Free AI Models
Omarchy bar widget tracking every currently-free AI model from the ClawLabsAI/free-ai-models daily tracker.
The bar shows a robot pill with the live count. Clicking it opens a panel
listing each model with provider, context window, modalities, and rate limit.
Data is fetched once by a shared service singleton, cached to
~/.local/state/omarchy/free-ai-models-cache.json, and refreshed every 6
hours (the upstream tracker updates daily).

Install
omarchy plugin add https://github.com/ArgusGuardian/omarchy-freemodels.git --enable
Or drop this folder into ~/.config/omarchy/plugins/ and run:
omarchy-shell shell rescanPlugins
omarchy bar move io.github.argusguardian.freemodels --section center
Usage
- Left-click the pill: open/close the model list panel
- Middle-click: force a data refresh
- Right-click: notification with today's top-ranked free model
- In the panel: left-click a row opens the provider page,
right-click copies the model id (e.g. for use in API calls),
Ror the Refresh button refetches
IPC
omarchy-shell io.github.argusguardian.freemodels status # JSON status
omarchy-shell io.github.argusguardian.freemodels refresh # force refresh
Dependencies
curl(fetch),wl-copy(copy model id),xdg-open(links) — all present on a stock Omarchy install. No API keys; only public endpoints.
Security notes
- Network responses are hard-capped at 256 KB (
curl --max-filesizeplus ahead -ctruncation withpipefail), so the long-lived shell never buffers more than the cap; HTTPS-only via--proto =https. - The cache file at
~/.local/state/omarchy/free-ai-models-cache.jsonis read through a guard: regular file only (symlinks/FIFOs rejected), owner must match the effective uid, size capped at 256 KB, re-verified on the open descriptor (/proc/self/fd) to close the stat/open race, and the whole read runs undertimeout 2so it can never stall the shell. - The
FileViewhandle used for cache writes is declaredpreload: false. Quickshell preloads its target path by default, which would read the predictable cache file into the long-lived shell outside the guard, so it is kept strictly write-only and never loads the path. All bytes entering shell memory come from one of the two audited paths above. - All service-rendered strings are plain-text only (
textFormat: Text.PlainText) and pass an ingest-time sanitizer, so a hostile tracker entry cannot flip QML's rich-text heuristic (no HTML rendering, no<img>-driven remote fetches from labels). - Rows are capped at 200 on both the network and cache paths, and cached entries re-run the exact same normalization/type-check contract as fresh fetches before anything reaches the UI.
- Click targets are restricted to http(s) URLs;
xdg-opennever receives tracker-controlledfile://or custom application URI schemes. - Writes use atomic rename (
FileViewatomicWrites). No elevated permissions anywhere.
Remove
omarchy plugin remove io.github.argusguardian.freemodels