Omahub
← All plugins
D

rclone

by david

rclone activity, remote status, and setup shortcuts in the Omarchy bar.

Security review

Potentially dangerous behavior detected · 2 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
2c29d80
Scanned
1 month ago
  • high persistence setup-daemon.sh:59

    Bundles a systemd unit file.

    [Unit]
  • Docs external_hosts README.md:14

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/davidszp/omarchy-rclone ~/.config/omarchy/plugins/io.github.davidszp.omarchy-rclone

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2c29d80
Reviewed
1 month ago

The deterministic scan's high rating comes from a README install one-liner and a systemd unit in setup-daemon.sh, but both are expected, user-initiated functionality rather than hidden behavior. The code is unusually careful about credentials, using stdin/HTTP bodies instead of argv, a unix socket, and 0600 files, and I found no obfuscation or destructive install-time commands. The main residual risk is the intended rclone daemon persistence and the inherent power of rclone sync/mirror operations.

  • setup-daemon.sh creates and enables a user-level systemd service (rclone-rcd.service) that starts at login; this is the plugin's intended daemon, but it is persistent by design and only runs after the user clicks 'Set up the rclone daemon'.
  • The README's `git clone` one-liner is documentation only; the plugin itself does not fetch or execute remote code at install or runtime.
  • Mirror/bisync operations can delete files at the destination; the UI defaults to dry-run and warns, but this is inherent to rclone sync semantics.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/davidszp/omarchy-rclone --enable
Productivity #system

rclone for the Omarchy bar

Your cloud drives in the bar: what's transferring, what's mounted, how much space is left — and adding a new provider without opening a terminal.

Built for my own machine and verified against live Google Drive, Box, OneDrive, Dropbox and Zoho accounts on Omarchy 4.0 / rclone 1.75.

<img src="preview.png" alt="The rclone panel mid-transfer: a copy job with progress, four files in flight with per-file speed and ETA, a bandwidth cap, and mounted drives with their storage" width="420">

Install

git clone https://github.com/davidszp/omarchy-rclone ~/.config/omarchy/plugins/io.github.davidszp.omarchy-rclone
omarchy restart shell

Add the widget to your bar, click it, and follow the panel. It sets up the rclone daemon on first run and walks you through connecting a drive. If rclone isn't installed it offers to do that too.

Needs Omarchy 4.x. (Python 3 is already there — uwsm, which starts your session, depends on it.)

What it does

  • Mount a drive with a switch, and have it come back after a reboot.
  • See what's transferring, with speed and progress, and stop a job.
  • Add a provider in the panel — Drive, OneDrive, Dropbox, Box, pCloud, Jottacloud, Yandex, Zoho, plus S3, B2, SFTP, WebDAV and FTP. Anything else falls back to rclone config in a terminal.
  • Copy, mirror or two-way sync a folder, with a dry run first.
  • Cap the bandwidth so a big upload doesn't eat your connection.
  • Open a drive in your file manager — double click the row, or use its menu.
  • Remove a remote, or stop every transfer and unmount everything at once.

Mounting and transferring are different things

Worth knowing, because rclone is not Dropbox and this trips people up.

Mounting gives you a folder that is the cloud. Nothing is downloaded up front; files are fetched when you open them and uploaded a few seconds after you save. Unmount and they're gone from your disk again. There's no local copy.

Transferring makes a real second copy — for offline access, or a backup that survives losing the account. It runs once when you click it. Nothing watches for changes afterwards.

So: mount to use your files, transfer to duplicate them.

If a row says "3 not uploaded yet", those writes are still in the local cache. Unmounting then will ask before throwing them away.

Keyboard

Up/down between remotes, left/right across a row's actions, Enter to run one. Actions are matched by name rather than position, so a row that gains a button doesn't shift what Enter does.

r refreshes, c checks each remote is reachable, a opens the Drive wizard.

Settings

Two, in the bar's plugin settings: how often to poll when idle (30s) and while something is transferring (2s).

Development

./check          # everything verifiable without a running shell — run this first

That covers the pure logic, the Python helpers, shell syntax, the manifest, that every icon exists in the font, and that nothing in the plugin has lost its last caller. It also runs the add → mount → remove lifecycle against a throwaway rclone daemon, and drives the live panel over IPC — the only way to test QML that imports Omarchy's own components. The last two skip themselves when there is no rclone or no running shell, and a skip is not a pass.

One rule worth repeating: after changing a .qml file, restart the shell before believing anything. Saving hot-reloads the plugin and that covers edits to existing code, but a newly added function does not take effect until omarchy restart shell — with no error to tell you which case you are in (NOTES.md, gotcha 11).

Give it a second or two between saving and restarting, though: restarting inside the plugin's own reload window crashes Quickshell (quickshell#956, open, not this plugin's bug). The shell restarts itself, but you lose your place.

status.py is the only thing that reads rclone's state, and rcclient.py the only thing that talks to its API — over a unix socket, so no credential is ever an argument. Model.js is pure logic with no QML imports, which is why it can be unit tested. Everything else is a panel component. See NOTES.md for how it fits together and the traps found on the way.

Not done yet

  • Most of rclone's 69 backends — thirteen are in the grid; the rest go through the terminal.
  • Encrypted remotes (crypt) — wraps an existing remote, so it needs a different form than "pick a provider and sign in".
  • Notifications — a mount that fails at login is only visible if you look.

License

MIT — see LICENSE.