# Security This plugin is unsandboxed Omarchy shell code. Marketplace validation and the Automated Security Baseline are static checks of an exact commit. They are not a security audit, certification, warranty, or endorsement. No sudo or pkexec is required. ## What it can do - Spawn `python3`, `adb`, and `omarchy agent prompt` as your user. - Talk to a paired Android phone over ADB (USB or TCP). The first USB sync may run `adb tcpip 5555` so later syncs work on a private LAN. Classic TCP ADB is unauthenticated. Only private or link-local addresses are saved and reconnected. - Wake the screen, dump the Pebble app UI, and send taps/swipes. It does not dismiss a lock screen. - Read and write `~/.local/state/omarchy/pebble-index/` (`index.json` and `adb.json`, mode 600; directory 700) through descriptor-based helpers (`bin/state.py`): O_NOFOLLOW, regular-file, owner, and size checks. Writes go to an exclusive unpredictable temp (O_EXCL, mode 0600 on the fd) and `rename()` onto the destination name. - Local IPC from your session: `omarchy-shell v.pebble-index` with `open|close|toggle|refresh|sync|notes|send`. ## What it does not do - No package manager commands. - No download-to-shell and no unpinned remote Git execution. - Index contents are not uploaded. Sending a row to the coding agent is an explicit local action. ## Data | Path | Mode | Contents | | --- | --- | --- | | `~/.local/state/omarchy/pebble-index/` | 700 | plugin state | | `index.json` | 600 | last scraped reminders and notes | | `adb.json` | 600 | saved ADB host/port/serial | UI dumps stay under `/data/local/tmp/` on the phone. Locally they are streamed with `adb exec-out` onto an exclusive fd (never `adb pull` onto the predictable `ui-dump.xml` path) and unlinked after parsing. Phone-controlled reminder and note strings are shown as `textFormat: Text.PlainText`. Report a plugin-specific concern through this repository's issues with titles and serials redacted. Marketplace-wide reports go through [omarchy-plugin-marketplace private reporting](https://github.com/HANCORE-linux/omarchy-plugin-marketplace/security/advisories/new).