Omahub
← All plugins
T

Tormarchy

by TripleU613

Route all system traffic through Tor from the Omarchy bar, with a real kill switch, new circuits, and exit-country selection.

Security review

Potentially dangerous behavior detected · 32 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
decca86
Scanned
4 days ago
  • high destructive_filesystem tormarchy:1820

    Destructive operation on the root filesystem or a block device.

    rm -rf /usr/local/lib/tormarchy
  • high destructive_filesystem tormarchy:1852

    Destructive operation on the root filesystem or a block device.

    rm -rf /etc/tormarchy
  • high persistence tormarchy:1394

    Registers scheduled or boot-time system tasks.

    systemd-run is required for browser-only mode"
  • high persistence tormarchy:1433

    Registers scheduled or boot-time system tasks.

    systemd-run --user --scope --collect \
  • high persistence tormarchy:1585

    Registers scheduled or boot-time system tasks.

    systemctl enable tormarchy-boot.service >/dev/null 2>&1 \
  • high persistence tormarchy:1609

    Registers scheduled or boot-time system tasks.

    systemctl disable tormarchy-boot.service >/dev/null 2>&1 || true
  • high persistence tormarchy:1801

    Registers scheduled or boot-time system tasks.

    systemctl disable tormarchy-boot.service >/dev/null 2>&1 || true
  • high persistence tormarchy:1812

    Registers scheduled or boot-time system tasks.

    systemctl disable tor.service 2>/dev/null || true
  • Bundles a systemd unit file.

    [Unit]
  • Dynamic code execution via eval().

    eval(fs.readFileSync(path.join(__dirname, "..", "Model.js"), "utf8"));
  • medium external_hosts tormarchy:1495

    Downloads or connects to an external HTTP(S) host.

    curl -sf -m 25 https://check.torproject.org/api/ip 2>/dev/null); then
  • medium external_hosts tormarchy:1508

    Downloads or connects to an external HTTP(S) host.

    curl -6 -sf -m 8 https://ipv6.icanhazip.com >/dev/null 2>&1; then
  • System package manager operation.

    apt-get update -qq
  • System package manager operation.

    apt-get install -y -qq shellcheck libxml2-utils nftables
  • medium package_manager …/workflows/ci.yml:23

    System package manager operation.

    apt-get update -qq
  • medium package_manager …/workflows/ci.yml:26

    System package manager operation.

    apt-get install -y -qq shellcheck libxml2-utils nftables
  • medium sudo tormarchy:15

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo would source a writable library as root. That
  • medium sudo tormarchy:26

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo can be configured to pass PATH through, and
  • medium sudo tormarchy:179

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo when there is a terminal to type into, pkexec otherwise. Called from the
  • medium sudo tormarchy:1125

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo both pass
  • medium sudo tormarchy:1573

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo tormarchy boot enable"
  • medium sudo tormarchy:1604

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo tormarchy boot disable
  • medium sudo Service.qml:196

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo when it has a tty, pkexec
  • medium sudo Makefile:10

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo the nftables ruleset is validated against the kernel, which is the
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo useradd --system --no-create-home --shell /usr/sbin/nologin tor || true
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get update -qq
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y -qq shellcheck libxml2-utils nftables
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo useradd --system --no-create-home --shell /usr/sbin/nologin tor || true
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get update -qq
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y -qq shellcheck libxml2-utils nftables
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo nft -c -f -` is accepted
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo nft -c -f -

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
decca86
Reviewed
4 days ago

Tormarchy is a legitimate Tor routing tool that requires root to modify firewall rules and install systemd units. The flagged destructive operations and persistence are part of its documented uninstall and optional boot-reconnect features, not hidden malicious behavior. The code is well-commented, security-conscious, and includes tests for symlink and /tmp attacks, but it still grants passwordless polkit access and alters system networking, so a human should verify the firewall rules and service before publishing.

  • Installs a passwordless polkit rule for the installing user, allowing any process running as that user to toggle Tor routing without authentication.
  • Modifies the system firewall (nftables) and disables IPv6, which could disrupt networking if misconfigured or if Tor fails.
  • Includes an optional systemd boot service that reconnects Tor at boot, which is opt-in but adds persistence.
  • The uninstall command removes files from /usr/local/lib and /etc, but these are its own installed files and are expected.
  • Uses external hosts (check.torproject.org, ipv6.icanhazip.com) for connectivity checks, which is normal for a Tor tool.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/TripleU613/tormarchy --enable
System #bar #system #security
<p align="center"> <img src="assets/logo.svg" alt="Tormarchy" width="340"> </p> <p align="center"> A Tor toggle for the Omarchy bar. Click the onion, all your traffic goes through Tor. Click it again, it doesn't. </p>

Needs Omarchy 4.x. Everything else it uses is already on an Arch box — nftables, systemd, polkit, curl, iproute2. setup installs tor itself. Bridges additionally want obfs4proxy (AUR) or meek, and it'll tell you which if you need them.

Install

omarchy plugin add https://github.com/TripleU613/tormarchy.git --enable
sudo ~/.config/omarchy/plugins/tripleu.tor/tormarchy setup

setup needs a terminal and tells you everything it touches as it goes. For the record, that's: tor installed, tormarchy copied to /usr/local/bin, a config snippet in /etc/tor/torrc.d/, one line added to /etc/tor/torrc, a polkit rule so the toggle doesn't ask for a password, your user added to the tor group, and /var/lib/tor loosened to 0750 so it can read Tor's control cookie. It doesn't touch your Firefox or browser profiles — browser mode makes its own.

Removing it

sudo ~/.config/omarchy/plugins/tripleu.tor/tormarchy uninstall
omarchy plugin remove tripleu.tor

uninstall puts all of the above back, including /var/lib/tor, and takes the firewall rules down first so you can't end up without a network. Add --purge to also drop the tor package and your group membership.

Modes

Maximum Everything through Tor. Local network dropped too.
Standard Everything through Tor, but printers, SSH and Syncthing still work.
Browser only Nothing system-wide. Launches a browser that can't reach anything except Tor.

Maximum and Standard also switch off IPv6 and refuse to forward traffic, so a VM or container can't route around the rules.

Browser only doesn't just set a proxy preference — a proxy setting is a request that WebRTC and QUIC happily ignore. It runs the browser under IPAddressDeny=any, so the kernel won't let it open a socket to anything but loopback. Works with any browser you have installed.

What it costs

  • No UDP. Video calls, WireGuard, most games.
  • No IPv6.
  • No forwarding, so VMs and containers lose their network.
  • No other VPN at the same time.
  • No NTP, so a very long session can drift its clock until Tor gives up.

Browser only avoids all of that.

And the obvious one: Tor changes where your traffic comes from, not who a site already knows you are. If you were logged in before you connected, you're still logged in.

Panel

<p align="center"> <img alt="Connected" width="46%" src="https://github.com/user-attachments/assets/f670dd75-11cd-498e-96b9-0e8a0ca544ae" /> </p>

Left click opens it, right click toggles, middle click gets a new circuit.

Inside: j/k to move, t toggle, n new circuit, e exit country, s measure latency, esc to close.

The onion only lights up once traffic is actually going through Tor. In browser only the switch follows Tor itself, since that mode routes nothing system-wide -- so it reads on while the onion stays dark.

Commands

tormarchy connect / disconnect On and off. --dry-run prints the firewall rules without applying them.
tormarchy status What's happening.
tormarchy ip Your circuit and exit, straight from Tor. Doesn't phone anyone to ask.
tormarchy newnym New circuit.
tormarchy exit de Leave from Germany. --list shows what's available.
tormarchy bridge For networks that block Tor.
tormarchy browser Launch a browser locked to Tor.
tormarchy doctor Check for leaks.
tormarchy boot enable Reconnect at boot if Tor was on when you shut down. Off by default.
tormarchy panic Rip out every rule. For when things go wrong.

Tab completion for all of it, bash and zsh, installed by setup.

If it breaks

If Tor dies while you're connected, the rules stay and your network goes with them. That's on purpose — a kill switch that fails open isn't one. Toggle it off, or run tormarchy panic.

Nothing survives a reboot, so restarting always gets your network back.

That's also why tormarchy boot enable is opt-in rather than the default — turning it on trades a little of that guarantee for not having to reconnect after every restart. It only reconnects if Tor was on when you shut down, and if the network isn't there or Tor can't bootstrap it applies no rules at all.

License

MIT

Not affiliated with or endorsed by the Tor Project.