Omahub
← All plugins
C

Codex Usage

by Codex Usage Contributors

Codex session and weekly usage, pace, and reset time in the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
c6a4911
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c6a4911
Reviewed
1 month ago

The plugin is a straightforward Codex usage/burn bar widget. It starts the locally installed `codex app-server --stdio` process, sends a single JSON-RPC `account/rateLimits/read` request, and parses the response; no install scripts, network exfiltration, or credential handling were observed in the reviewed files.

  • The reviewed sample of usage.py was truncated mid-file; the full fetch/refresh logic was not visible, though nothing suspicious appeared in the shown portion.
  • The plugin launches the `codex` CLI on the user's machine; it reads rate-limit data only but the complete subprocess/environment handling was not fully inspected.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/luinbytes/omarchy-codex-usage --enable
Widgets #ai

Codex Usage for Omarchy

A small Omarchy Quattro bar widget that shows remaining Codex weekly usage. Hover over it for session usage, weekly pace, reset time, and a seven-day burn chart. Right-click to refresh.

The widget asks the locally installed Codex app server for account/rateLimits/read. It does not read or print authentication tokens.

Preview

Codex usage details popup

Compact bar widget:

Codex usage bar widget

Requirements

  • Omarchy 4 with the Quattro shell
  • Codex CLI, signed in with ChatGPT
  • Python 3

No installer, background service, sudo, or additional package is required.

Install

omarchy plugin add https://github.com/luinbytes/omarchy-codex-usage.git --enable

The widget is added to the right section of the bar. Move it if preferred:

omarchy bar move community.codex-usage --section left

Use

  • Hover: open the usage card and refresh its data
  • Right-click: refresh immediately
  • The widget refreshes automatically every three minutes

[USG --] means Codex is unavailable, not signed in, or did not return a usage window. Right-click after fixing the Codex login to retry.

Configure

The helper recognizes these optional environment variables inherited by omarchy-shell:

Variable Default Purpose
CODEX_BIN codex Codex CLI executable
CODEX_QUICKSHELL_TIMEOUT 12 App-server timeout in seconds

Verify

python3 usage.py --self-test
python3 usage.py
omarchy plugin validate .
qmllint -I "$OMARCHY_PATH/shell" BarWidget.qml

The second command should print one JSON object using the current Codex login. It must not print a token.

Update and remove

omarchy plugin update community.codex-usage
omarchy plugin remove community.codex-usage

Privacy and security

Omarchy plugins run unsandboxed as the current user. This plugin starts codex app-server --stdio only while refreshing usage and requests the supported account/rateLimits/read method. Review the source before installing it.

Never add ~/.codex/auth.json, .env files, logs, screenshots containing personal information, or local shell configuration to this repository.

Attribution

The pace calculation and seven-slot burn chart are adapted from CodexBar, Copyright © 2026 Peter Steinberger, under the MIT License.

License

MIT. See LICENSE.