Omahub
← All plugins
J

Password Store

by Jonny Heggheim

pass, the standard unix password manager, as an Omarchy launcher: press a key, type to search your store, then copy or type a password, username or OTP code. Decryption and clipboard clearing are left to pass itself.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
1e166ef
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
1e166ef
Reviewed
1 month ago

The plugin is a well-structured password manager launcher that delegates all decryption and clipboard operations to the standard `pass` tool, with no obfuscation or hidden behavior. The deterministic scan found no issues, and manual review confirms the code is transparent and safe, with only minor considerations around the use of external tools and the handling of secrets.

  • The plugin relies on external tools (`pass`, `wl-clipboard`, `wtype`, `jq`) which must be installed; if missing, actions fail gracefully with notifications.
  • The `type-password` action uses `wtype` to type the password into the focused window, which could be a security concern if the user is not aware of the focus, but this is clearly documented and user-controlled via the `allowTyping` setting.
  • The recent list is stored in plaintext at `~/.local/state/omarchy-passwordstore/recent`, which could leak entry names, but this is documented and outside the store.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/hegjon/omarchy-passwordstore --enable
System #security

Password Store for Omarchy

pass, the standard unix password manager, in the Omarchy bar.

Bar button and popup

  • A key on the bar. Click it (or omarchy-shell shell toggle hegjon.passwordstore from a keybinding) and type to search your store; ghb finds web/github.com.
  • Enter copies the password, Alt+U the username, Alt+O a fresh OTP code (with pass-otp). Ctrl+Enter types the password into the window you came from, Ctrl+Shift+Enter the username. Alt+E opens the entry in a terminal with pass edit.
  • Recently used entries float to the top of an empty search.
  • Nothing is decrypted by the widget. Every action is handed to pass itself, so gpg-agent prompts as it would from a terminal and the clipboard is cleared after 45 s exactly as pass -c does.

Install

omarchy plugin add https://github.com/hegjon/omarchy-passwordstore.git --enable
omarchy restart shell

If the bar widget is enabled but not visible, place it explicitly:

omarchy plugin enable hegjon.passwordstore --section right
omarchy restart shell

Update or remove:

omarchy plugin update hegjon.passwordstore --yes
omarchy plugin remove hegjon.passwordstore

Removing the plugin leaves your password store untouched (it is only ever read through pass). If you want no trace left, also delete the recently-used list, ~/.local/state/omarchy-passwordstore/, and any keybinding you added below.

Needs pass (omarchy pkg add pass), wl-clipboard and jq (both part of Omarchy), and wtype for the typing actions. pass-otp is optional; the OTP action only appears when it is installed.

A keybinding is the natural way to reach it. In ~/.config/hypr/bindings.lua (SUPER+P is Omarchy's pseudo-window toggle by default, hence the unbind):

hl.unbind("SUPER + P")
o.bind("SUPER + P", "Password store", "omarchy-shell shell toggle hegjon.passwordstore")

The bar widget is still needed even if you only ever use the keybinding: its bar entry is where the settings live.

Keys

Key Action
any printable Extend the search. Backspace, Ctrl+Backspace, Ctrl+U edit it
↑ ↓ Ctrl+J/K/N/P Move the cursor; PageUp/Down, Home, End jump
Enter Copy the password (pass show -c)
Alt+U / Alt+Enter Copy the username
Alt+O Copy an OTP code (pass otp -c)
Ctrl+Enter Type the password into the focused window
Ctrl+Shift+Enter Type the username
Alt+E pass edit in a terminal
F5 Re-read the store (it is also re-read every time it opens)
Esc Clear the search, then close
mouse Left click copies the password, right click the username, middle click an OTP

The username is the value of the first login: / user: / username: / email: line of the entry (configurable), or failing that the bare second line, which is where pass's conventions put it.

Settings

Change them from the bar's widget settings, or with omarchy bar set:

omarchy bar set hegjon.passwordstore storeDir ~/.password-store-work
omarchy bar set hegjon.passwordstore clipTimeSec 30
omarchy bar set hegjon.passwordstore allowTyping false --json
Key Default Meaning
storeDir (empty) Store location. Empty means $PASSWORD_STORE_DIR or ~/.password-store, as pass does.
clipTimeSec 45 Seconds until the clipboard is cleared (PASSWORD_STORE_CLIP_TIME).
usernameKeys login,user,username,email Field names that hold the username, matched case-insensitively.
allowTyping true Enable Ctrl+Enter / Ctrl+Shift+Enter (needs wtype).
notifyOnCopy true Notify when something was copied, naming the entry and its username. Failures are always notified.

How it works

The plugin has two parts: an overlay (PasswordstoreOverlay.qml, the card, summoned with omarchy-shell shell toggle hegjon.passwordstore) and a bar-widget (PasswordstoreWidget.qml, the key on the bar, which also holds the settings). Two small scripts do the work, and both can be run by hand:

  • passwordstore-list [--store DIR] [--recent FILE] prints the names of the *.gpg files in the store as JSON. It never decrypts anything.
  • passwordstore-action <action> <entry> [...] runs one action: copy-password, copy-username, copy-otp, type-password, type-username or edit. Secrets travel over pipes, never argv, and the popup has already closed when it runs, so a typed password lands in the window you were in.

Recently used names are kept in $XDG_STATE_HOME/omarchy-passwordstore/recent (~/.local/state/…), outside the store so they are never committed with it.

Development

test/lint runs qmllint, test/test-manifest checks the manifest, test/test-list and test/test-action exercise the scripts against a throwaway store and stand-in pass/wl-copy/wtype, so no gpg key is needed.

License

MIT