Omahub
← All plugins
H

2FA Codes

by hamzahasann

Search pass-otp entries and copy one-time codes

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
a412f62
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a412f62
Reviewed
1 month ago

The plugin is a straightforward Quickshell overlay for pass-otp. It reads 2FA entries, copies codes via `pass otp --clip`, and adds/removes a menu entry in the user's Omarchy config. The code is transparent, uses standard commands, and includes path traversal protections. No malicious behavior or hidden functionality was found.

  • The setup-menu script modifies the user's Omarchy menu configuration file, which is expected but should be reviewed for unintended changes.
  • The plugin handles sensitive 2FA data, but it relies on the standard pass-otp tool and does not expose secrets beyond the intended clipboard copy.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/hamzahasann/omarchy-totp --enable
Productivity #quickshell #launcher #security

Omarchy TOTP

A native Quickshell overlay for searching pass-otp entries and copying time-based one-time passwords on Omarchy.

The plugin reads entries under ~/.password-store/2fa, uses GPG/Pinentry for unlocking, and delegates clipboard handling to pass-otp. Copied codes are cleared automatically after 45 seconds.

Install

Install the system dependencies:

omarchy pkg add pass pass-otp oath-toolkit

Set up a GPG key and password store if you do not already have one:

gpg --full-generate-key
gpg --list-secret-keys --keyid-format=long
pass init YOUR_GPG_KEY_ID

Install and enable the plugin:

omarchy plugin add https://github.com/hamzahasann/omarchy-totp.git --enable
~/.config/omarchy/plugins/hamzahasann.totp/scripts/setup-menu
omarchy menu refresh

Press Super + Space, open Trigger, select 2FA Codes, type to search, and press Enter to copy the selected code.

Add an account

Paste an otpauth:// URL supplied by the service:

pass otp insert "2fa/GitHub"

Remove

Remove the menu entry before uninstalling the plugin:

~/.config/omarchy/plugins/hamzahasann.totp/scripts/remove-menu
omarchy menu refresh
omarchy plugin remove hamzahasann.totp

Your encrypted pass entries are deliberately retained in ~/.password-store/2fa. Remove them separately with pass rm only when you no longer need those accounts.

License

MIT