Omahub
← All plugins
K

Hark

by Konrad Kruk

A Wayland AI command palette for Omarchy and Hyprland.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
75b56a3
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
75b56a3
Reviewed
1 month ago

The plugin is a well-structured AI command palette that communicates with a local daemon via harkctl. The code shows good security practices, such as passing API keys via stdin, sanitizing URLs before opening externally, and avoiding exposure of daemon stderr. The deterministic scan found no issues, and my review confirms no obvious malicious or destructive behavior.

  • The plugin spawns a bundled daemon (harkd) and communicates with it via a Unix socket; the daemon binary is not reviewed here, so its behavior is a potential risk, though it appears to be a legitimate AI assistant backend.
  • The plugin stores API keys in the system keyring via harkctl; while this is a standard practice, the security of the keyring integration depends on the daemon's implementation.
  • The plugin can capture screenshots and send them to AI providers; this is a privacy consideration, but it is a core feature and requires user action to trigger.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/konradk/hark-plugin --enable
Productivity #quickshell #ai
<!-- Generated by scripts/publish-plugin-repo.sh. Do not edit this repository by hand; changes belong in https://github.com/konradk/hark and are republished on the next release. -->

Hark (Omarchy plugin)

Packaged Omarchy plugin build of Hark, released as v0.1.8 from commit 3f0cad03f904c2048a6411f82abe9bb69e4c5870.

omarchy plugin add https://github.com/konradk/hark-plugin.git --enable
omarchy-shell shell summon hark

Update with omarchy plugin update hark.

Source, documentation, issues, and security reporting all live in the main repository.

License

MIT.