Omahub
← All plugins
C

Quickdocs

by Casper Bottelet

Dash-style offline API documentation search. Hotkey-summoned overlay with fuzzy search across devdocs.io docsets, rendered in a panel, fully offline.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
da7079c
Scanned
1 month ago
  • medium external_hosts Overlay.qml:363

    Downloads or connects to an external HTTP(S) host.

    curl -fsSL --proto '=https' --proto-redir '=https' --max-filesize 10485760 --max-time 12 https://devdocs.io/docs.json | head -c 10485760 | jq -c '[.[] | {name, slug, version, release, size: .db_size, 

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
da7079c
Reviewed
1 month ago

The plugin downloads documentation from devdocs.io over HTTPS only when the user explicitly installs a docset, with size limits and HTML sanitization to prevent remote resource loading. The code is transparent, includes path/slug validation, and writes only to its own data directory. No malicious or hidden behavior was found.

  • Contacts an external service (devdocs.io) to download docsets; this is expected functionality but could be a vector if the service is compromised.
  • Downloaded HTML is sanitized to strip remote resources, but the sanitization is not exhaustive (e.g., CSS url() handling) and relies on the overlay's additional stripping at render time.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Bottelet/omarchy-quickdocs --enable
Developer Tools #quickshell #launcher

Quickdocs

Dash for Omarchy. Press a hotkey, fuzzy-search offline API documentation for your languages, and read the page right there — no browser, no network.

Quickdocs

Features

  • Hotkey-summoned overlay — no bar icon; one key opens the search, Esc closes it. Keyboard-first throughout.
  • Fuzzy search across every installed docset, with docset scoping: js:map, py:dict, go:append.
  • Instant preview — arrow through results and the page renders in the panel; PgUp/PgDn scrolls it. Relative links between pages work offline, external links open your browser.
  • 800+ docsets from devdocs.io — JavaScript, Python, Go, Rust, PHP, Laravel, React, PostgreSQL, Bash, and everything else devdocs ships. Download once, use forever offline.
  • Built-in docset manager — Ctrl+D lists the catalog (refreshed live from devdocs when online); Enter downloads, Del removes. Anything not in the catalog installs by typing its devdocs slug.

Install

omarchy plugin add https://github.com/Bottelet/omarchy-quickdocs.git --enable

There is no bar icon — bind a key in ~/.config/hypr/bindings.lua:

o.bind("SUPER + D", "Quickdocs", "omarchy-shell shell toggle bottelet.quickdocs")

Usage

Open the overlay and type. The docset manager opens automatically the first time (nothing is installed yet) — filter, then Enter to download.

Navigation is two-step: arrows move through the results (the page auto-previews), Enter locks the entry in for reading — the same keys then scroll the page — and Enter again drops back to the results.

Key Action
↑ ↓ (or Ctrl+J/K) Move through results; scroll the page while reading
↵ Read the selected entry / return to the results
PgUp PgDn Page through results, or through the page while reading
highlight text Selecting text in the page copies it to the clipboard
name:query Scope search to one docset (js:, py:, go:…)
Ctrl+D Toggle the docset manager
Del Remove the selected docset (manager)
Esc Step back: reading → search → close (Ctrl+C closes outright)

Docsets

Docsets are stored under ~/.local/share/omarchy-quickdocs/<slug>/ — a search index plus one HTML file per page, exploded from the devdocs db.json so lookups never touch the network. Pages are sanitized at download and render time so rendered content can never trigger a network request (images are stripped — Qt's rich text engine would otherwise fetch them remotely). The manager downloads them in the background; they become searchable the moment the download finishes.

Anything devdocs serves works, even if the catalog hasn't caught up: type the slug (e.g. python~3.13) in the manager and press Enter, or use the CLI:

~/.config/omarchy/plugins/bottelet.quickdocs/scripts/docs-fetch.sh python~3.13 "Python 3.13"

Remove

omarchy plugin remove bottelet.quickdocs

Downloaded docsets stay in ~/.local/share/omarchy-quickdocs/; delete that directory to reclaim the space. Remember to remove your keybinding from ~/.config/hypr/bindings.lua.

Dependencies

curl, jq, python3 — all present on a stock Omarchy install. Contacts devdocs.io over HTTPS only while downloading a docset.

License

MIT — see LICENSE, which also documents the external tools and network services this plugin uses.