Omahub
← All plugins
S

omavcamd

by Sphiment

Control the vcamd daemon from the Omarchy bar.

Security review

Review recommended · 5 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
167ef65
Scanned
1 month ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -U https://github.com/Sphiment/vcamd/releases/latest/download/vcamd-git-x86_64.pkg.tar.zst\n"
  • Docs sudo README.md:18

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -Syu linux-headers
  • Docs sudo README.md:20

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -U https://github.com/Sphiment/vcamd/releases/latest/download/vcamd-git-x86_64.pkg.tar.zst
  • Docs sudo README.md:26

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo modprobe v4l2loopback
  • Docs sudo README.md:58

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -Rns vcamd-git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
167ef65
Reviewed
1 month ago

This plugin is a thin QML client that talks to the vcamd daemon over a Unix socket; it contains no install scripts and no direct system-command execution. The sudo commands flagged by the deterministic scan are documentation and a user-facing hint string in Panel.qml, not commands the plugin runs. The external vcamd engine is installed separately by the user and is outside this repository's code.

  • The plugin's UI can show a `sudo pacman -U ...` command when the vcamd engine is missing; it is displayed text only and is not executed by the widget.
  • The README's sudo commands are installation instructions for a separate daemon/kernel module; they are not part of the plugin's executable path.
  • The plugin trusts the daemon's socket state, but that daemon is user-installed software and communication is local; no unexpected privilege boundary is introduced.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Sphiment/omavcamd --enable
Widgets #quickshell #media #system

omavcamd

The Omarchy wrapper for the vcamd daemon. It adds a bar widget for starting and stopping capture, choosing a phone, toggling the preview, and seeing connection problems before a call.

This repository contains no capture engine and runs no system commands. The widget is a thin client: it connects to the daemon's Unix socket, renders the whole state pushed by the daemon, and sends requests back over that socket.

Install

Install the engine first from Sphiment/vcamd:

# Use the headers package matching your kernel: linux-headers,
# linux-lts-headers, linux-zen-headers, or linux-hardened-headers.
sudo pacman -Syu linux-headers

sudo pacman -U https://github.com/Sphiment/vcamd/releases/latest/download/vcamd-git-x86_64.pkg.tar.zst

Reboot after installing the engine. To use it immediately without rebooting:

sudo modprobe v4l2loopback
systemctl --user daemon-reload
systemctl --user start vcamd.socket

Then install this wrapper:

omarchy plugin add https://github.com/Sphiment/omavcamd.git --enable

--enable interactively asks where to place the widget in the bar. On the phone, enable Developer options and USB debugging, connect it, and accept the debugging prompt. The panel can then start the camera; the same operation is available from a terminal with vcamd start.

If the engine is absent or cannot start, the panel shows the engine install command and the systemd status command to use. It deliberately does not install anything itself.

Remove

Remove the wrapper without touching the engine:

omarchy plugin remove sphiment.omavcamd

To remove both halves:

systemctl --user stop vcamd.socket vcamd.service
sudo pacman -Rns vcamd-git
omarchy plugin remove sphiment.omavcamd

Architecture

The widget expects protocol version 4. It keeps one connection to $VCAMD_SOCKET, or $XDG_RUNTIME_DIR/vcamd.sock by default. Connecting socket-activates the daemon. State changes made by the CLI, a phone, or the capture process are pushed to the widget; the wrapper does not poll or retain a second copy of daemon state.

The wrapper also forwards Omarchy's live corner-radius and border-width tokens when it asks the daemon to show the preview. All adb, scrcpy, hyprctl, module, capture, and persistence work belongs to the daemon.

Development

The wrapper has no build step. Run its structural tests with:

python -m unittest discover -s tests -v

The tests validate the manifest and enforce the client boundary: QML may use the socket API, but it may not spawn processes or invoke capture tools.

License

MIT — see LICENSE.