full commit SHA. It publishes the checksum and a GitHub artifact provenance attestation. The regular CI workflow independently downloads that exact release, verifies its checksum and attestation against the expected workflow, tag, and source commit, and only then executes it.

Architecture

service/Receiver.qml supervises one foreground controller process for the shell session. The launcher at bin/localsend-controller resolves the reviewed release and replaces itself with the verified executable. widget/LocalSendBar.qml is a thin per-monitor view that communicates with the service through short JSON RPC commands.

The Rust controller uses LocalSend's official core library at pinned commit af0416be50770a97760f7070684bc667b759a15c. It provides discovery, HTTPS transport, transfer decisions, progress, and cancellation without wrapping the interactive LocalSend CLI.

License

MIT. LocalSend and the Rust dependencies retain their respective licenses.