Omahub
← All plugins
B

VideoCorner

by bms

Search YouTube from the bar and pop out a video player.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
e7abb03
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e7abb03
Reviewed
1 month ago

No malicious or obfuscated code was found: the plugin searches YouTube via yt-dlp, opens a Chromium app window, and manages it with hyprctl, with external input sanitized. The one notable issue is that scripts/install-extension.sh silently adds a global Chromium --autoplay-policy=no-user-gesture-required flag that the README's transparency section doesn't disclose and remove-extension.sh doesn't remove. This is a browser-wide behavior change, not a system compromise, so the risk is low but worth a human look.

  • scripts/install-extension.sh appends --autoplay-policy=no-user-gesture-required to ~/.config/chromium-flags.conf, affecting all Chromium sites, while the README says it only appends the extension path and leaves every other line untouched.
  • scripts/remove-extension.sh removes only the VideoCorner --load-extension entry and leaves the autoplay flag behind, so uninstalling does not fully restore the previous Chromium configuration.
  • The bundled Chromium extension and QML/scripts otherwise look safe: no shell injection, no credential access, no destructive commands, and the extension only acts on URLs containing videocorner=1.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/brianspragge/videocorner --enable
Widgets #media

VideoCorner

Search YouTube from the Omarchy bar and pop the selected video into a floating, pinned, movable player window.

VideoCorner controls

VideoCorner search results

VideoCorner floating video player

Features

  • YouTube search through yt-dlp
  • Floating, pinned player that auto-matches the video's real aspect ratio
  • Video-only layout (no page chrome) via a bundled Chromium extension
  • Full native YouTube controls — play, pause, seek, volume, captions, settings
  • Configurable corner and size

Usage

Click the ▶ bar icon to open the panel, type to search, then click a video or press Ctrl+1…9 to play it. Move/resize the player from the panel.

Keys

While Panel is open

Key Action
Ctrl+1…9 play the numbered video
Ctrl+↑↓←→ / Ctrl+h/j/k/l move the player around
Ctrl+= / Ctrl+- resize up / down
Ctrl++ / Ctrl+_ max/min size
Ctrl+Q close the video
Esc / Ctrl+[ close the panel (back to main view from results)

Requirements

  • Omarchy Quattro
  • Chromium
  • yt-dlp which uses an api to search for youtube videos

Install

Use Omarchy's SUPER+SPACE->Setup->Plugins->Add Plugin and enter the url

https://github.com/brianspragge/videocorner.git

Then register the Chromium extension for the video-only player layout and restart Chromium by running:

~/.config/omarchy/plugins/bms.videocorner/scripts/install-extension.sh

Optional: add a keyboard shortcut

To open and close VideoCorner from anywhere, add this line to your personal Hyprland keybindings file, ~/.config/hypr/bindings.lua:

o.bind("SUPER + CTRL + Y", "VideoCorner", "omarchy-shell shell toggle bms.videocorner")

Clicking the ▶ bar icon also works, so this keybind is optional.

Remove

Run

~/.config/omarchy/plugins/bms.videocorner/scripts/remove-extension.sh

Use Omarchy's SUPER+SPACE->Setup->Plugins->Remove Plugin ITS GONE like nothing ever happened.

Transparency

VideoCorner runs only when you open its panel or play a video. It does not intercept or change input for any other application or window. Extension is minimal without peeping at your junk.

What the extension installer touches

The install-extension.sh script edits exactly one file:

~/.config/chromium-flags.conf

  • It appends the VideoCorner extension path to the existing --load-extension= line (or adds that line if it's absent).
  • Every other line in the file is left untouched.
  • It is idempotent: running it again does nothing.

What it does not touch

  • Hyprland, its input handling, or any keybindings
  • ~/.config/omarchy/shell.json or any other Omarchy settings
  • Browser history, bookmarks, cookies, or other Chromium data
  • Any other application, window, or remote session (e.g. browser-based environments like GitHub Codespaces)

Player extension scope

The bundled Chromium extension only activates for URLs containing videocorner=1 (your selected video). Regular YouTube tabs and all other sites are unaffected. It isn't necessary, but then you will have to manually enlarge every video you search for. The extension removes all the youtube page css junk.

Removal

scripts/remove-extension.sh strips only the VideoCorner entry from ~/.config/chromium-flags.conf, leaving every other flag and file intact.

License

MIT © 2026 Brian Spragge