Omahub
← All plugins
9

devlinkspad

by 920four

Command palette for Stripe, Vercel, Apple Team ID, and 140+ developer dashboard pages.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
0100e7d
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
0100e7d
Reviewed
1 month ago

The plugin is a local command palette that opens curated https dashboard URLs via xdg-open, with a small optional license/device-pairing flow against devlinkspad.com. The code is unusually defensive: it pins directories with file descriptors, refuses symlinks/FIFOs, caps response sizes, and sanitizes URLs and curl config before use. No destructive, obfuscated, or credential-exfiltrating behavior was found; the only residual risk is the inherent trust placed in the remote devlinkspad.com license endpoint and the bundled catalog.

  • The plugin performs network calls to devlinkspad.com for device pairing and license checks; a compromised or malicious server could in principle influence the license state, though the code caps response size and validates the URL/token format.
  • The bundled catalog is shipped in data/services.json and is read through a pinned directory fd; the sample is truncated, so a full review of every URL in the catalog was not possible, but the code only allows https:// URLs and sanitizes them before xdg-open.
  • The plugin is keepLoaded and runs a Python helper (save-state.py) on open; the helper is defensive and well-tested, but it is still executable code invoked from the overlay, so a human should confirm the full file matches the reviewed sample.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/920four4/omarchy-devlinkspad --enable
Developer Tools #quickshell #launcher

devlinkspad for Omarchy

Fullscreen command palette for Omarchy Quattro. Type stripe webhook, apple team id, or vercel tokens and Enter opens that dashboard in your browser.

Same catalog as devlinkspad.com. Search is local. Checkout never runs inside Omarchy.

Plugin id: 920four.devlinkspad (overlay). Modeled on omarchy.emojis / omarchy.clipboard.

Install

omarchy plugin add https://github.com/920four4/omarchy-devlinkspad.git --enable

Then:

omarchy-shell shell toggle 920four.devlinkspad '{}'

Escape closes it. Type to filter, arrows to move, Enter to open.

Keybind

Super + K is Omarchy’s keybinding cheatsheet. Bind Super + Shift + L:

-- ~/.config/hypr/bindings.lua
o.bind("SUPER + SHIFT + L", "devlinkspad",
  "omarchy-shell shell toggle 920four.devlinkspad '{}'")

Reload Hyprland (omarchy restart hyprland or log out/in) if the bind does not take immediately.

Prefill a query:

omarchy-shell shell summon 920four.devlinkspad '{"q":"apple team id"}'

Usage

  • Type to search the bundled catalog
  • ↑ ↓ / PageUp PageDown / Home End
  • Enter opens the URL with xdg-open
  • Escape clears the query, then closes
  • Click the dimmed scrim to dismiss
  • 20 free jumps. Click Sign in for unlimited to open devlinkspad.com in your browser. If you already have Pro, sign in and this computer unlocks. If not, Pro is $5/year — payment is never collected inside the plugin.

Remove

omarchy plugin remove 920four.devlinkspad

That disables the plugin and deletes the git checkout. It does not edit Hyprland binds or touch other Omarchy config. Optional leftover: ~/.local/state/omarchy/devlinkspad.json (device pairing + free-jump count). The plugin walks $HOME/.local/state/omarchy refusing a symlink at any step, pins that directory with a file descriptor, and reads/writes the state file only through that fd (O_NOFOLLOW|O_NONBLOCK on open; exclusive 0600 temp + renameat on write). The path is not re-resolved after the pin. Delete that file if you want a clean slate.

If you added the Super+Shift+L bind yourself, remove it from ~/.config/hypr/bindings.lua.

External dependencies

No sudo, no install hooks, no extra packages.

Dependency Why
xdg-open Open dashboard URLs and the sign-in page in your default browser
curl Optional Pro license check against https://devlinkspad.com. The bearer token is passed through curl’s stdin config (-K -), not process argv. Responses are capped at 8 KiB.
python3 Pin ~/.local/state/omarchy and data/ with a directory fd; read/write through that fd (O_NOFOLLOW, O_NONBLOCK, mode 0600 from the first create)
openssl Random device id for pairing (falls back if missing)

The catalog ships in data/services.json. Network is used only for Pro pairing / license refresh, not for search. License HTTP bodies are capped at 8 KiB. The catalog and persisted state file are both read through a pinned directory fd (O_NOFOLLOW|O_NONBLOCK) with a byte ceiling, so a replaced file or FIFO cannot grow or stall the keep-loaded overlay. xdg-open only receives https:// URLs.

Files

File Role
manifest.json Quattro overlay contract (keepLoaded)
Overlay.qml Fullscreen palette
Search.js Local catalog scoring
License.js Free-jump counter + Pro pairing state
save-state.py Walk + pin dirfds; owner-only no-follow I/O for the license state file and catalog
data/services.json Bundled deep links

Not affiliated with Apple, Stripe, Vercel, or Expo. Dashboard URLs belong to those products.