Omahub
← All plugins
S

SpaceX TV

by sighmon

Watch SpaceX broadcasts and Starship films from the Omarchy bar, with a next-launch countdown.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
b7d3ed7
Scanned
1 week ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
b7d3ed7
Reviewed
1 week ago

The plugin is a well-structured bar widget that fetches SpaceX data from the author's server and plays media via mpv. The code is transparent, with a notably hardened cache helper (dir_fd, O_NOFOLLOW, ownership checks) and bounded downloads. No malicious or destructive behavior was found; the only residual risk is the inherent trust placed in the remote cache and the external players it invokes.

  • Remote cache URL is hardcoded to the author's domain; a compromised server could supply malicious media URLs, though the plugin does not validate URL schemes before passing them to mpv/yt-dlp or xdg-open.
  • The plugin invokes external executables (curl, python3, mpv, xdg-open, swayimg/imv) based on remote data, which is a typical but non-zero attack surface.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/sighmon/omarchy-spacex-tv --enable
Widgets #media

Omarchy SpaceX TV

An Omarchy bar widget for watching SpaceX broadcasts and Starship films.

<img src="preview.png" width="100%" />

It loads the hosted SpaceX TV cache (no X API Bearer Token required), shows poster cards for X broadcasts, photo galleries, mixed-media posts, Starship films, talks, and flight tests, and displays a next-launch countdown from the same SpaceX feeds used by spacex.com/launches. Selecting a video plays its HLS or MP4 stream in mpv; galleries and mixed posts open inside the panel. Click the large gallery image to open it fullscreen in swayimg or imv, with the system URL handler as a fallback.

Playback automatically retries the alternate HLS/MP4 format and finally the original X or YouTube page. mpv uses yt-dlp for that last play-time resolution step, so installing yt-dlp is recommended for live X and YouTube fallback playback.

The plugin runs inside the long-lived omarchy-shell process. It does not start a second Quickshell process.

Install

omarchy plugin add https://github.com/sighmon/omarchy-spacex-tv.git --enable

Or copy this folder to ~/.config/omarchy/plugins/com.sighmon.spacex-tv/ and run omarchy-shell shell rescanPlugins.

Usage

Click the bar countdown (or SpaceX TV) to open the poster panel. Click a card to play it in mpv. Press Escape to close the panel.

After copying files onto a running desktop, restart the shell. omarchy-shell keeps compiled QML in memory, so rsync and omarchy-shell shell rescanPlugins leave the previous panel running:

omarchy-restart-shell

Configure

omarchy bar move com.sighmon.spacex-tv --section center
omarchy bar set com.sighmon.spacex-tv showCountdown false --json
omarchy bar set com.sighmon.spacex-tv showNextLaunchCountdown false --json
omarchy bar set com.sighmon.spacex-tv showCardFilters false --json
omarchy bar set com.sighmon.spacex-tv prefersMP4Playback true --json
omarchy bar set com.sighmon.spacex-tv useLocalCache false --json

showCountdown controls the bar label. The other preferences control the panel countdown, filter chips, HLS/MP4 priority, and fallback to the last successful hosted-cache response. They can also be toggled from the panel.

Cache downloads require python3 and curl. Cache directories must be owned by the current user, with no symlink components or group/other-writable ancestors (root-owned sticky ancestors such as /tmp are allowed). JSON and image caches use exclusive random staging files and descriptor-relative publication; cached JSON reads and fullscreen image viewing also avoid following cache path symlinks.

Playback uses mpv. Install it if it is not already on the system (xdg-open is not used unless you change Play.js). Install yt-dlp as well to resolve X or YouTube webpage fallbacks at play time.

Remove

omarchy plugin remove com.sighmon.spacex-tv

Discovery

Default discovery is https://www.sighmon.com/spacex-tv/x-cache.json (processed_cards, pinned/timeline posts, and starship_* playlist snapshots). Next launch comes from:

  • https://content.spacex.com/api/spacex-website/launches-page-tiles/upcoming
  • https://sxcontent9668.azureedge.us/cms-assets/future_missions.json

When present, the cache's starship_launch_tiles and starship_missions snapshots add upcoming Starship holding cards and their X or YouTube webcasts. The last successful cache response is stored under the user's XDG cache directory for offline startup.

Logs

Plugin console.log lines are prefixed [SpaceX TV] and go to the Omarchy shell log:

qs log -p "$OMARCHY_PATH/shell" --tail 100

If qs is not on your PATH:

journalctl --user -f | grep -i "SpaceX TV"

Tests

node --test tests/test_spacex_tv.js
python3 -B -m unittest discover -s tests -p 'test_cache_io.py'

Links