Omahub
← All plugins
B

Navigator

by bhanuprassad

Sysadmin and devops overlay: Ansible, SSH, Compose, Terraform, kube contexts, failed units.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
4d92a75
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4d92a75
Reviewed
1 month ago

The Navigator overlay is a legitimate sysadmin/devops picker that scans local files, reads SSH config, and lists kube/systemd state, then launches user-selected commands in a terminal. All subprocesses are time-boxed and output-capped, and command arguments are shell-quoted to prevent injection. No malicious behavior, persistence, or network activity was found.

  • The plugin reads ~/.ssh/config and exposes host aliases in the UI, which is expected functionality but touches sensitive data.
  • It runs read-only system commands (kubectl, systemctl) and launches terminals with user-chosen tools; all actions require explicit user interaction.
  • The plugin runs unsandboxed in the long-lived Omarchy shell, so a compromised dependency or future change could be risky, but the current code is transparent and safe.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/bhanuprassad/omarchy-navigator --enable
System #quickshell #launcher

Navigator

A sysadmin and devops overlay for Omarchy. One search, then a terminal in the right place.

Kind How it is found Enter
Ansible ansible.cfg, site.yml, ansible-navigator.yml ansible-navigator
Compose compose.yml / docker-compose.yml lazydocker or docker compose ps
Terraform main.tf, .terraform.lock.hcl, terragrunt.hcl shell in that directory
SSH ~/.ssh/config Host lines ssh host
Kubernetes kubectl config get-contexts k9s or kubectl
systemd systemctl --failed journalctl -u

This is a picker, not a second TUI. Ansible still uses ansible-navigator with --execution-environment false.

Navigator overlay

Demo

demo.mp4 — find bheem-ansible, open navigator.

Install

Review the source first. Plugins run unsandboxed inside the long-lived Omarchy shell.

omarchy plugin add https://github.com/bhanuprassad/omarchy-navigator.git --enable

The plugin does not install packages. Put ansible-navigator, kubectl, k9s, lazydocker, tofu / terraform, and docker on PATH yourself if you want those launches.

Summon it:

omarchy-shell shell toggle io.github.bhanuprassad.navigator '{}'

Suggested Hyprland bind in ~/.config/hypr/bindings.lua:

hl.bind("SUPER + SHIFT + A", hl.dsp.exec_cmd([[omarchy-shell shell toggle io.github.bhanuprassad.navigator '{}']]), { description = "Navigator" })

Usage

Key Ansible Compose Terraform SSH / kube Failed unit
Type Filter
Enter navigator welcome lazydocker / compose ps shell ssh / context journalctl
Ctrl-R run site.yml compose up plan — systemctl status
Ctrl-I inventory — — — —
Ctrl-C collections — — — —
Esc Close

The footer changes with the selected row.

Configure

No settings panel. Optional extra search roots:

export NAVIGATOR_PATH=~/bheem-ansible:~/infra:~/ops

Default scan: $HOME, $HOME/src, $HOME/ansible, $HOME/playbooks, $HOME/infra, $HOME/ops, depth 4. Skips .git, .venv, node_modules.

Remove

omarchy plugin remove io.github.bhanuprassad.navigator

Dependencies

  • Omarchy Quattro (omarchy-shell, qs.Commons, qs.Ui)
  • xdg-terminal-exec
  • GNU find (-printf)
  • GNU coreutils (head, timeout)
  • Optional: ansible-navigator, ansible, docker, lazydocker, tofu/terraform, kubectl, k9s

The plugin does not install packages, add hooks, or make network calls. Retained output is byte-capped before it enters the shell. Discovery subprocesses also have deadlines: 10 seconds for the filesystem scan, 3 seconds for Kubernetes and systemd listings, and 2 seconds for the SSH config read, followed by a 1-second TERM-to-KILL grace period.

License

MIT. See LICENSE.

Develop

node Model.test.js
omarchy plugin validate .
qmllint -I "$OMARCHY_PATH/shell" Overlay.qml
omarchy-shell shell summon io.github.bhanuprassad.navigator '{}'