Omahub
← All plugins
A

Disaster Alert

by Andres Gracia

Shows nearby GDACS disaster alerts

Security review

Review recommended · 5 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
84add1e
Scanned
1 month ago
  • medium external_hosts Panel.qml:377

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsSL", "--max-time", "20", "-A", "Disaster-Alert/1.0", "https://nominatim.openstreetmap.org/search?format=jsonv2&addressdetails=1&limit=5&q=" + encodeURIComponent(query)]
  • medium external_hosts Panel.qml:411

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsSL", "--max-time", "20", "-A", "Disaster-Alert/1.0", "https://nominatim.openstreetmap.org/search?format=jsonv2&featuretype=country&polygon_geojson=1&limit=5&q=" + encodeURIComponent(query)]
  • medium external_hosts Panel.qml:436

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsSL", "--max-time", "15", "https://ipwho.is/"]
  • medium external_hosts Panel.qml:469

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsSL", "--max-time", "30", "https://www.gdacs.org/gdacsapi/api/events/geteventlist/latest"]
  • Docs external_hosts README.md:37

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/a-gracia/disaster-alert.git ~/.config/omarchy/plugins/disaster-alert

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
84add1e
Reviewed
1 month ago

The plugin fetches disaster alert data from public APIs (GDACS, ipwho.is, Nominatim) using curl, which is expected for its functionality. No malicious code, obfuscation, or destructive commands were found. The external host flags are legitimate API calls for geolocation and disaster information.

  • Uses external network services (GDACS, ipwho.is, Nominatim) which could potentially be used for tracking, but this is disclosed in the README and is inherent to the plugin's purpose.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/a-gracia/disaster-alert --enable
Widgets #bar #system

Disaster Alert

An Omarchy bar widget that shows nearby GDACS disaster alerts for earthquakes, tsunamis, floods, volcanoes, tropical cyclones, wildfires, droughts, epidemics, and other major events.

Features

  • Shows the current alert status in the Omarchy bar.
  • Displays nearby events on a map with Red and Orange markers.
  • Shows the current location on the map.
  • Detects the approximate location from the public ipwho.is service.
  • Lets you search for and monitor another city with OpenStreetMap Nominatim.
  • Sends desktop notifications for new nearby orange and red alerts.
  • Opens the GDACS report for an event from the details panel.
  • Remembers previously seen events without writing state into the plugin directory.

Disclaimer

This plugin is not an early warning system and must not be used as a replacement for official emergency alerts. Always follow instructions and information from local authorities and official emergency services.

Requirements

  • Omarchy with shell plugin support.
  • curl.
  • notify-send for desktop notifications.
  • An internet connection for location, map boundary, and GDACS data.

Installation

Install it as a local Omarchy plugin:

mkdir -p ~/.config/omarchy/plugins
git clone https://github.com/a-gracia/disaster-alert.git ~/.config/omarchy/plugins/disaster-alert
omarchy plugin enable disaster-alert

The plugin can also be installed from a Git repository using Omarchy's plugin manager:

omarchy plugin add https://github.com/a-gracia/disaster-alert.git --enable

Publishing Checklist

  1. Create a public repository named disaster-alert under a-gracia.
  2. Upload the contents of this directory to the repository root.
  3. Confirm that manifest.json, README.md, and LICENSE are present at the repository root.
  4. Commit and push the changes to GitHub.
  5. Submit https://github.com/a-gracia/disaster-alert through the Omarchy plugin submission form with a category and tags.

Removal

Disable the plugin before removing it:

omarchy plugin disable disaster-alert
omarchy plugin remove disaster-alert --yes

If it was installed with git clone, remove the plugin directory after disabling it:

rm -rf ~/.config/omarchy/plugins/disaster-alert

The optional local snapshot can be removed separately:

rm -f ~/.local/state/omarchy/disaster-alert.json

Configuration

The refresh interval can be changed in the Omarchy plugin settings. The manifest defaults to 600 seconds and accepts values from 60 to 3600 seconds.

To move the widget in the bar:

omarchy bar move disaster-alert --section right

The popup is anchored to the widget instead of being centered on the bar.

Data Sources

The plugin stores only a list of previously seen event keys at:

~/.local/state/omarchy/disaster-alert.json

No location or event history is stored by the plugin.

Files

  • manifest.json - Omarchy plugin metadata and settings schema.
  • BarWidget.qml - Bar button and popup loader.
  • Panel.qml - Location, map, event list, notifications, and controls.