Omahub
← All plugins
D

Daily Hanzi

by danglenoir

Learn a new Chinese character every day from the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
d1ff8cf
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d1ff8cf
Reviewed
1 month ago

The deterministic scan found no issues, and my review agrees there is no malicious or dangerous code. This is a well-hardened dictionary widget: network fetches are restricted to en.wiktionary.org over HTTPS with response-size limits, all remote text is sanitized before display, external URLs must match the https://www.mdbg.net/ prefix, and the only shell invocation pipe-writes a single shell-quoted CJK character to wl-copy. No persistence, credential access, destructive commands, or obfuscation were found; the residual risk is limited to the inherent surface of any widget that spawns a bundled Node.js script and fetches remote content.

  • The widget executes the bundled Hanzi.js via `node` from the plugin directory; a tampered plugin update would run arbitrary code in the user session, so the plugin directory should remain trusted/read-only (standard supply-chain consideration for all plugins).
  • The clipboard copy uses `bash -c` with Util.shellQuote on a value guaranteed to be a single CJK character from the allowlisted HSK pool, so command injection is not feasible as written.
  • Renders content fetched from en.wiktionary.org; input is sanitized (tags/control chars stripped, length capped) on both the Node and QML sides, and the response is size-limited, so malformed remote data is handled safely.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/danglenoir/omarchy-hanzi --enable
Other #bar

Omarchy Daily Hanzi

An Omarchy Shell bar widget that teaches one Chinese character a day.

The bar shows 汉字. Hover for today's character, pinyin, and meaning. Click the widget for components, example words, and a dictionary link. The refresh button (or a middle-click) gives you a different character for today.

Requirements

  • Omarchy 4.0 or newer with the Quickshell-based Omarchy Shell
  • Node.js (v18 or newer)
  • Internet access to en.wiktionary.org

Character data comes from the English Wiktionary Action API (CC BY-SA 4.0). There is no bundled dictionary.

Install

Install and enable the plugin through Omarchy:

omarchy plugin add https://github.com/danglenoir/omarchy-hanzi.git --enable

The widget is added to the right section of the bar. Move it when needed:

omarchy bar move danglenoir.hanzi --section right

Local development install

Omarchy rejects plugin folders that contain symlinks, so copy the checkout into the user plugin directory:

mkdir -p ~/.config/omarchy/plugins
rsync -a --delete --exclude .git "$PWD/" ~/.config/omarchy/plugins/danglenoir.hanzi/
omarchy-shell shell rescanPlugins
omarchy plugin enable danglenoir.hanzi

Use

  • Hover the bar mark to see today's hanzi, pinyin, and meaning.
  • Click to open the panel.
  • Refresh (󰑐, middle-click, or R in the panel) to study a different character today. Tomorrow returns to the hashed daily pick.
  • Copy (󰆏 or C) puts the character on the clipboard.
  • Look up on MDBG opens the CC-CEDICT entry in your browser.

To inspect the adapter directly:

node ~/.config/omarchy/plugins/danglenoir.hanzi/Hanzi.js --pretty
node ~/.config/omarchy/plugins/danglenoir.hanzi/Hanzi.js --shuffle --pretty
node ~/.config/omarchy/plugins/danglenoir.hanzi/Hanzi.js --character 学 --pretty

Useful Omarchy checks:

omarchy plugin validate ~/.config/omarchy/plugins/danglenoir.hanzi
omarchy plugin list --json
omarchy-shell shell rescanPlugins

Today's snapshot is cached in ~/.cache/omarchy-hanzi/. If Wiktionary is temporarily unreachable, the panel keeps the last successful card and marks it as cached.

Update

omarchy plugin update danglenoir.hanzi

Uninstall

omarchy plugin remove danglenoir.hanzi

Optionally remove the cache:

rm -rf ~/.cache/omarchy-hanzi

For a local development symlink, disable the widget first, then remove the link:

omarchy plugin disable danglenoir.hanzi
rm ~/.config/omarchy/plugins/danglenoir.hanzi
omarchy-shell shell rescanPlugins

License

MIT