Omahub
← All plugins
T

Wayfinder

by Tom Ballard

Native AI model routing with in-panel setup, project profiles, prompt-free value, status, and controls for Omarchy.

Security review

Potentially dangerous behavior detected · 28 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
e72f170
Scanned
7 hours ago
  • high permission_ownership …/workflows/arch-app.yml:40

    Recursively changes file ownership.

    chown -R builder:builder .
  • Bundles a systemd unit file.

    [Unit]
  • medium external_hosts test/claude-code-smoke.sh:86

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null; then
  • medium external_hosts test/claude-code-smoke.sh:91

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null || {
  • medium external_hosts test/claude-code-smoke.sh:106

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null; then
  • medium external_hosts test/claude-code-smoke.sh:111

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null || {
  • medium external_hosts test/aider-smoke.sh:99

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null; then
  • medium external_hosts test/aider-smoke.sh:104

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null || {
  • medium external_hosts test/aider-smoke.sh:119

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null; then
  • medium external_hosts test/aider-smoke.sh:124

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null || {
  • medium external_hosts test/pi-smoke.sh:113

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null; then
  • medium external_hosts test/pi-smoke.sh:118

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null || {
  • medium external_hosts test/pi-smoke.sh:133

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null; then
  • medium external_hosts test/pi-smoke.sh:138

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null || {
  • medium external_hosts test/opencode-smoke.sh:136

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null; then
  • medium external_hosts test/opencode-smoke.sh:141

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null || {
  • medium external_hosts test/opencode-smoke.sh:156

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null; then
  • medium external_hosts test/opencode-smoke.sh:161

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null || {
  • medium external_hosts test/codex-smoke.sh:115

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null; then
  • medium external_hosts test/codex-smoke.sh:120

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${provider_port}/healthz" >/dev/null || {
  • medium external_hosts test/codex-smoke.sh:135

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null; then
  • medium external_hosts test/codex-smoke.sh:140

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent "http://127.0.0.1:${router_port}/healthz" >/dev/null || {
  • medium package_manager …/workflows/ci.yml:89

    System-wide Python package installation (not --user).

    pipx install aider-chat==0.86.1
  • Docs external_hosts docs/troubleshooting.md:19

    Downloads or connects to an external HTTP(S) host.

    curl --fail --silent http://127.0.0.1:8088/healthz
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed libsecret gnome-keyring
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -U ./wayfinder-0.6.0-1-x86_64.pkg.tar.zst
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -R wayfinder`. Package removal preserves
  • Docs sudo README.md:63

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -R wayfinder

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e72f170
Reviewed
5 hours ago

The plugin is a local AI router manager that downloads a pinned, SHA-256-verified router binary and runs a user-level systemd service. The deterministic scan's high-risk flags are mostly false positives: the external hosts are all loopback health checks, the package manager and chown findings are in CI workflows, and the sudo commands are documentation for installing the Arch package, not part of plugin execution. No obfuscation, credential theft, or destructive behavior was found.

  • The install.sh script downloads a binary from GitHub releases, but it verifies a pinned SHA-256 digest and checks the archive layout before installation.
  • The plugin installs a systemd user service (wayfinder-router.service) that runs on login; this is expected for the router functionality and is clearly documented.
  • The plugin stores API keys in the desktop keyring via the router, which is appropriate for the intended use.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/asdecided/omarchy-wayfinder --enable
Developer Tools #bar #quickshell #ai
<h1 align="center">Wayfinder for Omarchy</h1> <p align="center"> <a href="https://github.com/tcballard/omarchy-badges"><img src="https://raw.githubusercontent.com/tcballard/omarchy-badges/75975e5b5bf75e7ede3764bcd2950046f7abfe2c/badges/v1/omarchy-app.svg" alt="Built for Omarchy: App" height="20"></a> </p>

One local endpoint for your coding agents.

Wayfinder connects your coding agents to a shared AI router. Open the app to manage connections, tune routing and chat through the gateway. Inspect recent decisions, then connect your coding agents and projects. Close the window when you're done: the background service keeps routing requests.

The optional Omarchy bar companion comes with the app. It shows whether the local gateway is reachable and opens Wayfinder with a click.

Install

Wayfinder is an Arch application, installed and updated with Pacman. There is one package for the app, Router and bar companion; no separate plugin download.

The bundled install path is being prepared for v0.6.0. The latest published v0.5.0 package predates the bundled companion. This branch can be built and tested using the Arch package guide. Official Omarchy packaging is pending.

After installation, open Wayfinder from your launcher. Connect OpenAI, choose a model and verify a request. Then use Connect an agent for the connection instructions. Your desktop keyring must be unlocked.

To add the bar button, choose Omarchy bar → Enable bar companion in the app. Right-click the button to refresh its status; click to open Wayfinder.

Your control centre

  • Overview: gateway status, configured models, recent decisions and priced savings.
  • Connections: hosted APIs, local model servers and desktop-keyring credentials.
  • Routing: thresholds, model tiers, feature weights and private prompt previews.
  • Chat: conversations through your Router, with routing receipts and optional saved history.

The interface follows your Omarchy colours. ChatGPT subscription sign-in is not available in this Linux build. See the development handoff for current behavior and the remaining XPS checks.

<!-- Real app screenshot pending from Tom; no mockup is presented as an XPS capture. -->

Already using the plugin?

Install the app package, then follow the migration guide. The app preserves existing configuration and credentials, and backs up the old plugin before replacing it with the bundled companion.

Update and remove

Update the Wayfinder package through Pacman. The companion updates with it; re-enable it from the app to reload the bar after an update.

To remove just the bar button, choose Omarchy bar → Remove bar companion. Routing continues. To remove the app, stop the service and remove the package:

systemctl --user stop wayfinder-router.service
sudo pacman -R wayfinder

Remove the companion from the app first if you enabled it. Configuration, project profiles, credentials and migration backups remain in your account.

Installation and testing · Migration and rollback · Report a bug

Legacy plugin reference · Apache-2.0 licensed

<!-- Keep old inbound README anchors useful during the app migration. -->

<a id="configure"></a> <a id="controls"></a> <a id="license"></a> <a id="project-profiles"></a> <a id="project-value"></a> <a id="remove"></a> <a id="requirements"></a> <a id="validate"></a> <a id="verified-coding-agents"></a>

Looking for the former plugin controls? Open the legacy reference →