Omahub
← All plugins
A

OmaVault

by anel

Back up your Omarchy settings, Hyprland config, terminal configs and installed plugins as an AES-256 encrypted, checksummed folder tree you can carry on a USB stick and restore on a fresh machine. A password is required every time -- there is no plain-text option.

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
31dc804
Scanned
1 month ago
  • high shell_profile bin/export.sh:326

    Appends or writes to a shell profile or session init file.

    echo "  dotfiles/.bashrc etc -> ~/.bashrc etc"

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
31dc804
Reviewed
1 month ago

OmaVault is a user-invoked backup/restore bar widget with no install-time commands, no network/exfiltration behavior, and no destructive operations in the sampled code; plaintext is kept in tmpfs, backups are gpg-encrypted, and restores are checksum-verified and backed up beforehand. The deterministic "high" finding is a false positive: bin/export.sh:326 only echoes a description of the dotfiles mapping into a generated README/help text, not an actual write to ~/.bashrc. The remaining risk is the intended broad read/write access to home-directory configs, which requires explicit user action and a passphrase.

  • The shell_profile finding at bin/export.sh:326 over-matched an echo string that describes the backup layout; it does not append to or modify any shell profile.
  • Restore intentionally writes config/dotfiles under $HOME, including files that may contain secrets or executable config (e.g. .bashrc, Hyprland configs); existing files are preserved under ~/.local/state/omavault/pre-restore-* and nothing is deleted.
  • Importing a backup from an untrusted source is inherently risky because restored configs can influence shell/desktop behavior; OmaVault verifies integrity but cannot verify the trustworthiness of a backup's contents.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/anelcelik/omavault --enable
System #system

OmaVault

Back up your Omarchy setup -- bar/dock/search/theme settings, installed plugins, Hyprland config, terminal configs, and (opt-in) shell/editor dotfiles -- to a folder tree, typically a USB stick, and restore it on a fresh Omarchy install. Click the teal OV chip on the bar.

<p align="center"> <img src="screenshots/export-tab.png" width="46%" alt="Export tab: category checklist, destination picker, required passphrase fields"> <img src="screenshots/import-locked.png" width="46%" alt="Import tab: a detected backup, locked, waiting for its passphrase"> </p>

(Mockups reproduced from the actual popup's QML/copy to illustrate the layout -- not raw screen captures. Real file counts/sizes/drive names will differ on your machine.)

Install

omarchy plugin add https://github.com/anelcelik/omavault --enable

Or clone it yourself into ~/.config/omarchy/plugins/io.github.anelcelik.omavault/ and run omarchy plugin enable io.github.anelcelik.omavault.

Design

  • Always encrypted -- no plain-text option. Every export builds a mirrored copy of your real config files (config/omarchy/..., config/hypr/..., dotfiles/.bashrc, ...) in a scratch dir, then packs the whole thing -- including manifest.json and README.txt, nothing carved out -- into one payload.tar.gpg (AES-256 via gpg --symmetric) and deletes the plaintext scratch copy. Nothing about a backup is readable off the stick without the passphrase: not the file contents, not the category labels, not even the source hostname. Non-text files (icons, sqlite dbs, compiled caches) are left out automatically before packing and listed in the backup's own (encrypted) README.txt. The passphrase travels over each process's stdin, never argv or disk, and isn't remembered anywhere -- there's no recovery if it's lost.
  • Checksummed, not just copied. Every export writes a SHA256SUMS covering every file (manifest.json included) before encrypting. Import decrypts, verifies the whole thing before touching anything on this machine, and refuses to restore if a checksum fails.
  • Non-destructive restore. Anything an import is about to overwrite is copied first to ~/.local/state/omavault/pre-restore-<timestamp>/. Restoring only adds/overwrites -- it never deletes existing files.
  • Decryption happens in memory, not on disk. Import decrypts into a tmpfs temp dir ($XDG_RUNTIME_DIR, never the disk or the stick), wiped again once the popup closes or the restore attempt finishes.
  • You choose what's included, every time. The Export tab lists every category it found on this machine with a live file count/size and a plain-language description; nothing is exported until you press Export.
  • In-popup folder browser, not a native file-picker dialog -- a native GTK/portal FolderDialog reliably crashed the whole Quickshell process in testing (GVFS aborting inside libgtk-3's directory-monitor D-Bus call). "Browse..." instead lists real subdirectories via a small bash script + QML list, entirely in-process.

Layout

bin/lib.sh                Category registry (source→snapshot path map) + shared helpers
bin/list-categories.sh    What's exportable on this machine, with live file counts
bin/list-drives.sh        Detected removable drives + any OmaVault snapshots already on them
bin/list-dir.sh           Powers the in-popup folder browser
bin/export.sh             Builds a snapshot and encrypts it (stdin passphrase, required)
bin/inspect-snapshot.sh   Reads manifest.json + verifies SHA256SUMS, without touching the machine
bin/decrypt-snapshot.sh   Decrypts payload.tar.gpg into a tmpfs temp dir (stdin passphrase)
bin/cleanup-temp.sh       Removes a decrypt-snapshot.sh temp dir
bin/import.sh             Backs up existing files, then restores selected categories

Adding a new category means one entry in lib.sh's list_category_meta (the checkbox + description) and category_entries (the real path -> snapshot path mapping) -- every script shares that one registry.