Conversation
Static security triage for an Omarchy checkout: shebang-based script discovery,
batched shellcheck, and an embedded map of the v4.0.1-v4.0.3 security fixes so an
already-patched finding is not re-reported.
Discovery is shebang-based because extension-based discovery finds nothing. Omarchy's
bin/ ships 444 scripts and none of them end in .sh - they are all extensionless - while
the 464 real .sh files sit in test/, migrations/ and install/. A `find bin -name '*.sh'`
sweep returns 0 and never inspects a single shipped command. This finds all 444.
The fix map records the remedy used for each of the 27 shipped fixes, not just the bug,
so a sibling that lacks the remedy is distinguishable from the fix itself. Most
summaries list only 8 of the 27.
The Skill also records two traps that otherwise waste a whole hunt:
- the default branch is quattro at 4.0.0.alpha, not the release; audit the tag
- "root-reachable" is not "runs as root". Grepping bin/ for a missing `export PATH=`
yields 67 hits that are all false positives, because those scripts run as the user
and call sudo, so sudo's secure_path governs the child. Only scripts in
etc/sudoers.d are invoked as root, and both omarchy ones already carry the fix.
Verified against a v4.0.4 checkout:
discover_scripts -> 444 bin/ scripts (0 via a *.sh glob)
shellcheck_run -> 461 scripts, 121 findings, 15 tagged already-fixed-pattern
a planted script that would create a marker file never executes
The server is dependency-free Node over stdio. It executes no target code, writes
nothing to the target, makes no network calls, and submits nothing anywhere: it emits a
table and a human decides what to report.
npm run validate -> OK plugin BoozeLee/omarchy-audit, 29 hosted Plugins validated
npm run check -> 345 tests, 342 pass, 3 fail; all 3 are in
tests/plugins/octopus-meme-maker and reproduce on the base commit
with this plugin absent (its scripts/_fonts.py hardcodes Debian-only
font paths, so it fails on Arch/Omarchy even with CJK fonts
installed). No failure touches this plugin.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a dependency-free stdio MCP server plus a Skill for static security triage of an Omarchy checkout.
Why
Three things go wrong with a naive sweep, and each one costs a whole hunt:
Extension-based discovery finds nothing.
bin/ships 444 scripts and none of them end in.sh— they are all extensionless. The 464 files that do end in.shlive intest/,migrations/, andinstall/. So:This Plugin discovers scripts by shebang and finds all 444.
Most summaries of the fix history are incomplete. Omarchy shipped 27 security fixes across v4.0.1, v4.0.2, and v4.0.3; the commonly cited list has 8. The embedded map records each one's file, PR, and remedy — so a sibling lacking the remedy is distinguishable from the fix itself, which is what determines whether a finding is new or a duplicate.
"Root-reachable" is not "runs as root." Grepping
bin/for scripts withoutexport PATH=returns 67 hits, and every one is a false positive: they run as the user and merely callsudo, so sudo's ownsecure_pathgoverns the child. Only scripts inetc/sudoers.d/are actually invoked as root — two omarchy ones, both already fixed. The Skill says so and tells you to enumerate that set first.The Skill also records that the default branch is
quattroat4.0.0.alpha, not the release, so findings should be taken against the tag users run.Try it
cp -r omarchy-audit ~/.minimax/plugins/ mcode plugin add omarchy-audit@localOr drive the server directly, with no dependencies:
Requirements
MiniMax Code 0.3+ for the Skill, or Node 18+ for
server.mjsdirectly.shellcheckonPATHfor theshellcheck_runtool; without it that one tool returns a note and the rest keep working. An Omarchy checkout to audit.Network and data
shellcheckparses; it does not run. Covered by a regression test that plants a script which would create a marker file and asserts the marker never appears.Verification
Against a
v4.0.4checkout:discover_scriptsonbin/*.shglob finds 0)shellcheck_runalready-fixed-patternclassifyon a known-fixed pathalready-fixed-patternTODORepository gate:
The 3 failures are all in
tests/plugins/octopus-meme-makerand reproduce on the base commit6481e4awith this plugin absent, so they are unrelated. Their cause looks like a genuine portability bug worth a separate issue: that plugin'sscripts/_fonts.pyhardcodes Debian-onlyFONT_CANDIDATESpaths (/usr/share/fonts/opentype/noto/...,/usr/share/fonts/truetype/wqy/...), while Arch and Omarchy installfonts-noto-cjkto/usr/share/fonts/noto-cjk/, which is in none of those candidates. I did not touch it, per the guidance not to modify another contributor's Plugin.Not bounty-targeted and not a security fix — offered as a reusable triage tool.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.