Omahub
← All plugins
C

Twingate

by crbelaus

Twingate VPN status, connection toggle, resources, and account login/logout

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
2ee72a6
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2ee72a6
Reviewed
1 month ago

The plugin is a straightforward Twingate status widget that invokes the official twingate CLI with bounded output and safe argument passing. No obfuscation, persistence, credential theft, or destructive commands were found. The use of pkexec for connect/disconnect is user-triggered and expected for VPN control.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/crbelaus/omarchy-twingate --enable
System #system #security

Twingate for Omarchy

Shows whether the Twingate VPN is connected from the Omarchy bar. Click the icon to open a panel with connection status, authorized resources, and account login/logout — similar to the built-in Tailscale widget.

Omarchy's Twingate pangel

Install

omarchy plugin add https://github.com/crbelaus/omarchy-twingate --enable

Requires the Twingate Linux client to be installed via the twingate AUR package.

Use

  • The lock icon fills in when Twingate is connected.
  • Click the icon to open the panel.
  • The switch in the panel header connects or disconnects Twingate.
  • Right-click the bar icon to toggle without opening the panel.
  • The ACCOUNT section shows your logged-in account (email and network) with a log-out button, and an Add account row to log in — it opens your browser to finish authentication after you type your network name.
  • The RESOURCES section lists your authorized resources while connected, with a button to copy each address to the clipboard.

Keyboard shortcuts

Inside the panel:

  • j / k or arrows: move cursor
  • enter / space: activate current row (toggle, log out, copy address)
  • t: toggle Twingate
  • r: refresh status
  • l: open the login prompt
  • esc: close (or cancel the login prompt)

Settings

Key Description Default
refreshIntervalSec How often to poll twingate status, resources, and account info, in seconds 15

Troubleshooting

  • Icon shows "Not installed" — the twingate binary isn't on PATH for the shell the bar runs in. Confirm which twingate works.
  • Connect/disconnect fails — confirm twingate connect / twingate disconnect work from a terminal. The widget just runs those commands directly and surfaces whatever error they return.
  • Icon stays on "Checking…" or seems stuck — twingate status can hang while the daemon socket is flapping; the widget kills a stuck status check after 10s and retries on the next poll.
  • Resources list is empty — resources only load while connected, and the panel only requests the default (non-hidden) list; a hint in the section header shows how many background resources are hidden.

Security

The plugin runs twingate status, twingate resources, and twingate account list as your own user. Connecting and disconnecting run twingate connect / twingate disconnect via pkexec, matching what the CLI itself requires. Logging in runs twingate account add (which opens your browser for authentication); logging out runs twingate account logout for the selected account. None of this reads, stores, or transmits your Twingate credentials — all authentication is handled by the Twingate client itself.

Every one of those commands is spawned behind head -c 65536, so the shell can never read more than 64 KiB back from any single invocation: once the limit is hit head exits, the pipe closes, and the producer takes SIGPIPE. The cap is enforced by the kernel pipe before any of the shell's own buffers see the data, so a malfunctioning or compromised twingate binary cannot grow the shell's memory by streaming output at it. Command arguments are passed as bash positional parameters ("$@") rather than interpolated into a shell string, so values that came out of the CLI — account emails, network names — are never re-parsed as shell syntax.