Omahub
← All plugins
O

Security Posture

by Omar (@omarkamal)

A private, evidence-based security posture and activity monitor for Omarchy.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
8844ff6
Scanned
3 weeks ago
  • medium sudo Panel.qml:341

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or remediation"

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
8844ff6
Reviewed
3 weeks ago

The plugin is a read-only, user-level security scanner: it runs fixed-argument commands with timeouts and bounded output, stores only sanitized local state at 0600 permissions, and contacts network sources only on an explicit user action. The deterministic scan's medium finding about sudo appears to be a false positive from a documentation/UI string in Panel.qml; no executable sudo, privilege escalation, telemetry, or destructive command path was found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/omarkamal/omarchy-security-posture --enable
System #quickshell #system #security

Security Posture for Omarchy

A private, evidence-based security posture widget for the Omarchy Quattro bar. It highlights meaningful changes and review items without pretending that a desktop widget can prove a machine is uncompromised.

Status License

What it checks

  • Official package updates and optional arch-audit results
  • Foreign/AUR package count and changes, using review language rather than calling unofficial packages malicious
  • Recent aggregate package activity from the local pacman log
  • Failed and newly enabled systemd units
  • Firewall service state
  • New listening sockets and wildcard database/cache exposure
  • Docker wildcard port publishing and privileged containers
  • SSH password/root-login posture, broad listening, key-set changes, and aggregate authentication failures when the journal is readable
  • Root encryption, Secure Boot, and selected kernel hardening controls

Checks adapt to installed software. An unavailable check is shown as unavailable; it is never silently interpreted as safe.

Privacy and security model

  • No telemetry; automatic/local checks run offline
  • Refresh online data explicitly contacts package/advisory sources; cached counts show their last refresh time and expire after 24 hours
  • No sudo, pkexec, configuration changes, or automatic remediation
  • No shell interpolation: the scanner executes fixed argument arrays
  • Per-command timeouts and bounded output
  • Local state retains generic finding titles, timestamps, review decisions, notification tokens, and observation fingerprints. The online cache contains counts, fingerprints, and refresh times. Neither retains IP addresses, usernames, keys, journal lines, raw package output, or secrets
  • State is written atomically with mode 0600

Omarchy plugins run unsandboxed with your user permissions. Review this plugin and every update before enabling it.

Install

From a published Git repository:

omarchy plugin add https://github.com/omarkamal/omarchy-security-posture.git --enable

For local development:

omarchy plugin validate "$PWD"
mkdir -p "$HOME/.config/omarchy/plugins"
cp -a "$PWD" "$HOME/.config/omarchy/plugins/io.github.omarkamal.security-posture"
omarchy plugin enable io.github.omarkamal.security-posture

The plugin's own install command should be preferred once it is published. Avoid editing packaged Omarchy files under /usr/share/omarchy.

Use

  • Left-click the shield to open the report.

  • The fixed footer identifies the loaded UI version and build. You can also run omarchy-shell io.github.omarkamal.security-posture version.

  • Right-click the shield to refresh local checks.

  • An ! on the shield marks an incomplete, failed, or stale report.

  • Open Check coverage for each check’s status and reason.

  • Use Refresh online data to fetch fresh update/advisory counts.

  • Expand Details & review for evidence, confidence, observation dates, and Copy command. Copying never executes the command.

  • Mark as expected or Snooze until date reduces repeated alerts; changed conditions or increased severity restore the finding to review.

  • History keeps resolved findings and prior observations that could not be verified by the latest scan. Category filters apply to findings and history.

  • Choose Balanced, Developer, or Strict in the widget settings.

  • Enable New finding notifications in settings if desired (off by default). New warning/critical findings produce one aggregate notification, with a 15-minute cooldown and persistent deduplication.

  • Tab moves between panel controls; Ctrl+Tab switches to the next bar panel.

  • Trigger a refresh from the command line:

    omarchy-shell io.github.omarkamal.security-posture refresh
    

The scanner can also be run independently:

./bin/omarchy-security-scan --pretty
./bin/omarchy-security-scan --profile developer --no-state --pretty
# Explicitly contact package/advisory sources:
./bin/omarchy-security-scan --refresh-data --pretty

Profiles

  • Balanced: useful desktop defaults with moderate noise.
  • Developer: presents common development listeners as notices while retaining warnings for wildcard database/cache and Docker exposure.
  • Strict: elevates broad exposure and missing hardening controls.

Profiles change presentation severity, not the underlying facts.

Development and validation

omarchy plugin validate .
python3 tests/lint-qml.py
python3 -m py_compile bin/omarchy-security-scan
python3 -m unittest discover -s tests -v
# Real Wayland UI test using temporary scanner/clipboard fixtures:
python3 tests/qml-smoke.py

The lint helper selects Qt 6 and provides Quickshell’s qs import namespace. Static warnings about dynamic shell properties may remain; the real Wayland smoke test exercises the loaded controls and process handlers.

The scanner report contract is documented in docs/scanner-schema.md.

Known limitations

  • Unprivileged users may not be able to inspect firewall rules, process owners, Docker, effective root-only SSH settings, or all journal entries.
  • UFW status alone cannot prove Docker-published ports are filtered.
  • Configuration parsing is conservative and cannot reproduce every conditional sshd Match rule without root access.
  • Online update/advisory data is unavailable until an explicit refresh.
  • Notifications and clipboard copying require notify-send and wl-copy, respectively. Notifications respect the desktop notification service.
  • First-run observations establish a baseline. Changes become more useful from the second scan onward.
  • Findings are indicators for human review, not malware verdicts.

Remove

omarchy plugin remove io.github.omarkamal.security-posture
rm -rf "${XDG_STATE_HOME:-$HOME/.local/state}/omarchy-security-posture"

If XDG_STATE_HOME is unset, state is under ~/.local/state/omarchy-security-posture.