Omahub
← All plugins
J

Which Key

by Jason Lee <huacnlee@gmail.com>

A LazyVim which-key-style shortcut guide that automatically reads Omarchy live keybindings and appears when you hold Super

Security review

Potentially dangerous behavior detected · 2 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
fba0cdb
Scanned
2 weeks ago
  • high destructive_filesystem tests/test_settings_script.sh:101

    Destructive operation on the root filesystem or a block device.

    rm -rf /" 2>/dev/null; then
  • medium external_hosts tests/test_source.sh:113

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/huacnlee/omarchy-which-key.git' README.md; then

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
fba0cdb
Reviewed
2 weeks ago

The plugin is a which-key overlay that reads live Hyprland bindings and shows a shortcut guide. The deterministic scan's high-risk findings are in test scripts (tests/test_settings_script.sh and tests/test_source.sh) that intentionally exercise rejection of destructive input and README checks; they are not part of the runtime code. The plugin's installer modifies the user's Hyprland config and creates a symlink, but does so reversibly with clear markers and no destructive or hidden behavior.

  • The installer modifies ~/.config/hypr/bindings.lua and creates ~/.local/bin/which-key-trigger, but this is documented, reversible, and guarded against symlink attacks.
  • The deterministic scan flagged destructive commands in test files, but these are test assertions, not executed during normal plugin use.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/huacnlee/omarchy-which-key --enable
Productivity #Hyprland #quickshell

Omarchy Which Key

Omarchy Which Key brings LazyVim's which-key experience to the desktop. It automatically reads the active Omarchy and Hyprland keybindings and shows a compact guide at the bottom right of the focused display when you hold Super.

<img width="250" alt="Omarchy Which-Key" src="preview.png" />

Requirements

Omarchy 4 with its Quickshell desktop and Hyprland Lua configuration support.

Install

Add and enable the plugin with Omarchy:

omarchy plugin add https://github.com/huacnlee/omarchy-which-key.git --enable

Open the Which Key bar widget settings and turn on Enabled. The plugin configures its keyboard integration automatically.

How it works

The plugin reads Hyprland's active keyboard model, layout, variant, and XKB options, so remaps such as altwin:swap_alt_win still trigger the logical Super modifier. It observes modifier state without registering a new shortcut. The overlay then runs hyprctl binds each time Super is held and filters those live results for the active modifier combination. It contains no built-in shortcut information, so reloaded system changes appear on next use. The full-screen layer has an empty input region and requests no keyboard focus.

Usage

Press and hold Super — the Command (⌘) key on an Apple keyboard or the Windows (⊞) key on a PC keyboard — to show the shortcut guide. Keep holding Super and add Shift, Ctrl, or Alt to see shortcuts for that exact key combination. Release Super to close the guide.

Running a shortcut leaves the guide open, so one held Super can drive several shortcuts in a row. Only releasing Super closes it.

By default, the guide appears after Super is held for 200 ms, so a quick tap does not open it. You can change this delay and choose which modifier combinations are shown from the Which Key bar widget settings. The guide shows up to twenty shortcuts at a time.

Uninstall

Turn off Enabled in the Which Key bar widget settings, then remove the plugin with Omarchy:

omarchy plugin remove huacnlee.which-key

Disabling removes the plugin's keyboard integration. Other bindings and files are left untouched.

Troubleshooting

If nothing appears, check hyprctl configerrors and confirm the plugin is enabled with:

omarchy plugin list --json | jq '.[] | select(.id == "huacnlee.which-key")'

Bindings without a Hyprland description are intentionally omitted. If the keyboard layout or XKB options change, turn Enabled off and on again in the Which Key settings.

More Omarchy projects

  • Omamail — A mail plugin for Omarchy with Gmail, HEY, and IMAP support. Read and manage email right from the desktop.
  • Omasend — A native LocalSend client for Omarchy. Share files, folders, and text over your local network. Built with GPUI Kit for Linux, macOS, and Windows.
  • omarchy-mihoro — An Omarchy bar panel for Mihoro. Monitor your proxy, switch between Rule, Global, and Direct modes, and manage subscriptions.