Omahub
← All plugins
N

Howdy Lock

by Nate

Omarchy lock screen with a button to unlock using Howdy face recognition.

Security review

Review recommended · 10 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
e5e5402
Scanned
1 month ago
  • medium sudo setup.sh:23

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo and enrollment prompt). Agents: read
  • medium sudo setup.sh:30

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo can prompt." >&2
  • medium sudo setup.sh:220

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo howdy add"
  • medium sudo setup.sh:222

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo howdy test"
  • medium sudo setup.sh:227

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo howdy add now? [y/N] " answer
  • Docs sudo README.md:46

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f /etc/pam.d/omarchy-lock-howdy
  • Docs sudo AGENTS.md:44

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo howdy add` in a terminal. Do not enroll for them from a non-interactive agent session.
  • Docs sudo AGENTS.md:48

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo howdy test`. It crashes on OpenCV 5 / NumPy 2 (`IndexError` in `cli/test.py`). Preview the IR node with `mpv <device>` or `ffplay <device>`.
  • Docs sudo AGENTS.md:49

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo howdy test` with Qt/xcb workarounds as a success check.
  • Docs sudo AGENTS.md:71

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo howdy test` still crashes (OpenCV histogram bug).

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e5e5402
Reviewed
1 month ago

The deterministic scan's medium rating is driven by `sudo` mentions, but those are user-triggered setup/documentation commands rather than automatic or hidden elevation. The sampled QML and shell code are transparent and defensive (root-owned file checks, `python3 -I`, no PAM changes), and the main residual risk is the disclosed manual AUR install of `howdy-git`.

  • `setup.sh`, when run manually, uses sudo and installs `howdy-git` from the AUR while editing `/etc/howdy/config.ini`; this is disclosed and user-initiated, but it is a system-level trust decision.
  • The plugin replaces the stock `omarchy.lock` with a custom lock service, and while the sampled code retains password/PAM fallback, the full service should be kept under normal code review.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/nate8199/omarchy-plugin-howdy-face --enable
System #security

Howdy Lock

Omarchy lock screen with a button to unlock using Howdy face recognition. Password and fingerprint still work as before. Face unlock only runs when you press Unlock with face.

This plugin replaces omarchy.lock. Installing the plugin does not install Howdy or change PAM; run setup.sh after.

Requires

  • Omarchy 4.x (Quattro)
  • An IR camera (Windows Hello / GREY V4L node)

setup.sh will install howdy-git from the AUR if needed.

Install

omarchy plugin add https://github.com/nate8199/omarchy-plugin-howdy-face.git --enable
~/.config/omarchy/plugins/nate.howdy-lock/setup.sh

Run setup.sh in a terminal (sudo password, and optional howdy add). Agents helping with setup should read AGENTS.md.

The face button appears after /usr/lib/howdy/compare.py and /etc/howdy/models/$USER.dat are present.

Then lock with Super+Ctrl+L (or omarchy system lock) and press Unlock with face. Escape or Cancel stops a scan and lets you type a password. Face unlock runs compare.py directly (not pam_howdy, which waits for a password/Enter).

Security notes

  • Face unlock runs compare.py as your user — no root Python on the lock path — and unlocks only on exit status 0. Before the face button appears, the lock screen verifies /usr/lib/howdy/compare.py and /etc/howdy/models/<user>.dat are root-owned and not group/world-writable; any session code able to rewrite them could otherwise enroll a face everyone matches.
  • Face scans are limited to 5 failed attempts per lock; after that only password works until the next lock.
  • Camera snapshots are disabled by setup.sh (capture_failed=false, capture_successful=false); Howdy never stores images.
  • The camera is only opened when you press Unlock with face; there is no always-on scanning. Escape or Cancel kills the scan immediately.
  • Password unlocking keeps PAM faillock rate limiting. Face attempts are deliberately button-triggered rather than continuously retried.
  • No PAM configuration is created or required. /etc/pam.d/omarchy-lock-howdy is legacy from older versions and safe to delete (./setup.sh --remove).

Remove

omarchy plugin remove nate.howdy-lock
~/.config/omarchy/plugins/nate.howdy-lock/setup.sh --remove

If you already removed the plugin:

sudo rm -f /etc/pam.d/omarchy-lock-howdy

Removing the plugin restores omarchy.lock. Howdy itself is left installed.

License

MIT. Lock screen code is derived from Omarchy's omarchy.lock.