Omahub
← All plugins
R

Omacam

by Rahul

Use an Android phone as a permanent Omarchy webcam over USB, Wi-Fi, or native UVC.

Security review

Potentially dangerous behavior detected · 19 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
5b12277
Scanned
1 month ago
  • Bundles a systemd unit file.

    [Unit]
  • medium package_manager …/workflows/ci.yml:20

    System package manager operation.

    apt-get install --yes jq shellcheck
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe -r v4l2loopback
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -R --noconfirm omarchy-phonecam
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f -- \
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -rf -- /usr/lib/omarchy-phonecam
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm control --reload
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl daemon-reload
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe -r v4l2loopback; then
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install --yes jq shellcheck
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed \
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm control --reload
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl daemon-reload
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback; then
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe -r v4l2loopback" >&2
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback" >&2
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe -r v4l2loopback
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
5b12277
Reviewed
1 month ago

The plugin is a legitimate Android-phone-as-webcam service. The deterministic scan flagged sudo usage and a systemd unit, but those are confined to the separate host installer (install-host.sh) that the user runs manually with clear documentation; the plugin itself runs as the logged-in user and only talks to a local Unix socket. No obfuscation, credential theft, or destructive behavior was found in the sampled code.

  • The host installer (install-host.sh) runs sudo to install packages, load the v4l2loopback kernel module, and reload systemd/udev; this is expected for the functionality but requires user consent and is not part of the plugin's runtime.
  • The uninstall script removes system files with sudo; again user-initiated and documented.
  • The plugin's Service.qml spawns phonecamctl and other commands, but all arguments are fixed and validated; no injection risk observed.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rahulmanuwas/omacam --enable
Hardware #bar #quickshell #media

Omacam

Omacam turns an Android phone into one permanent Linux webcam named Omarchy Phone Camera. No phone app, no cloud.

  • Android 12+ capture over USB or paired ADB Wi-Fi (scrcpy), plus native UVC when the phone supports it.
  • Stable /dev/video50. Conferencing apps see Omarchy Phone Camera, not the phone's USB name.
  • Idle privacy is one still black frame, then sleep. Apps still see a live camera; nothing is encoded until a phone streams.
  • Front/rear, 720p/1080p, 24/30/60 fps, rotation, mirror, torch, stills.
  • Auto-reconnect, disconnect recovery, stop on lock or suspend.
  • Omarchy bar panel: Orientation, Capture, Connection.

Android-first 0.2.0. Phone mic, browser/iPhone mode, effects, and a native iOS app are later. iPhone UVC nodes are ignored.

Validated on Omarchy 4 with USB scrcpy, front/rear, rotation, and Google Meet. Remaining app checks: docs/release-checklist.md.

Architecture

Android UVC / scrcpy ──> phonecamd ──> /dev/video50
                           │  live: scrcpy, ffmpeg when needed
                           │  idle: one black frame, then sleep
                           └── Unix socket ──> phonecamctl ──> bar panel

The plugin does not install packages or request sudo. phonecamd owns ADB, scrcpy, V4L2, and idle privacy so a shell reload does not drop a call. ffmpeg is for UVC, 90°/270° letterbox, snapshots, and recording — not idle privacy.

Requirements

Omarchy 4, Android 12+ with USB debugging, matching kernel headers, and a user session with systemd, PipeWire, and V4L2.

./install-host.sh installs android-tools, ffmpeg, pipewire, wireplumber, python, python-dbus-next, scrcpy, v4l-utils, v4l2loopback-dkms, base-devel, and the running kernel's headers. It does not install DroidCam.

Install

Host first (sudo for pacman, headers, DKMS):

./install-host.sh
phonecamctl status

Then the plugin:

omarchy plugin add https://github.com/rahulmanuwas/omacam --enable

Local checkout: ./install-plugin-local.sh (use --update after QML edits). --no-deps skips package install. ./scripts/build-host-package.sh --install --syncdeps builds the pacman package only.

First USB connection

  1. Enable Developer options and USB debugging.
  2. Connect a data-capable cable, unlock, and always-allow this computer.
  3. In the Omacam bar panel, click Use next to the phone.
  4. In Meet, Zoom, OBS, Discord, or Slack, select Omarchy Phone Camera.

Use with auto-connect trusts the device. Stop camera suppresses reconnect until unplug or a new Use.

Some Android 14 QPR1+ phones expose Webcam under USB Preferences. Select it and Omacam routes that UVC node through /dev/video50. Built-in and unrelated USB webcams are ignored.

Wireless debugging

  1. Developer options → Wireless debugging → Pair device with pairing code.
  2. Enter the address and six-digit code, Pair.
  3. Switch to the connection port shown on the main Wireless debugging screen, Connect, then Use.

Wireless debugging often dies after a phone reboot. USB is the reliable path. The daemon never enables open ADB-over-TCP.

phonecamctl pair 192.168.1.25:37145 123456
phonecamctl wifi-connect 192.168.1.25:39877
phonecamctl connect 'adb:192.168.1.25:39877' --trust

Controls

phonecamctl status
phonecamctl devices
phonecamctl camera front
phonecamctl resolution 720p
phonecamctl fps 30
phonecamctl rotate 90
phonecamctl mirror on
phonecamctl torch off
phonecamctl auto-connect on
phonecamctl disconnect
phonecamctl snapshot
phonecamctl record
phonecamctl diagnostics --json

Stills go to ~/Pictures/Omacam. Middle-click the bar icon to capture when a phone is ready; right-click stops the camera. Record always passes --webcam-device=/dev/video50.

Troubleshooting · socket protocol

Privacy

Daemon and CLI run as the logged-in user. The socket is 0600 in $XDG_RUNTIME_DIR. Video stays on USB or the local LAN. Idle is a still frame, not an encode. The camera stops on lock and before suspend. iOS and laptop cameras are skipped. Removing the plugin stops producers after a short watcher grace period.

Plugins are unsandboxed. Review Service.qml and BarWidget.qml. Marketplace listing is not a security review.

Development

./scripts/check.sh

Stdlib-only unit tests. Hardware, scrcpy, and conferencing apps need a real Omarchy machine.

Uninstall

omarchy plugin remove io.github.rahulmanuwas.omacam
./uninstall-host.sh

--purge also drops this user's config and logs. Dependencies stay installed.

License

MIT