Omahub
← All plugins
M

Omarchy On-Screen Keyboard

by Maarten Tolhuijs

Touch-first on-screen keyboard for an unlocked Omarchy session.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
a41b45a
Scanned
2 weeks ago
  • medium package_manager …/workflows/ci.yml:24

    System package manager operation.

    apt-get install -y gcc pkg-config libwayland-dev libxkbcommon-dev
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y gcc pkg-config libwayland-dev libxkbcommon-dev

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a41b45a
Reviewed
2 weeks ago

The plugin is a transparent, well-documented on-screen keyboard with no malicious, obfuscated, or hidden behavior found in the sampled source. The deterministic scan's medium findings are from the GitHub Actions CI workflow (sudo apt-get install), which runs only on CI infrastructure and never on a user's system, so they do not represent user risk. Runtime behavior is limited to locally building a small helper from bundled source and injecting validated single key events through the Wayland virtual-keyboard protocol, with no network, clipboard, credential, or persistence behavior.

  • The plugin runs unsandboxed inside the long-lived omarchy-shell process and can inject keystrokes into the focused application; this is inherent to an on-screen keyboard and is clearly documented.
  • The optional SDDM login integration requires explicit sudo and writes system files under /usr/share/sddm/themes and /etc/sddm.conf.d; the installer is hash-tracked, refuses symlinked destinations, and preserves unrelated files, so this appears safe but is still privileged system modification.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/mtolhuys/omarchy-onscreen-keyboard --enable
Hardware #Hyprland #bar #quickshell

Omarchy On-Screen Keyboard

Built for Omarchy: Plugin

Omarchy lock-screen and desktop on-screen keyboards

The plugin provides the desktop keyboard shown on the right. The trusted lock-screen keyboard on the left ships with Omarchy itself.

A touch-first keyboard for Omarchy. Open it from the bar, type into the application that already has focus, and use normal application and Omarchy shortcuts without reaching for a physical keyboard. An optional, separately installed SDDM theme adds touch input to the login screen.

Requirements

  • An Omarchy release with Quattro shell-plugin support.
  • Omarchy's standard base-devel, wayland, and libxkbcommon packages. The plugin uses them to build its small input helper locally; it downloads nothing and needs no root access for desktop use.
  • jq for the optional SDDM installer and status commands.

The plugin runs unsandboxed inside the long-lived omarchy-shell process. Review the source before enabling it, as you should for any third-party shell plugin.

Install

omarchy plugin add https://github.com/mtolhuys/omarchy-onscreen-keyboard.git --enable

The keyboard icon is placed on the right side of the bar by default. Installation does not run a setup hook or change system files.

Use

Tap or left-click the keyboard icon to show or hide the keyboard. The icon is bright while the keyboard is visible and dim while it is hidden. On supported detachable hardware, an actual attach or detach transition also hides or shows it.

The keyboard includes letters, numbers, common punctuation, function and navigation keys, and one-shot Ctrl, Alt, Shift, and Super modifiers. Tap a modifier and then a key to send a chord. Hold a key with a small corner hint to open its alternatives.

Scripts can use the same direct controls:

omarchy-shell onscreen-keyboard show
omarchy-shell onscreen-keyboard hide
omarchy-shell onscreen-keyboard toggle
omarchy-shell onscreen-keyboard status

Optional login-screen keyboard

Desktop use needs no root access. Login-screen support is a separate, explicit system integration that replaces the active SDDM theme with the bundled keyboard-enabled theme:

PLUGIN_DIR="$HOME/.config/omarchy/plugins/io.github.mtolhuys.onscreen-keyboard"
sudo "$PLUGIN_DIR/bin/install-login-keyboard"
"$PLUGIN_DIR/bin/login-keyboard-status"

Log out to test it. Rebooting also shows it when SDDM autologin is disabled. Encrypted Omarchy installations normally keep autologin enabled because disk encryption is the boot authentication boundary, so a normal reboot may skip the greeter.

The installer:

  • writes /usr/share/sddm/themes/omarchy-onscreen-keyboard and /etc/sddm.conf.d/99-z-omarchy-onscreen-keyboard.conf;
  • does not restart SDDM, access the network, edit Omarchy's packaged theme, or change autologin;
  • records hashes for every owned file and refuses to replace locally modified owned files unless --force is supplied.

The login theme follows Omarchy's standard single-user behavior and signs in userModel.lastUser. It edits only SDDM's password model and submits through the SDDM API; the desktop virtual-keyboard helper is never used at the login screen.

Plugin updates do not silently rewrite system files. After an update, check and refresh the optional integration explicitly:

"$PLUGIN_DIR/bin/login-keyboard-status"
sudo "$PLUGIN_DIR/bin/install-login-keyboard"

Update

omarchy plugin update io.github.mtolhuys.onscreen-keyboard

Remove

If you installed the optional login-screen integration, remove it before removing the plugin checkout so its uninstaller is still available:

PLUGIN_DIR="$HOME/.config/omarchy/plugins/io.github.mtolhuys.onscreen-keyboard"
sudo "$PLUGIN_DIR/bin/uninstall-login-keyboard"
omarchy plugin remove io.github.mtolhuys.onscreen-keyboard

If you never installed the login-screen integration, only the final command is needed. Install and uninstall both preserve unrelated files and stop on locally modified owned files; use --force only after inspecting the reported paths.

The compiled helper is ordinary disposable cache data under ~/.cache/omarchy-onscreen-keyboard/ (or $XDG_CACHE_HOME/omarchy-onscreen-keyboard/) and is not deleted automatically by Omarchy's plugin removal command.

Migrating from the pre-marketplace build

Versions through 0.2.1 used the temporary ID dev.omarchy.onscreen-keyboard. Remove any optional login integration with that checkout's uninstaller, remove the old plugin, and then use the install command above. The marketplace ID is now permanently namespaced to this GitHub account.

Security boundaries and limitations

  • The current layout and injected XKB keymap are English (US).
  • Attach/detach reactions are confirmed on the ASUS ROG Flow Z13 through Hyprland's device inventory. Other devices can always use the bar icon or direct commands.
  • The desktop helper is compiled from bundled source into the user's cache. It injects only closed, individual key actions through Wayland's virtual-keyboard protocol and never stores typed strings, uses the clipboard, reads hardware input devices, or requests extra privileges.
  • Desktop injection cannot cross into SDDM or the lock screen. Those trusted surfaces use their own direct password-model integrations.
  • The lock-screen keyboard belongs to Omarchy itself, not this third-party plugin. Keep Omarchy updated to obtain it.
  • The disk-encryption prompt runs before Omarchy, SDDM, or this plugin and is outside this project's scope.
  • Floating and fullscreen windows are adjusted when necessary and restored when the keyboard hides. Physical geometry can still vary with display scale and compositor configuration.

See SECURITY.md for the complete security model and private vulnerability-reporting link.

Development

The portable test suite uses Bash, Node.js, jq, a C compiler, wayland-scanner, and the Wayland and xkbcommon development files:

./bin/test

Validate the marketplace manifest with the current Omarchy CLI:

omarchy plugin validate .

The suite runs without a graphical session. Release candidates are additionally exercised in a disposable Omarchy VM for plugin lifecycle, shell reload, pointer interaction, and real Wayland input behavior.

License

Original project code and documentation are available under the MIT License. The bundled Wayland protocol definition retains its own permissive copyright notice; see NOTICE.md.