Omahub
← All plugins
I

Todo

by iamkxyz

Today’s open work on the Omarchy bar, with previous due, a Foot TUI, and a local ~/.todo.txt file.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
42526cf
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts …/omarchy-todo/SKILL.md:33

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/KOUSTAV2409/omarchy-todo.git ~/.config/omarchy/plugins/iamkxyz.todo

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
42526cf
Reviewed
1 month ago

The deterministic finding is a `git clone` instruction inside an AI skill document, not code executed by the plugin. The runtime is a local todo widget that only reads/writes ~/.todo.txt through a symlink-safe, size-capped Python helper, with no network access, persistence, or destructive commands.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/KOUSTAV2409/omarchy-todo --enable
Productivity #Hyprland #bar #quickshell

Todo

A bar widget for Omarchy. Same shell, same theme tokens, same Foot + gum TUI pattern as the rest of the desktop. Not part of Omarchy itself.

One local file: ~/.todo.txt. No daemon, no account, no network, no cloud.

<p align="center"> <img src="docs/bar.png" alt="Todo on the Omarchy bar: a week of squares and an open count" width="480"> </p> <p align="center"> <img src="docs/panel.png" alt="Todo panel: heatmap, add a line, today’s open work" width="400"> </p>

Install

Plugins run unsandboxed inside omarchy-shell. Read the source, then:

omarchy plugin add https://github.com/KOUSTAV2409/omarchy-todo.git --enable --yes
omarchy bar move iamkxyz.todo --section right
omarchy restart shell

One widget on the right is enough.

Remove

omarchy plugin remove iamkxyz.todo

Removing the plugin does not delete ~/.todo.txt.

Update

omarchy plugin update iamkxyz.todo
omarchy restart shell

Dependencies

Need Notes
Omarchy omarchy-shell, Foot, Hyprland
gum Used by the Foot TUI (already common on Omarchy)
cal Monday calendar in the TUI (util-linux)

No package installer and no remote downloads. The plugin runs only as your user inside omarchy-shell.

Privileges and data

  • Reads and writes only under $HOME (default ~/.todo.txt).
  • State I/O goes through safe_todo_io.py: regular file only, O_NOFOLLOW|O_NONBLOCK, and a 256 KiB cap (rejects FIFOs, symlinks, and oversized files).
  • Right-click launches omarchy-launch-tui with an argv list.
  • Does not edit shell.json, Hyprland config, or other user settings unless you add the optional keybind or menu yourself.

Use

  • Left-click the bar: today’s open tasks. Type a line, press Enter. Click a row to finish it. Delete removes it.
  • Previous due lists unfinished work from earlier days.
  • Later is tomorrow, a date, or an undated queue.
  • Right-click the bar icon for the Foot TUI.

Optional keybind and window

~/.config/hypr/bindings.lua:

o.bind("SUPER + SHIFT + T", "Todo", os.getenv("HOME") .. "/.config/omarchy/plugins/iamkxyz.todo/todo.sh")

~/.config/hypr/hyprland.lua:

o.window("org.omarchy.todo", { float = true, center = true, size = { 720, 520 } })

Menu rows: merge examples/omarchy-menu.jsonc into your existing omarchy-menu.jsonc. See examples/README.md.

File format

PENDING | 2026-08-26 | - | Write the letter
COMPLETED | 2026-08-25 | 2026-08-25 | Send the letter

Do not install this under /usr/share/omarchy.

License

MIT. LICENSE.