Omahub
← All plugins
D

Wazuh View

by DevInBlack001

Local Wazuh agent status in the bar: SCA, FIM, rootcheck, config, and log health, all read-only, no manager or API required

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
c2d9488
Scanned
1 month ago
  • medium sudo Panel.qml:259

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo usermod -aG wazuh $USER, then log out and back in (group membership only takes effect for a new session)."
  • Docs external_hosts README.md:72

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/DevInBlack001/omarchy-wazuh-view ~/.config/omarchy/plugins/devinblack001.wazuh-view
  • Docs sudo README.md:55

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo usermod -aG wazuh $USER

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c2d9488
Reviewed
1 month ago

The plugin is a read-only status viewer for a local Wazuh agent. It reads configuration files and SQLite databases, runs the agent's own status command, and never writes, connects to the network, or executes arbitrary commands. The deterministic scan flagged sudo and git clone in the README and a comment, but those are user instructions, not executed by the plugin.

  • The README contains installation instructions with sudo and git clone, but these are user actions, not part of the plugin's runtime behavior.
  • The plugin runs the agent's own wazuh-control status command via subprocess, but with an absolute path and no shell, which is expected for status reporting.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/DevInBlack001/omarchy-wazuh-view --enable
System #bar #quickshell #security

Wazuh View

Local Wazuh agent status for the Omarchy Quickshell bar. SCA policy results, FIM baseline, rootcheck activity, effective configuration, and recent agent log lines, all inside the bar, no separate GUI window.

Preview

This plugin talks only to the local agent's own files and databases. It does not connect to a Wazuh manager or the Wazuh API, so it works even on an agent that has never reported to a manager, and it never sends anything anywhere.

Features

  • Connection status, last keepalive, and message count from the agent's own state file
  • Module enablement matrix (FIM, rootcheck, SCA, active response) and live process status
  • SCA policy scan results, pass/fail totals, and failed checks with remediation text
  • FIM baseline: count of monitored paths and a sample of what is being watched
  • Rootcheck: enabled state and recent scan activity parsed from the agent log
  • Effective configuration: FIM directories, log sources, SCA policies, active response commands, manager address
  • Recent agent log lines with error and warning counts
  • Bar icon changes color when something needs attention

What this plugin never touches

  • etc/client.keys, the file holding the agent's shared authentication key, is never read
  • No agent file or database is ever written to; every read goes through SQLite in read-only mode where a database is involved
  • No network calls, no manager connection, no Wazuh API calls
  • No command is ever run through a shell; the only subprocess invoked is the agent's own bin/wazuh-control status, using its resolved absolute path

Requirements

  • Omarchy with Quickshell
  • Python 3
  • A local Wazuh agent installation (checked at /var/ossec or /opt/ossec by default; see below to point elsewhere)

Agent install path

The install path is never hardcoded to a single location. At each refresh the helper checks, in order:

  1. the WAZUH_HOME environment variable
  2. the OSSEC_HOME environment variable
  3. /var/ossec
  4. /opt/ossec

The first candidate that has both a bin/ directory and etc/ossec.conf is used. If none match, the panel reports that no agent was detected instead of guessing.

Permissions

Several agent files (logs/ossec.log, the SCA and FIM databases, the state file) are typically owned by root:wazuh and not world readable. If a section shows "Permission denied", add your user to the wazuh group and log back in:

sudo usermod -aG wazuh $USER

Everything degrades gracefully section by section: a permission issue in one area (say, the SCA database) does not block the others from showing data.

Installation

Add it with the Omarchy plugin CLI:

omarchy plugin add https://github.com/DevInBlack001/omarchy-wazuh-view --enable

Or manually: clone into your Omarchy plugins directory, then enable it.

git clone https://github.com/DevInBlack001/omarchy-wazuh-view ~/.config/omarchy/plugins/devinblack001.wazuh-view
omarchy plugin enable devinblack001.wazuh-view right

Then reload the shell:

omarchy restart shell

Updating

omarchy plugin update devinblack001.wazuh-view
omarchy plugin update   # update every installed git-managed plugin

Removing

omarchy plugin remove devinblack001.wazuh-view

Then reload the shell:

omarchy restart shell

Usage

Click the shield icon in the bar to open the panel. Use the tab row (Overview, SCA, FIM, Rootcheck, Config, Logs) to switch views. The panel refreshes every 5 seconds while open, and every 30 seconds in the background.

Version differences

Wazuh's local database schemas for SCA and FIM can shift between versions. Rather than assume one fixed schema, the helper inspects each database's actual tables and columns at read time and adapts, so a version mismatch degrades to less detail instead of a broken panel.

Scope

This plugin is agent-side only. Full historical alerts, cross-agent correlation, and vulnerability data live on the manager and are out of scope here by design.

License

MIT, see LICENSE.