Omahub
← All plugins
A

OMARCHOMANDER

by Asfar Sadewa

A two-panel file manager for the Omarchy shell with the keyboard commands of Norton Commander. It copies, moves, and renames files, moves files to the trash, shows file contents, runs commands, and shows system information.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
dde2d1d
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
dde2d1d
Reviewed
1 month ago

This is a well-structured, clearly-documented Norton Commander-style file manager for the Omarchy shell. The code is clean, defensive, and accompanied by a thorough test suite. The deterministic scan's single 'obfuscation' finding is a false positive: it flags a binary test fixture (`b"\x00\x01ABC"`) in test_viewer.py used to verify hex-dump output, not obfuscated code. The plugin's ability to run shell commands and delete files is its documented, user-invoked purpose, and all such operations include appropriate confirmations and safety checks.

  • The plugin executes shell commands via `sh -c` (shellcmd.py), but this is the explicitly documented core feature of the file manager's command line, runs with user privileges, and is capped at 30 seconds with output limits.
  • The plugin can permanently delete files, but only after explicit user confirmation with 'No' preselected, and the code carefully guards against symlink attacks and self-copy data loss.
  • The deterministic scan's 'obfuscation' flag on tests/test_viewer.py:31 is a false positive — it is a binary test fixture for the hex viewer, not obfuscated or malicious code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/asfarsadewa/omarchy-omarchomander --enable
System #quickshell #system

OMARCHOMANDER

OMARCHOMANDER is a file manager plugin for the Omarchy shell. It shows two directory panels, a command line, and a row of function keys. The keyboard commands agree with the commands of Norton Commander.

OMARCHOMANDER

Functions

  • Two directory panels. Each panel can sort, filter, and select files.
  • File operations: copy, move, rename, make directory, move to trash, permanent delete. Each operation shows its progress and asks before it overwrites or deletes data.
  • F8 moves files to the freedesktop.org trash ($XDG_DATA_HOME/Trash). Other file managers can restore these files. Shift+F8 deletes files permanently after a confirmation.
  • F3 shows the content of a file as text, or as hexadecimal data for a binary file. F4 opens the file in the configured Omarchy editor.
  • Ctrl+L shows system information in the second panel: CPU, cores, load, RAM, swap, disk, and uptime.
  • A command line below the panels. Text you type goes to the command line. Enter runs the command in the directory of the active panel. The command output shows on the Ctrl+O screen. The command cd changes the directory of the active panel.
  • The panel directories, sort orders, and the hidden-file setting persist across sessions.

Installation

Run these commands:

omarchy plugin add https://github.com/asfarsadewa/omarchy-omarchomander.git
omarchy plugin enable asfarsadewa.omarchomander

The plugin adds a folder icon to the bar. Click the icon to open the file manager. The installation does not add a keyboard shortcut. To add one, put this line in ~/.config/hypr/bindings.conf:

bindd = SUPER SHIFT, N, File manager, exec, omarchy-shell omarchomander toggle

The plugin has no external dependencies. It uses the Python 3 standard library, which Omarchy includes.

Removal

Run this command:

omarchy plugin remove asfarsadewa.omarchomander

This removes the plugin files and the bar icon. The plugin state file remains at ~/.local/state/omarchomander/state.json. Delete it if you do not want to keep it. Files in the trash remain in the trash.

Keyboard commands

Keys Function
↑ ↓ PgUp PgDn Home End Move the cursor. A mouse click also moves the cursor.
Tab Change the active panel.
Ctrl+U Exchange the two panels.
Backspace Go to the parent directory (with an empty command line).
Enter Enter a directory, or open a file with the default application.
Ins / Ctrl+T Select or deselect the file at the cursor.
+ / - / * Select all, select none, invert the selection (with an empty command line, or on the keypad).
Ctrl+S Filter the active panel. Type to narrow the list. Esc removes the filter. Enter keeps it.
Ctrl+H Show or hide the hidden files.
Ctrl+R Read the directories again.
F1 Show the help screen.
F2 / Ctrl+L Show system information in the second panel.
F3 Show the file at the cursor (text or hexadecimal).
F4 Open the file at the cursor in the Omarchy editor.
F5 Copy the selected files to the given path. The path of the second panel is the initial value.
F6 Move the selected files to the given path. A name without / renames the file. Shift+F6 sets the current name as the initial value.
F7 Make a directory.
F8 / Del Move the selected files to the trash, after a confirmation.
Shift+F8 / Shift+Del Delete the selected files permanently, after a confirmation. The confirmation preselects No.
F9 Set the sort order of the active panel: name, extension, time, size, or none.
Ctrl+Enter Put the name of the file at the cursor on the command line.
Ctrl+E / Ctrl+X Go through the command history.
Ctrl+O Show or hide the command-output screen.
F10 / Esc Close the file manager. Esc first clears a typed command, then closes an open screen.

File operations

  • When a target file exists, the operation stops and asks: Overwrite, All, Skip, Skip all, or Abort. Enter selects Skip. The question shows the size and time of both files.
  • The progress dialog shows the current file, the file count, and the byte count. C cancels the operation. Esc hides the dialog; the operation continues. F10 closes the file manager; the operation continues and the bar icon shows the progress.
  • When an operation reports errors, the full error list is available on the Ctrl+O screen.
  • A move on one filesystem is a rename. A move to a different filesystem copies the data first and then removes the source. A trash operation to a different filesystem also copies the data first.
  • Copied directories keep their permissions and modification times.

The command line

The command line is not a terminal. A command gets no terminal and no standard input. The output is limited to 400 lines. A command stops after 30 seconds. A background process that a command starts continues to run; the file manager stops waiting for its output shortly after the command exits.

Architecture

The QML layer only paints. A Python backend (directory omarchomander/, standard library only) holds the panel state, the cursor rules, the selection, the rendering, and all file operations. The backend and the shell communicate with one JSON object per line on stdin and stdout.

Tests

Run:

./scripts/test

The test suite needs only the Python standard library. It covers the directory listing, the renderer, the panel rules, the file operations with their conflict and cancel paths, the trash, the viewer, the system information, and the command dispatch.

License

MIT