Omahub
← All plugins
C

Omatidy

by Casper Bottelet

Rule-based file tidying. A hotkey-summoned rules pane and a background folder watcher: invoices filed by date, downloads unzipped, old installers binned — automatically.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
15126cc
Scanned
1 month ago
  • medium eval tests/run.sh:21

    Shell sources dynamically generated content.

    source <(sed '/^# ---------- CLI/,$d' "$engine")
  • medium package_manager …/workflows/test.yml:14

    System package manager operation.

    apt-get install -y jq libarchive-tools
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y jq libarchive-tools

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
15126cc
Reviewed
1 month ago

Omatidy is a local, rule-driven file-management engine; the sampled runtime code is straightforward, with no network access, obfuscation, or install-time execution. The deterministic 'medium' findings are confined to the test harness and GitHub Actions CI (process substitution in tests/run.sh and sudo apt-get in test.yml), not end-user code. The main remaining risk is the plugin's intended ability to automatically move/trash/permanently delete files based on user-created rules, which can cause data loss if misconfigured.

  • Automatic watcher runs can apply move/trash/delete actions without per-action confirmation; this is a documented feature, but users should be careful with broad rules or the 'delete' action.
  • LICENSE contains boilerplate 'External dependencies and services' text describing another plugin (curl, devdocs.io, omarchy-quickdocs) that contradicts Omatidy's no-network claim; no corresponding network code appears in the sampled runtime files, so it appears to be a documentation copy/paste issue.
  • Deterministic scan findings are non-runtime: tests/run.sh dynamically sources engine functions for unit tests, and .github/workflows/test.yml uses sudo apt-get inside CI only; neither executes on a user's machine.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Bottelet/omarchy-omatidy --enable
Productivity #quickshell #system

Omatidy

Your folders, on autopilot. Point rules at a folder and stop living in a landfill: invoices file themselves by date, downloads unzip themselves, week-old installers walk to the trash — all in the background while you work.

Omatidy

Features

  • Hotkey-summoned rules pane — no bar icon; one key opens a two-pane editor (rules left, conditions & actions right), Esc closes it. Arrow keys step through rules.
  • Rules that read like sentences — conditions (name contains, glob, extension, content contains — including inside PDFs, older than N days, size over/under) matched with all or any, then actions applied in order: move, copy, rename, extract, trash, delete. Rules run top to bottom; the first match wins per file.
  • A real background watcher — flip Watching on and an inotify loop reacts to folder changes within seconds, waits for downloads to settle (.part/.crdownload and friends are never touched), and sweeps every 15 minutes so age-based rules fire without folder activity. Survives shell restarts; only ever one watcher no matter how many monitors you have.
  • Tokens — {name} {ext} {date} {year} {month} {day} {today} work in rename patterns and destination folders: ~/Documents/{ext} sorts a whole folder by type with one rule, {date} {name} stamps files with their modified date, and a pattern ending in a new extension changes it ({name}.md for feeding an Obsidian vault).
  • Extract that thinks — archives with one top-level folder unpack in place; loose-file archives get a folder named after the archive. Never overwrites. Chain with trash for the classic "unzip it, bin the zip".
  • Preview before you trust it — every rule has a dry-run Preview showing exactly what would happen right now, and an Activity feed shows everything the watcher has done (also logged to ~/.local/state/omatidy/omatidy.log).
  • Safe by construction — name collisions get 2, 3, … instead of overwriting, hidden files are ignored, trash uses the real system trash (gio trash), and delete is clearly marked as bypassing it.

Install

omarchy plugin add https://github.com/Bottelet/omarchy-omatidy.git --enable

There is no bar icon — bind a key in ~/.config/hypr/bindings.lua:

o.bind("SUPER + SHIFT + T", "Omatidy", "omarchy-shell shell toggle bottelet.omatidy")

Usage

Open the pane, add a rule, point it at a folder, add conditions and actions. Preview shows what it would do; Run now applies it once; the Watching toggle keeps it running in the background from then on.

Rules live in ~/.config/omatidy/rules.json if you prefer editing JSON — the pane and the watcher both pick up outside edits live.

Some favorites:

Rule Conditions Actions
Unzip downloads extension is zip, tar.gz extract → move to trash
File invoices extension pdf + content contains invoice move to ~/Documents/Invoices as {date} {name}
Purge old installers glob *.iso + older than 7 days move to trash
Sort by type (no conditions — everything) move to ~/Documents/{ext}
Emails → Obsidian extension txt rename {name}.md, move to vault

Tests

The rule engine ships with a 37-case test suite (pattern expansion, every condition type, first-match-wins, extract shapes, dry-run, collision handling), run on every push by CI:

tests/run.sh

Security

Omatidy makes no network requests — everything runs locally as your user. The watcher only ever touches the folders your rules point at, and filenames are handled strictly as data: every external command gets them as arguments (argv arrays end to end), nothing is interpolated into a shell string, and names shown in the pane render as plain text. Extraction relies on bsdtar's default protections (absolute paths, .. traversal, and writes through symlinks are refused) and never overwrites existing files. Symlinks and hidden files in watched folders are always ignored. The test suite includes hostile-filename and traversal-archive regression cases.

Remove

omarchy plugin remove bottelet.omatidy

Your rules (~/.config/omatidy/) and the activity log (~/.local/state/omatidy/) stay behind; delete those folders to remove every trace.

Dependencies

Everything ships with Omarchy: jq, bsdtar (libarchive), gio (glib2), inotify-tools, python3. Optional: poppler (pdftotext) for content matching inside PDFs.

python3 is used for exactly one thing: opening the rules file with O_NOFOLLOW | O_NONBLOCK and validating it on that descriptor, which bash cannot express. Nothing else in the engine needs it.

License

MIT