Omahub
← All plugins
M

Steam Guard

by matyifkbt

A local Steam Guard bar widget backed by steamguard-cli for codes and confirmations.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
f7975da
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f7975da
Reviewed
1 month ago

The plugin is a straightforward Steam Guard widget that invokes the local steamguard-cli binary for codes and confirmations. It contains no obfuscation, hidden persistence, or credential theft, and all destructive actions (accepting all confirmations, installing the CLI) are user-triggered and clearly documented. The deterministic scan found no issues, and I concur.

  • The 'Confirm all' action runs `steamguard confirm -a`, which accepts all pending Steam confirmations; this is destructive but requires explicit user toggle and is clearly warned in the README.
  • The plugin runs unsandboxed inside omarchy-shell and can execute arbitrary commands via the terminal, but only those explicitly initiated by the user.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/MatyiFKBT/omarchy-steamguard --enable
Other #games

Omarchy Steam Guard

A local Steam Guard widget for the Omarchy Quickshell bar. The bar displays a key icon; clicking it opens the current Steam Guard code and confirmation controls.

The plugin delegates authentication work to steamguard-cli, rather than reimplementing Steam's account storage or cryptography:

  • steamguard confirm opens an interactive confirmation session.
  • steamguard confirm -a accepts all pending mobile confirmations.

Dependency

This plugin requires steamguard-cli at runtime. The recommended Arch package is steamguard-cli-bin from the AUR; it installs the steamguard executable used by this plugin.

Install it with:

omarchy pkg aur add steamguard-cli-bin

Verify the dependency:

command -v steamguard
steamguard --offline

Requirements

After installing steamguard-cli, configure at least one account. It must be able to generate a code without prompting:

steamguard --offline

The CLI searches for accounts in:

~/.config/steamguard-cli/maFiles/
~/maFiles/

The account must be configured through the CLI or imported from a compatible maFiles backup.

Install

omarchy plugin add https://github.com/MatyiFKBT/omarchy-steamguard.git --enable --yes
omarchy bar move io.github.matyifkbt.omarchy-steamguard --section right

For local development, copy this folder to ~/.config/omarchy/plugins/io.github.matyifkbt.omarchy-steamguard/, then run:

omarchy-shell shell rescanPlugins
omarchy plugin enable io.github.matyifkbt.omarchy-steamguard

The plugin uses a key icon in the bar. Its tooltip is Open Steam Guard.

Usage

Click the key icon to open the panel. The code refreshes every 30 seconds and should match:

steamguard --offline

Use the default Open confirmation window action to review confirmations interactively in a floating terminal:

steamguard confirm

Enable Confirm all in the panel to change the action to Confirm all, which runs:

steamguard confirm -a

That action is destructive: it accepts every currently pending Steam mobile confirmation for the selected account(s).

Security

Plugins run unsandboxed inside omarchy-shell. This plugin executes the local steamguard binary and does not make network requests itself. steamguard-cli handles account secrets and encryption. Protect the CLI's maFiles and keyring credentials, and keep backups plus the Steam revocation code secure. Anyone who can access the configured account data may be able to generate codes or accept confirmations.

Troubleshooting

Verify the CLI independently:

steamguard --offline
steamguard confirm --help

After changing the plugin files:

omarchy-shell shell rescanPlugins
omarchy restart shell

If the icon is missing, confirm the plugin is enabled and present in the bar:

omarchy plugin list --json
omarchy bar move io.github.matyifkbt.omarchy-steamguard --section right

Uninstall

Remove the plugin with:

omarchy plugin remove io.github.matyifkbt.omarchy-steamguard

If steamguard-cli is no longer needed, remove the binary package separately:

omarchy pkg aur remove steamguard-cli-bin

Removing the plugin does not remove your steamguard-cli account data. Delete or back it up separately if required:

rm -rf ~/.config/steamguard-cli/maFiles

License

This plugin is released under the MIT License.