Omahub
← All plugins
B

Bralyx Reminders

by Bralyx

Reminders in your Omarchy bar — set a time, get a desktop notification, then snooze, edit, or delete from the pill. Fully local (systemd user timers), no account and no network.

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
be10a66
Scanned
1 month ago
  • high persistence bin/reminderctl:254

    Registers scheduled or boot-time system tasks.

    systemd-run --user --quiet --collect --on-active="${minutes}m" --unit="$unit" \
  • Docs persistence README.md:27

    Registers scheduled or boot-time system tasks.

    systemd-run`)
  • Docs sudo README.md:74

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required. No extra packages, no network.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
be10a66
Reviewed
1 month ago

The plugin manages reminders via systemd user timers and a helper script. The deterministic scan flagged systemd-run and sudo usage, but the actual code uses systemd-run only for user-level timers (intended functionality) and explicitly avoids sudo/pkexec. The install script safely copies a binary to ~/.local/bin with symlink checks. No malicious behavior or hidden persistence beyond the expected reminder scheduling.

  • The scan flagged systemd-run as persistence, but it is used for user-level reminder timers, which is the plugin's purpose.
  • The scan mentioned sudo/pkexec in the README, but the README states no sudo is required and the code does not use it.
  • The install script writes to ~/.local/bin, which is a standard user bin directory and is safe.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/GimpyHand/bralyx-reminders --enable
Productivity #bar #quickshell

Bralyx Reminders

Reminders in your Omarchy bar — set a time, get a desktop notification, then snooze, edit, or delete from the pill. Fully local (systemd user timers), no account and no network.

A bar pill and popup for the Omarchy Quattro shell. Plugin id: bralyx.reminders. Disable the built-in omarchy.reminders overlay while this is enabled so you do not get two reminder UIs:

omarchy plugin disable omarchy.reminders

Install

omarchy plugin add https://github.com/GimpyHand/bralyx-reminders.git --enable
~/.config/omarchy/plugins/bralyx.reminders/install.sh
omarchy bar move bralyx.reminders --section right

install.sh copies bin/reminderctl to ~/.local/bin/reminderctl and chmod +x. Re-running it is safe. The pill and popup call reminderctl from PATH, so ~/.local/bin must be on your PATH (it is on a default Omarchy user session).

omarchy plugin add is what enables the plugin. install.sh only installs the helper binary. It does not edit shell.json.

Dependencies

Stock Omarchy already provides these:

  • systemd user session (systemctl --user, systemd-run)
  • jq (JSON output from reminderctl list)
  • omarchy-notification-send and omarchy-shell (fired reminders open the manager popup)

No sudo, pkexec, extra packages, or network access.

Usage

Click the bell pill to open the manager from the bar. Right-click the pill to refresh the count. Click a fired notification to open the same popup.

Each reminder has snooze chips (5m / 15m / 30m / 1h), Edit, and Delete. New reminders: type a message, then click a duration chip or enter 15m / 2h / 1d / 1w / HH:MM and Add. Edit uses Days / Hours / Minutes fields.

Keyboard:

  • ↑ ↓ — select
  • Enter — snooze 5 minutes
  • E — edit
  • Del or X — delete
  • N — new reminder
  • Esc — close
reminderctl list
printf '%s' "Check the oven" | reminderctl set 15
reminderctl cancel <unit>
reminderctl snooze <unit> 10
printf '%s' "new message" | reminderctl edit <unit> 20

set / edit take the reminder message from stdin (max 500 bytes), never argv, so private text is not exposed in /proc/<pid>/cmdline.

Configure

omarchy bar move bralyx.reminders --section right

Remove

omarchy plugin remove bralyx.reminders
rm -f ~/.local/bin/reminderctl

omarchy plugin remove deletes the plugin folder. It does not remove ~/.local/bin/reminderctl or already-armed systemd user timers. Cancel leftovers with reminderctl list / reminderctl cancel before deleting the helper.

reminderctl

bin/reminderctl is required. It owns create / cancel / snooze / edit / list / fire against one-shot systemd user timers named omarchy-reminder-<minutes>m-<unix>.timer and sibling .message files in $XDG_RUNTIME_DIR/omarchy-reminders/. No sudo or pkexec is required. No extra packages, no network.

The omarchy-reminder-* timer prefix matches the built-in Omarchy reminder engine so existing timers keep working.