Omahub
← All plugins
U

OmaSecurity

by ucmz851

Security posture auditor, shell plugin code health scanner, and hardening advisor for Omarchy Quattro.

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
4507720
Scanned
1 month ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo sysctl --system"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo ufw default deny incoming"
  • Docs curl_pipe_sh README.md:37

    curl output is executed by a shell (curl | sh pattern).

    curl ... | sh` / `wget ... | bash`).
  • Docs eval README.md:38

    Dynamic code execution via eval().

    eval()`, `new Function()`, base64 decoding piped to shell, and in-memory byte execution.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4507720
Reviewed
1 month ago

The plugin is a security auditor that reads system configuration and plugin source files to identify risks. It does not execute any dangerous commands itself; the flagged sudo commands are part of recommendation strings, not actual executions. The README examples are documentation of what the plugin detects. No malicious behavior found.

  • The deterministic scan flagged sudo commands in audit.py, but these appear to be recommendation strings for the user to copy, not commands executed by the plugin.
  • The README contains examples of dangerous patterns (curl|sh, eval) but these are illustrative of what the plugin detects, not actual code execution.
  • The script reads plugin source files and system configuration files, but only for pattern matching and does not exfiltrate data.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ucmz851/omasecurity --enable
System #system #security

OmaSecurity (ucmz851.omasecurity)

OmaSecurity is a lightweight, zero-bloat security posture auditor and deep plugin code health scanner designed specifically for the Omarchy Quattro desktop environment (omarchy-shell / Quickshell).

It provides continuous, glanceable security auditing on the status bar and expands into actionable recommendations with one-click copyable shell remediation commands.


<p align="center"> <img src="preview.png" alt="OmaSecurity Preview" width="420" /> </p>

Installation & Removal

Installation

Install directly using the Omarchy plugin manager:

omarchy plugin add https://github.com/ucmz851/omasecurity.git --enable

Removal

To disable and remove the plugin from your system:

omarchy plugin remove ucmz851.omasecurity

Core Security Capabilities

1. Deep Shell Plugin Code & Safety Analysis

Scans all installed QML, JavaScript, Python, Shell, and TOML files in ~/.config/omarchy/plugins/:

  • Dangerous Downloads & Execution: Detects unverified web piping (curl ... | sh / wget ... | bash).
  • Dynamic & Obfuscated Code: Detects eval(), new Function(), base64 decoding piped to shell, and in-memory byte execution.
  • Hardcoded Secrets & Tokens: Detects unencrypted private keys (RSA, OPENSSH, EC), GitHub Personal Access Tokens (ghp_), and cloud provider keys (AKIA...).
  • Protected Path Snooping: Flags scripts attempting to access ~/.ssh/id_*, ~/.gnupg/, ~/.local/share/keyrings/, browser profile data, or /etc/shadow.
  • Privilege Escalation (sudo/pkexec): Flags unneeded root invocations inside user plugins.
  • Pinpoint Reporting: Displays exact plugin name, relative file path, line number, risk explanation, and code snippet.

2. Linux Kernel & Memory Protections (Sysctl)

  • YAMA ptrace scope: Verifies process memory inspection protections (kernel.yama.ptrace_scope >= 1) to stop unauthorized memory dumping of browser tokens or password managers.
  • Kernel Log Restrictions: Verifies kernel.dmesg_restrict to prevent unprivileged users from reading kernel debug logs.
  • Kernel Symbol Hiding: Checks kernel.kptr_restrict to prevent kernel exploit address targeting.

3. Privilege Boundaries & Execution Integrity

  • Sudoers Audit: Detects dangerous NOPASSWD: ALL misconfigurations.
  • PATH Integrity: Audits $PATH to ensure no relative directories (.) or world-writable directories are present that could allow binary hijacking.

4. Host Firewall & Exposure

  • Firewall State: Audits ufw, nftables, or firewalld active states.
  • Listening Ports: Audits public listeners bound to 0.0.0.0 or :: vs localhost (127.0.0.1).
  • SSH Hardening: Verifies PermitRootLogin settings in /etc/ssh/sshd_config.

5. Authentication & Key Permissions

  • SSH Directory & Private Keys: Enforces 700 on ~/.ssh and 600 on private keys.
  • GnuPG Keyring: Enforces 700 permissions on ~/.gnupg/.
  • Session Locking: Verifies automated idle screen lock timeouts in hypridle.conf and shell.json.

User Interface & Features

  • Glanceable Status Bar Widget: Shield icon (󰒃) dynamically tints green, yellow, or urgent red based on security score.
  • Animated Rescan: Spinning refresh button () provides immediate visual feedback.
  • Category Filter Tabs: Quickly filter audit results by All, Plugins, System, Network, and Auth.
  • One-Click Remediation: Click any fix command box or press Enter/Space to copy the exact shell command to your clipboard.
  • Zero-Bloat Performance: Complete deep scan executes in <120ms without background daemons or battery drain.

Controls & Keybindings

Action How to Trigger
Open / Close Panel Left-click the shield icon on your top bar
Immediate Rescan Middle-click the bar icon, click the refresh icon, or press R inside panel
Navigate Issues Up / Down arrow keys
Copy Fix Command Enter / Space on selected issue, or click the copy button
Filter Categories Click category pills (All, Plugins, System, Network, Auth)
Dismiss Panel Escape

File Structure

omasecurity/
├── BarWidget.qml       # Bar widget icon, dynamic color tinting, and tooltip
├── Panel.qml           # Anchored flyout panel with score, category filters, and finding cards
├── manifest.json       # Omarchy Quattro plugin manifest (namespaced id: ucmz851.omasecurity)
├── LICENSE             # MIT License
├── README.md           # Documentation & instructions
├── preview.png         # Marketplace preview thumbnail
├── screenshots/        # Additional UI screenshots
└── scripts/
    └── audit.py        # Fast, non-blocking Python audit engine (<120ms execution)

License

MIT © ucmz851