Skip to content

feat(plugins): add BoozeLee/omarchy-audit - #70

Closed
BoozeLee wants to merge 1 commit into
MiniMax-AI:mainfrom
BoozeLee:feat/omarchy-audit
Closed

BoozeLee wants to merge 1 commit into
MiniMax-AI:mainfrom
BoozeLee:feat/omarchy-audit

Conversation

@BoozeLee

@BoozeLee BoozeLee commented Oct 4, 2026 •

Copy link
Copy Markdown

Adds a dependency-free stdio MCP server plus a Skill for static security triage of an Omarchy checkout.

Why

Three things go wrong with a naive sweep, and each one costs a whole hunt:

Extension-based discovery finds nothing. bin/ ships 444 scripts and none of them end in .sh — they are all extensionless. The 464 files that do end in .sh live in test/, migrations/, and install/. So:

$ find bin -name '*.sh' | wc -l
0
$ find bin -type f | wc -l
444

This Plugin discovers scripts by shebang and finds all 444.

Most summaries of the fix history are incomplete. Omarchy shipped 27 security fixes across v4.0.1, v4.0.2, and v4.0.3; the commonly cited list has 8. The embedded map records each one's file, PR, and remedy — so a sibling lacking the remedy is distinguishable from the fix itself, which is what determines whether a finding is new or a duplicate.

"Root-reachable" is not "runs as root." Grepping bin/ for scripts without export PATH= returns 67 hits, and every one is a false positive: they run as the user and merely call sudo, so sudo's own secure_path governs the child. Only scripts in etc/sudoers.d/ are actually invoked as root — two omarchy ones, both already fixed. The Skill says so and tells you to enumerate that set first.

The Skill also records that the default branch is quattro at 4.0.0.alpha, not the release, so findings should be taken against the tag users run.

Try it

cp -r omarchy-audit ~/.minimax/plugins/
mcode plugin add omarchy-audit@local

Or drive the server directly, with no dependencies:

printf '%s\n' \
  '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{}}' \
  '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"discover_scripts","arguments":{"root":"/path/to/omarchy"}}}' \
  | node server.mjs

Requirements

MiniMax Code 0.3+ for the Skill, or Node 18+ for server.mjs directly. shellcheck on PATH for the shellcheck_run tool; without it that one tool returns a note and the rest keep working. An Omarchy checkout to audit.

Network and data

  • No network access. The fix map is embedded rather than fetched, so a sweep works fully offline and this Plugin never contacts a registry, API, or package index.
  • No credentials. It reads no environment secrets and writes no configuration.
  • Reads the target tree only, and writes nothing to it. It never follows a symlink out of the tree.
  • Never executes target code. shellcheck parses; it does not run. Covered by a regression test that plants a script which would create a marker file and asserts the marker never appears.
  • Never submits anything. It emits a table. Reporting is a human decision.

Verification

Against a v4.0.4 checkout:

Check Result
discover_scripts on bin/ 444 scripts (a *.sh glob finds 0)
shellcheck_run 461 scripts, 121 findings, 15 tagged already-fixed-pattern
classify on a known-fixed path already-fixed-pattern
Planted marker script never executes
Symlinks in the package 0
Literal TODO 0

Repository gate:

$ npm run validate
OK   plugin BoozeLee/omarchy-audit
Validated 29 hosted Plugins and all examples.

$ npm run check
# tests 345
# pass  342
# fail  3

The 3 failures are all in tests/plugins/octopus-meme-maker and reproduce on the base commit 6481e4a with this plugin absent, so they are unrelated. Their cause looks like a genuine portability bug worth a separate issue: that plugin's scripts/_fonts.py hardcodes Debian-only FONT_CANDIDATES paths (/usr/share/fonts/opentype/noto/..., /usr/share/fonts/truetype/wqy/...), while Arch and Omarchy install fonts-noto-cjk to /usr/share/fonts/noto-cjk/, which is in none of those candidates. I did not touch it, per the guidance not to modify another contributor's Plugin.

Not bounty-targeted and not a security fix — offered as a reusable triage tool.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Static security triage for an Omarchy checkout: shebang-based script discovery,
batched shellcheck, and an embedded map of the v4.0.1-v4.0.3 security fixes so an
already-patched finding is not re-reported.

Discovery is shebang-based because extension-based discovery finds nothing. Omarchy's
bin/ ships 444 scripts and none of them end in .sh - they are all extensionless - while
the 464 real .sh files sit in test/, migrations/ and install/. A `find bin -name '*.sh'`
sweep returns 0 and never inspects a single shipped command. This finds all 444.

The fix map records the remedy used for each of the 27 shipped fixes, not just the bug,
so a sibling that lacks the remedy is distinguishable from the fix itself. Most
summaries list only 8 of the 27.

The Skill also records two traps that otherwise waste a whole hunt:
- the default branch is quattro at 4.0.0.alpha, not the release; audit the tag
- "root-reachable" is not "runs as root". Grepping bin/ for a missing `export PATH=`
  yields 67 hits that are all false positives, because those scripts run as the user
  and call sudo, so sudo's secure_path governs the child. Only scripts in
  etc/sudoers.d are invoked as root, and both omarchy ones already carry the fix.

Verified against a v4.0.4 checkout:
  discover_scripts -> 444 bin/ scripts (0 via a *.sh glob)
  shellcheck_run   -> 461 scripts, 121 findings, 15 tagged already-fixed-pattern
  a planted script that would create a marker file never executes

The server is dependency-free Node over stdio. It executes no target code, writes
nothing to the target, makes no network calls, and submits nothing anywhere: it emits a
table and a human decides what to report.

npm run validate -> OK plugin BoozeLee/omarchy-audit, 29 hosted Plugins validated
npm run check    -> 345 tests, 342 pass, 3 fail; all 3 are in
                    tests/plugins/octopus-meme-maker and reproduce on the base commit
                    with this plugin absent (its scripts/_fonts.py hardcodes Debian-only
                    font paths, so it fails on Arch/Omarchy even with CJK fonts
                    installed). No failure touches this plugin.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant