Omahub
← All plugins
A

Croc Transfer

by alexdont

Send a file to anyone, anywhere, without a terminal: drop it on the bar, paste the code to your recipient, done. End-to-end encrypted via croc — no accounts, no shared network. Receive side included

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
0753c14
Scanned
1 month ago
  • medium sudo Service.qml:75

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S croc")
  • medium sudo Service.qml:106

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S croc")
  • medium sudo Overlay.qml:217

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S croc"
  • Docs sudo README.md:27

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S croc

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
0753c14
Reviewed
1 month ago

The plugin is a clean front-end for the croc file-transfer tool: it validates external inputs, passes them to croc as positional arguments, and never executes the sudo commands the deterministic scan flagged (those are user-facing install instructions/error text). No obfuscation, persistence, credential theft, or destructive behavior was found; residual risk is limited to the inherent nature of receiving files from a code the user chooses to redeem.

  • The `sudo pacman -S croc` strings flagged by the scan are only user-facing install instructions/error messages; the plugin never executes sudo.
  • The plugin shells out via `sh -c`/`bash -c`, but all dynamic values are passed as validated positional arguments, so no command-injection path was found.
  • As with any croc receive, an untrusted sender could fill the disk; the README warns users to only accept codes from trusted people.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/alexdont/croc-transfer --enable
Productivity #bar #quickshell

Croc Transfer for Omarchy

Send a file to anyone, anywhere, without touching a terminal: drop it on the bar, paste the short code to your recipient, done. Powered by croc — end-to-end encrypted (PAKE), no accounts, no shared network, resumable, and the recipient can be on Linux, macOS, or Windows. Receiving works the same way in reverse: paste a code, the file lands in ~/Downloads.

The Croc Transfer card waiting for a recipient: the paste-ready croc code with a copy button, a scannable QR of the same command, and Cancel

This is the third leg Omarchy was missing: omarchy share covers the same LAN (LocalSend) and Taildrop covers your own tailnet — this covers another person, anywhere on the internet.

Install

⚠️ croc is required and must be installed first. This plugin is a front-end for the croc command-line tool — nothing can be sent or received without it. It's in the official Arch repos and is the only dependency you need to install (wl-clipboard and qrencode already ship with Omarchy).

Requires Omarchy 4.x (Quattro):

sudo pacman -S croc
omarchy plugin add https://github.com/alexdont/croc-transfer.git --enable

If croc is missing, the plugin doesn't break — the card and every send or receive attempt tell you exactly what to install, and it starts working the moment croc is present (no restart needed).

Optional keybindings (add to ~/.config/hypr/bindings.lua):

o.bind("SUPER + ALT + S", "Croc: pick & send", "omarchy-shell croctransfer pick")
o.bind("SUPER + ALT + R", "Croc transfer", "omarchy-shell croctransfer toggle")

Use

Send — drop files or a folder onto the bar icon 󰒊 (or onto the open card, or click Pick files…). The moment croc is ready, the paste-ready command — croc lion-brave-sunset — is on your clipboard and a toast shows it; paste it to your recipient over any channel and they run it in any terminal. Clicking the toast reopens the card, which shows the code, a scannable QR of the command, live progress, and Cancel. The bar icon tracks state: ··· while waiting, a percentage while bytes move.

Receive — click the bar icon, paste the code someone sent you into the receive field (a full croc xyz paste works too), hit Enter. Files land in ~/Downloads. A receive that finds no sender gives up after five minutes.

One transfer runs at a time; starting another tells you so instead of silently doing nothing. IPC for scripting: omarchy-shell croctransfer pick | toggle | send <path> | receive <code> | cancel | status (status returns state as JSON).

Custom relay

By default croc meets through its public relay, which only ever carries end-to-end encrypted traffic and never sees filenames or contents. If you run your own relay:

omarchy bar set io.github.alexdont.croc-transfer relay "myrelay.example.com:9009"

(The setting is declared in the widget's manifest schema, so it will also appear in the shell's widget-settings UI as that lands.)

Security notes

  • End-to-end encrypted by croc (PAKE): the relay — public or yours — relays ciphertext only.
  • The code phrase is single-use: whoever redeems it first gets the file, so share it over a channel you trust, and Cancel revokes a pending send at any time.
  • The receive code is handed to croc via the CROC_SECRET environment variable (croc's own recommended form), not argv.
  • The plugin keeps no state and no transfer history — a transfer's only record is its notification. Codes live in memory (and your clipboard) for the transfer's lifetime, and the plugin never writes a state or log file of its own.
  • Received files land in ~/Downloads, nothing else. The plugin runs croc with ~/Downloads as the working directory and never executes what arrives. croc itself refuses malicious sender filenames — path traversal and symlinks that point outside the transfer are rejected (verified against croc 11.x: an escaping symlink aborts the receive with "refusing files"). Only accept codes from people you trust, since a very large transfer will fill your disk like any download.
  • The plugin passes every external value — file paths, the receive code, a custom relay — to croc as separate arguments, never spliced into a shell string; the code is additionally restricted to letters, digits, and dashes.
  • This plugin does not ship its own browser/web receive bridge: that would mean a server holding decrypted files, breaking the end-to-end claim. (croc upstream offers its own web helper; that's croc's, not this plugin's, and this plugin never routes your files through it.)

Remove

omarchy plugin remove io.github.alexdont.croc-transfer

Nothing else to clean up — the plugin writes no state.

License

MIT