Omahub
← All plugins
B

exe.dev VMs

by Brian Scott

See and manage your exe.dev VMs from the Omarchy bar: SSH in, open web endpoints, restart VMs, and jump to your account settings in the browser.

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
7e50628
Scanned
1 month ago
  • high destructive_filesystem tests/model.test.js:115

    Destructive operation on the root filesystem or a block device.

    rm -rf /"), "")

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
7e50628
Reviewed
1 month ago

The deterministic scan flagged a literal `rm -rf /` string in tests/model.test.js, but that is a test case verifying that unsafe VM names are rejected, not executed code. The plugin itself is a defensive QML widget that validates all remote SSH inputs, restricts URLs to exe.dev infrastructure, and requires confirmation for destructive actions. No actual dangerous behavior was found.

  • The flagged `rm -rf /` appears only in a unit test string, not in any executable path.
  • The plugin runs SSH commands to a remote management endpoint, but uses BatchMode, timeouts, and output caps; this is the intended functionality.
  • All VM names, URLs, and SSH destinations are validated and sanitized before use, and destructive actions (restart/delete) require explicit confirmation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/bscott/exedev-oma-plugin --enable
Widgets #bar #quickshell #system

exe.dev VMs — Omarchy bar plugin

An Omarchy shell (Quickshell) bar widget for exe.dev virtual machines. A server icon in the bar shows how many VMs are running; the popout lists every VM on the account with one-click actions.

Popout preview

Features

  • VM list — emoji, name, status, region, and tags for every VM, running VMs first, refreshed over SSH (ssh exe.dev "ls --json").
  • SSH in a terminal — opens your default Omarchy terminal already connected to the VM (row button, or s on the selected row).
  • Per-VM action menu — open the VM's https://<vm>.exe.xyz endpoint, its web terminal, its Shelley agent, or the VM in VS Code or Zed (when a Zed CLI is installed); copy the ssh command; restart or delete the VM — both behind a confirmation dialog.
  • New VM — the + button in the popout header runs ssh exe.dev "new --json --no-email" and refreshes the list.
  • Account settings in the browser — the cog in the popout header (or right-click on the bar icon) asks exe.dev for a one-shot magic login link (ssh exe.dev "browser --json") and opens it in your browser.
  • Full keyboard navigation, matching the first-party Omarchy panels.

Requirements

  • Omarchy with the Quickshell-based shell (omarchy-shell).
  • An exe.dev account with this machine's SSH key enrolled — ssh exe.dev ls must work non-interactively.

No other external dependencies: the plugin only shells out to ssh, wl-copy, and standard omarchy-launch-* helpers already present on Omarchy. The "Open in Zed" action appears only if a Zed CLI (zeditor or zed) is installed. Licensed under the MIT License.

Install

omarchy plugin add https://github.com/bscott/exedev-oma-plugin.git --enable

Then place the widget on the bar (or add {"id": "bscott.exedev"} to the bar layout in ~/.config/omarchy/shell.json):

omarchy bar put bscott.exedev --section right

For development, clone anywhere and symlink into ~/.config/omarchy/plugins/bscott.exedev instead; the shell hot-reloads plugin code on save (force with omarchy-shell shell rescanPlugins).

Uninstall

omarchy plugin remove bscott.exedev

This removes the plugin and its bar entry. The plugin never modifies any other configuration.

Bar icon

  • Left click — toggle the popout.
  • Middle click — refresh the VM list now.
  • Right click — open account settings in the browser.

The icon dims when exe.dev is unreachable; a small count shows running VMs.

Keyboard (popout open)

Key Action
j / k / arrows Move the cursor (h/l switch header buttons)
Enter Header: activate the focused button · VM row: open the action menu
s SSH into the selected VM in a terminal
o Open the selected VM's https endpoint
c Copy the selected VM's ssh command
n Create a new VM
d / x Delete the selected VM (with confirmation)
r Refresh
a Open account settings
Esc Close

Settings

Configured inline in ~/.config/omarchy/shell.json on the widget entry:

Key Default Meaning
refreshIntervalSec 120 Seconds between VM list refreshes (15–3600)
host exe.dev SSH destination for the management endpoint

IPC

omarchy-shell bscott.exedev toggle    # open/close the popout
omarchy-shell bscott.exedev refresh   # refresh the VM list
omarchy-shell bscott.exedev settings  # open account settings in the browser
omarchy-shell bscott.exedev status    # "3/8 running"

Tests

Model.js (parsing/formatting) is pure and runs under Node:

node tests/model.test.js