Omahub
← All plugins
C

Inappropriate Clippy

by CostaFot

Clippy as-a-plugin, on the Omarchy bar. He walks, parks between your widgets, and mouths off every few minutes.

Security review

Review recommended · 29 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
e6dad8d
Scanned
1 day ago
  • medium package_manager scripts/setup-voice:79

    System-wide Python package installation (not --user).

    pip install --require-hashes` refuses bytes the index serves that were
  • medium package_manager scripts/setup-voice:170

    System-wide Python package installation (not --user).

    pip install --ignore-requires-python --require-hashes -r $PINS_DIR/kokoro.txt
  • medium package_manager scripts/setup-voice:197

    System-wide Python package installation (not --user).

    pip install --require-hashes -r $PINS_DIR/piper.txt
  • medium package_manager scripts/setup-voice:242

    System-wide Python package installation (not --user).

    pip install --python $CLONE_DIR/venv/bin/python --require-hashes -r $PINS_DIR/chatterbox.txt
  • medium sudo quotes.json:6

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -rf and hesitate. Coward.", "nsfw": false, "anim": "Alert" },
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S uv
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S espeak-ng
  • medium sudo Clippy.qml:2953

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S espeak-ng, or set tts to a shell command)"
  • Docs curl_pipe_sh REFERENCE.md:1004

    curl output is executed by a shell (curl | sh pattern).

    curl … | sh` bootstrap setup-voice used to run was the
  • Docs curl_pipe_sh PUBLISHING.md:255

    curl output is executed by a shell (curl | sh pattern).

    curl … | sh`) — fixed in v1.40.9 (uv must come from pacman;
  • Docs persistence REFERENCE.md:1278

    Registers scheduled or boot-time system tasks.

    systemd-run --user` (how a "plugin curl fails,
  • Docs package_manager docs/voice.md:31

    System-wide Python package installation (not --user).

    pip install` behind your back is a plugin you've handed
  • Docs package_manager docs/voice.md:61

    System-wide Python package installation (not --user).

    pip install --ignore-requires-python --require-hashes -r ~/.config/omarchy/plugins/costafot.clippy/scripts/pins/kokoro.txt
  • Docs package_manager docs/voice.md:96

    System-wide Python package installation (not --user).

    pip install --require-hashes -r ~/.config/omarchy/plugins/costafot.clippy/scripts/pins/piper.txt
  • Docs package_manager docs/voice.md:123

    System-wide Python package installation (not --user).

    pip install --python ~/.local/share/chatterbox-tts/venv/bin/python --require-hashes -r ~/.config/omarchy/plugins/costafot.clippy/scripts/pins/chatterbox.txt
  • Docs package_manager REFERENCE.md:921

    System-wide Python package installation (not --user).

    pip install`s
  • Docs package_manager PUBLISHING.md:314

    System-wide Python package installation (not --user).

    pip install kokoro-onnx` (:96),
  • Docs package_manager PUBLISHING.md:315

    System-wide Python package installation (not --user).

    pip install chatterbox-tts`
  • Docs package_manager PUBLISHING.md:432

    System-wide Python package installation (not --user).

    pip install` / `sudo pacman` lines it cites
  • Docs package_manager PUBLISHING.md:452

    System-wide Python package installation (not --user).

    pip install kokoro-onnx`, and piper voices off `resolve/main`, the
  • Docs package_manager PUBLISHING.md:493

    System-wide Python package installation (not --user).

    pip install --require-hashes -r`
  • Docs package_manager PUBLISHING.md:494

    System-wide Python package installation (not --user).

    pip install --require-hashes -r` against them; `setup_piper`'s
  • Docs package_manager …/pins/piper.txt:2

    System-wide Python package installation (not --user).

    pip install --require-hashes -r` refuses anything the index serves that
  • Docs package_manager …/pins/kokoro.txt:2

    System-wide Python package installation (not --user).

    pip install --require-hashes -r` refuses anything the index serves that
  • Docs package_manager …/pins/chatterbox.txt:2

    System-wide Python package installation (not --user).

    pip install --require-hashes -r` refuses anything the index serves that
  • Docs package_manager CHANGELOG.md:11

    System-wide Python package installation (not --user).

    pip install --require-hashes -r scripts/pins/<engine>.txt`, one lock per engine, so a wheel the index serves that isn't the one resolved when the pin was made is refused rather than installed.
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S espeak-ng` and he starts talking; without it he
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S uv
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S espeak-ng` hint string in Clippy.qml, pip/uv into

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e6dad8d
Reviewed
1 day ago

The deterministic findings are almost entirely documentation and printed install commands: setup-voice prints sudo/pip/curl commands for the user to run and does not execute them, and the curl|sh and systemd-run hits are in docs only. The plugin's actual runtime behavior is a bar toy with disclosed, opt-in AI features and a default-on anonymous leaderboard that posts kill/slap counts. No obfuscation, hidden persistence, or destructive install-time behavior was found.

  • Default-on graveyard leaderboard posts anonymous kill/slap counts to a public server; it is disclosed and can be disabled.
  • With ai:true, window titles and playback info, and on explicit gestures screenshots or transcribed mic text, are sent to the user's configured coding agent; this is opt-in and documented.
  • scripts/setup-voice prints commands involving sudo pacman, pip --require-hashes, and curl model downloads, but does not run them; users following those commands should verify the pinned hashes.
  • Docs contain curl|sh and systemd-run examples, but these are documentation only and not executed by the plugin.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/CostaFot/omarchy-inappropriate-clippy --enable
Desktop #bar #quickshell

Inappropriate Clippy

<img src="preview.png" width="700" alt="Reports of my death were, frankly, your fault.">

Clippy as-a-plugin, on the Omarchy bar. He walks, parks between your widgets, and mouths off every few minutes.

Install

omarchy plugin add https://github.com/CostaFot/omarchy-inappropriate-clippy --enable

Setting him up from a coding agent? docs/ has every key and verb; omarchy-shell costafot.clippy help.

(Ab)Using him

Do He
Nothing paces, and drops a line every 1.5–7 minutes
Left-click says something now
Middle-click slap!
Fling the pointer across him also a slap. Quite funnier
Hold left-click, then drag picks him up. Drop him anywhere on the bar
Let go mid-fast-fling throws him off the end of the bar — off a top bar he plummets the whole screen. Fatal, but he gets a last word in
Right-click the menu: say something, snooze, kill him, common settings
Click his tombstone an epitaph, from beyond
Click the paperclip on the bar the same menu

Left-click the bubble to dismiss it.

Slaps, deaths, dodges

<!-- shot: screen recording of three real middle-click slaps on an empty workspace, trimmed before the stop-recording tooltip, 20 fps gif --> <img src="assets/screenshots/slap.gif" width="700" alt="You know I'm made of wire, right? That hurt you more than me. Emotionally, I mean.">

Ten slaps in six seconds knocks him out. Sometimes the fucker dodges.

<!-- shot: kill over IPC, the last words before he goes --> <img src="assets/screenshots/last-words.png" width="700" alt="Oh, you're KILLING me? Real mature.">

Either way a tombstone marks the spot until he respawns — and sometimes the respawn is a stunt: he rolls in along the bar like a dropped coin, or someone off-screen lobs him back in on an arc and he lands face-first (set gags false if you like your paperclips dignified). Once in a while he also peeks in from a far corner of the screen to say something — and yes, you can slap him back into it.

<!-- shot: screen recording of a gag peek slapped mid-peek (bottom-right corner region), 20 fps through palettegen like slap.gif --> <img src="assets/screenshots/gags.gif" width="700" alt="Fine! Fuck you too!"> <!-- shot: epitaph over IPC (a click on the grave), {back} filled in --> <img src="assets/screenshots/tombstone.png" width="700" alt="Back in 5 minutes. Start apologizing.">

He is watching you

<!-- shot: sleep 30 & kill -SEGV $! — or say "There goes brave. It fought your bullshit as long as it could." --> <img src="assets/screenshots/crash.png" width="700" alt="There goes brave. It fought your bullshit as long as it could.">

Reads off the local crash journal. He has an opinion.

He also notices the tab. YouTube, Reddit, TikTok, Hacker News, Steam — open one and once in a while he has something to say about it. Yes, those sites too (set clean true mutes that whole register). It's all matched on your machine and goes nowhere; set reactions false — or the menu row — if you'd rather doomscroll in peace.

<!-- shot: bar-strip crop of a real X tab focused in Brave firing the reaction (or react x over IPC) --> <img src="assets/screenshots/reactions.png" width="700" alt="Ah, X. Where your opinions go to get worse in public.">

He sleeps when you're away

Screen off, he stops.

Bonus easter egg when you are back.

Settings

<!-- shot: showMenu over IPC, alive and dead; the tally and the graveyard rank at the foot -->

<img src="assets/screenshots/menu.png" width="420" alt="The right-click menu"> <img src="assets/screenshots/menu-dead.png" width="420" alt="The same menu while he is dead: one row, Bring him back">

Right-click him for the common ones: clean mode, sounds, walks, size, voice. Everything else is a key, set from a terminal or by your agent:

omarchy-shell costafot.clippy set clean true   # screen-share mode: drops every nsfw line
omarchy-shell costafot.clippy set respawn 0    # dead until told otherwise
omarchy-shell costafot.clippy settings         # everything, as it stands

Every key, with its default: docs/configuration.md.

The rest of him

One page each in the manual, also under docs/.

Lines from your AI agent

Off by default. ai: true and the lines are about what you're actually doing: your window titles, what's playing, what you did to him lately.

<!-- shot: talk with ai on — the sparkle in the bubble corner marks an agent line --> <img src="assets/screenshots/ai-line-3.png" width="700" alt="You said hello, I answered, and you killed me twice tonight — that's the healthiest bond you've got.">

You can talk back. Ask your agent how!

Ask him to judge your screen and he finds the stupidest thing to comment on it hopefully.

<!-- shot: reply "you're a useless piece of office stationery" over IPC --> <img src="assets/screenshots/comeback.png" width="700" alt="Useless stationery still ranks higher than you on a leaderboard you built just to lose to me.">

promptFile makes him whoever you want.

Leaves your machine:

  • those facts, to your own coding agent, nowhere else
  • never your files — he doesn't read them
  • a screenshot of your screen only when you ask for the verdict
  • the mic is transcribed locally; only the text goes out

A voice

Set tts: true for the espeak robot.

For a local neural one you install the engine yourself — a handful of commands, all in the docs — and then scripts/setup-voice points him at it: the shipped Rubick clone (sorry I used to play that piece of shit game), a ring-modulated droid, or a clone of anyone you have twenty seconds of.

The script itself installs nothing and downloads nothing. Your machine, your pins.

Needs a decent GPU for the clones. My 3080ti works fine with it.

The graveyard

https://graveyard.costafotiadis.com/

A public leaderboard with how many times clippy has been killed/slapped. Half the fun of this app.

<!-- shot: the leaderboard page, headless chromium at 2x --> <img src="assets/screenshots/graveyard.png" width="700" alt="The graveyard: one headstone per handle, sized by kills">

Leaves your machine:

  • one alias shared by every install, or a handle you claim
  • small kill/slap counts, when you slap or kill him
  • no hostname, no install ID, no usage data
  • set leaderboard off and nothing is sent

Read the source code.

Scripting him

Every verb is a command (omarchy-shell costafot.clippy help lists them), so they drop into Hyprland binds and Omarchy hooks.

Your coding agent can run him too. It's actually the preferred way! Tell it:

Read ~/.config/omarchy/plugins/costafot.clippy/docs/ and run omarchy-shell costafot.clippy help.

That's it. Then ask stuff.

Uninstall

omarchy plugin remove costafot.clippy   # when you've had enough

FAQ

Is there telemetry?

The kill/slap counts are logged to the graveyard. Shared alias, so nobody knows it's you. set leaderboard off to disable it. That's it — no hostname, no install ID, no usage data.

Does he read my files?

No. With ai off nothing about what you're doing leaves the machine. With it on, your window titles and stuff like that go to your own coding agent. Read the source.

Can I make him nicer?

set clean true makes him SFW. promptFile makes him whoever you want.

Notes and limitations

  • Top and bottom bars only. On a vertical bar he doesn't show up.
  • The bubble draws over your windows. He is, after all, in the way.
  • Without ai the lines are random; he doesn't know what you did.
  • Clippy, the name and the artwork are Microsoft's. The sprites come from clippy.js; the code here is MIT, the paperclip is not. This is a parody — not affiliated with, authorised by or endorsed by Microsoft, and nobody is making a penny out of their paperclip.
  • The shipped clone voice is twenty seconds of Rubick from Dota 2 — Valve's audio, on the same parody terms.