Omahub
← All plugins
B

Codex Notifications

by Brian Blakely

Clickable lifecycle notifications that return to the originating Codex context.

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
5fa6339
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
5fa6339
Reviewed
1 month ago

The high-severity deterministic finding is a false positive: `dd bs=4096 of=/dev/null` is only draining stdin in `hook-adapter` and does not write to disk, and the flagged octal escapes are tmux field separators in test fixtures, not production obfuscation. The plugin transparently installs Codex lifecycle hooks, sends notifications, and focuses the originating terminal; its hooks-file updates are atomic, locked, idempotent, and preserve user-owned entries. No credential theft, hidden persistence, or destructive behavior was found.

  • The plugin automatically modifies `~/.codex/hooks.json` to register its own handlers; users should follow the README and run `/hooks` in Codex to review and trust them.
  • If enabled, Stop/SubagentStop/PostToolUse notifications can include recent Codex output or tool responses as plain-text notification descriptions, which may expose sensitive content on screen.
  • The deterministic scan's destructive_filesystem and obfuscation findings are false positives: a stdin drain and test-only escape sequences.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/brianblakely/omarchy-codex-notifications --enable
Developer Tools #ai

Codex Notifications

Clickable Omarchy notifications for Codex lifecycle events. Clicking a notification (or invoking it with SUPER + ALT + COMMA) focuses the terminal, tmux pane, or Herdr agent pane that is running the corresponding Codex instance.

Notification screenshot

Install

omarchy plugin add https://github.com/brianblakely/omarchy-codex-notifications.git --enable --yes

To complete the install, close all instances of Codex, open a fresh one, and run /hooks to review and trust the new notification handler. Notification handlers are added to ~/.codex/hooks.json for all supported events without disrupting any pre-existing handlers.

Configure

Settings are configured in ~/.config/omarchy/shell.json. Here are the defaults:

{
  "id": "b.codex-notifications",
  "events": ["PermissionRequest", "Stop"],
  "notifyWhenFocused": true
}

events accepts these Codex lifecycle hooks:

  • SessionStart
  • SessionEnd
  • SubagentStart
  • PreToolUse
  • PermissionRequest (notifications suppressed when auto-approve is enabled)
  • PostToolUse
  • PreCompact
  • PostCompact
  • UserPromptSubmit
  • SubagentStop
  • Stop

notifyWhenFocused defaults to true; set it to false to notify only while Codex is in the background.

Update

omarchy plugin update b.omarchy-codex-notifications

Uninstall

omarchy plugin remove b.omarchy-codex-notifications