# Security Omahero runs as unsandboxed user code inside `omarchy-shell` and launches a local Python helper with the user's privileges. Review the repository before enabling it. Report suspected vulnerabilities through [GitHub private vulnerability reporting](https://github.com/camerontucker/omahero/security/advisories/new), and avoid public disclosure until the report has been triaged. ## Supported versions Security fixes are made against the latest release on the `main` branch. Older releases are not maintained separately while Omahero is pre-1.0. ## System interactions - The Python helper reads Hyprland's active window, monitor, client, binding, option, and per-window property metadata through `hyprctl`. - Entering hero mode temporarily changes only the selected window's geometry, floating/fullscreen/maximum-size state and focus, plus opacity overrides for peer windows on the same workspace. Active, inactive, and fullscreen opacity values and their override flags are all recorded before mutation and restored. - The shell service creates click-through backdrop and top-bar dimming layers. It does not capture pointer or keyboard input on those surfaces. - Shape cycling and Escape are registered as contextual Hyprland bindings only while hero mode is active. They are removed on normal exit and recovery. - The first-run screen checks the proposed shortcut and writes a permanent binding only after the user confirms the exact change. Users can choose a custom shortcut, explicitly replace one occupied binding, or skip. The local installer follows the same path after an explicit command. - Shortcut setup manages one marked block in `$XDG_CONFIG_HOME/hypr/bindings.lua`, validates the change with Hyprland, and atomically restores the previous content if validation fails. - Symlinked Hyprland binding files remain symlinks. A dangling binding symlink is rejected instead of being replaced. - External commands are invoked as argument arrays. Dynamic commands passed to Hyprland's Lua dispatcher are encoded before use rather than interpolated as executable shell text. - Removal restores an active hero session and deletes only the marked Omahero binding block. Preferences and remembered shapes are retained. ## Local data and privacy Recovery state is written mode `0600` beneath `$XDG_RUNTIME_DIR/omahero` before any compositor mutation. Per-application shape preferences are written mode `0600` beneath `$XDG_STATE_HOME/omahero`. Setup completion and optional configuration are stored beneath `$XDG_CONFIG_HOME/omahero`. Omahero does not inspect window contents, clipboard data, typed text, browser data, or credentials. It has no network client, account, telemetry, package installer, privilege escalation, or remote-code download path.