Security Posture for Omarchy
A private, evidence-based security posture widget for the Omarchy Quattro bar. It highlights meaningful changes and review items without pretending that a desktop widget can prove a machine is uncompromised.
What it checks
- Official package updates and optional
arch-auditresults - Foreign/AUR package count and changes, using review language rather than calling unofficial packages malicious
- Recent aggregate package activity from the local pacman log
- Failed and newly enabled systemd units
- Firewall service state
- New listening sockets and wildcard database/cache exposure
- Docker wildcard port publishing and privileged containers
- SSH password/root-login posture, broad listening, key-set changes, and aggregate authentication failures when the journal is readable
- Root encryption, Secure Boot, and selected kernel hardening controls
Checks adapt to installed software. An unavailable check is shown as unavailable; it is never silently interpreted as safe.
Privacy and security model
- No telemetry; automatic/local checks run offline
- Refresh online data explicitly contacts package/advisory sources; cached counts show their last refresh time and expire after 24 hours
- No
sudo,pkexec, configuration changes, or automatic remediation - No shell interpolation: the scanner executes fixed argument arrays
- Per-command timeouts and bounded output
- Local state retains generic finding titles, timestamps, review decisions, notification tokens, and observation fingerprints. The online cache contains counts, fingerprints, and refresh times. Neither retains IP addresses, usernames, keys, journal lines, raw package output, or secrets
- State is written atomically with mode
0600
Omarchy plugins run unsandboxed with your user permissions. Review this plugin and every update before enabling it.
Install
From a published Git repository:
omarchy plugin add https://github.com/omarkamal/omarchy-security-posture.git --enable
For local development:
omarchy plugin validate "$PWD"
mkdir -p "$HOME/.config/omarchy/plugins"
cp -a "$PWD" "$HOME/.config/omarchy/plugins/io.github.omarkamal.security-posture"
omarchy plugin enable io.github.omarkamal.security-posture
The plugin's own install command should be preferred once it is published.
Avoid editing packaged Omarchy files under /usr/share/omarchy.
Use
-
Left-click the shield to open the report.
-
The fixed footer identifies the loaded UI version and build. You can also run
omarchy-shell io.github.omarkamal.security-posture version. -
Right-click the shield to refresh local checks.
-
An ! on the shield marks an incomplete, failed, or stale report.
-
Open Check coverage for each check’s status and reason.
-
Use Refresh online data to fetch fresh update/advisory counts.
-
Expand Details & review for evidence, confidence, observation dates, and Copy command. Copying never executes the command.
-
Mark as expected or Snooze until date reduces repeated alerts; changed conditions or increased severity restore the finding to review.
-
History keeps resolved findings and prior observations that could not be verified by the latest scan. Category filters apply to findings and history.
-
Choose Balanced, Developer, or Strict in the widget settings.
-
Enable New finding notifications in settings if desired (off by default). New warning/critical findings produce one aggregate notification, with a 15-minute cooldown and persistent deduplication.
-
Tab moves between panel controls; Ctrl+Tab switches to the next bar panel.
-
Trigger a refresh from the command line:
omarchy-shell io.github.omarkamal.security-posture refresh
The scanner can also be run independently:
./bin/omarchy-security-scan --pretty
./bin/omarchy-security-scan --profile developer --no-state --pretty
# Explicitly contact package/advisory sources:
./bin/omarchy-security-scan --refresh-data --pretty
Profiles
- Balanced: useful desktop defaults with moderate noise.
- Developer: presents common development listeners as notices while retaining warnings for wildcard database/cache and Docker exposure.
- Strict: elevates broad exposure and missing hardening controls.
Profiles change presentation severity, not the underlying facts.
Development and validation
omarchy plugin validate .
python3 tests/lint-qml.py
python3 -m py_compile bin/omarchy-security-scan
python3 -m unittest discover -s tests -v
# Real Wayland UI test using temporary scanner/clipboard fixtures:
python3 tests/qml-smoke.py
The lint helper selects Qt 6 and provides Quickshell’s qs import namespace.
Static warnings about dynamic shell properties may remain; the real Wayland
smoke test exercises the loaded controls and process handlers.
The scanner report contract is documented in
docs/scanner-schema.md.
Known limitations
- Unprivileged users may not be able to inspect firewall rules, process owners, Docker, effective root-only SSH settings, or all journal entries.
- UFW status alone cannot prove Docker-published ports are filtered.
- Configuration parsing is conservative and cannot reproduce every conditional
sshdMatchrule without root access. - Online update/advisory data is unavailable until an explicit refresh.
- Notifications and clipboard copying require
notify-sendandwl-copy, respectively. Notifications respect the desktop notification service. - First-run observations establish a baseline. Changes become more useful from the second scan onward.
- Findings are indicators for human review, not malware verdicts.
Remove
omarchy plugin remove io.github.omarkamal.security-posture
rm -rf "${XDG_STATE_HOME:-$HOME/.local/state}/omarchy-security-posture"
If XDG_STATE_HOME is unset, state is under
~/.local/state/omarchy-security-posture.