Omahub
← All plugins
C

Omahero

by Cam Tucker

Make one window the hero

Security review

Potentially dangerous behavior detected · 6 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
12a9401
Scanned
1 month ago
  • high decode_and_execute install.sh:59

    Interpreter evaluated with an execution builtin.

    python3 -c '
  • medium package_manager …/workflows/ci.yml:32

    System package manager operation.

    apt-get update
  • medium package_manager …/workflows/ci.yml:33

    System package manager operation.

    apt-get install --yes qt6-declarative-dev-tools
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get update
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install --yes qt6-declarative-dev-tools
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n")

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
12a9401
Reviewed
1 month ago

The deterministic scan's high rating is driven by false positives: the inline `python3 -c` in install.sh only parses `omarchy plugin list --json`, and the sudo/apt-get steps run only in GitHub Actions CI, not on a user's machine. The actual plugin is a user-level Hyprland focus mode that requires explicit consent before writing a managed key binding, edits configuration atomically with rollback, and contains no network, credential, or destructive behavior.

  • The plugin modifies ~/.config/hypr/bindings.lua and can replace an existing shortcut, but only via an explicit local install command or the consent-based first-run UI.
  • The inline python3 -c in install.sh is flagged as decode_and_execute, but it only reads structured JSON from the local omarchy CLI and checks for the plugin ID; it does not execute remote or user-controlled code.
  • The CI workflow uses sudo apt-get, but those commands run only on the GitHub-hosted runner for testing QML parsing, not during plugin installation or runtime.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/camerontucker/omahero --enable
Productivity #Hyprland #quickshell #workspaces
<div align="center">

Omahero

Make one window the hero

Omahero focus mode with Omawrite

Install · Use · Configure · Security · Remove

</div>

Omahero is a focus mode for Omarchy that hides all other windows and restores the layout when you leave.

Install

Requires Omarchy Quattro; no additional packages beyond its standard Hyprland and Python 3 runtime.

omarchy plugin add https://github.com/camerontucker/omahero.git --enable

On first launch, confirm Super + H or choose another shortcut. Nothing is written until you confirm.

Local checkout: ./install.sh --shortcut "SUPER + H"

Use

  • Super + H — toggle Hero mode
  • Super + Alt + H — cycle prose, square, and landscape shapes
  • Escape — leave Hero mode

Shape and Escape shortcuts exist only while Hero mode is active. Shape choices are remembered per app.

Configure (~/.config/omahero/config.json)

{
  "prose_width": 840,
  "square_size": 900,
  "landscape_width": 1400,
  "landscape_ratio": 1.6,
  "default_shape": "prose",
  "shape_shortcut": "SUPER + ALT + H",
  "vertical_margin": 48,
  "dim_strength": 0.0,
  "other_windows_opacity": 0.0,
  "bar_opacity": null
}

Update

omarchy plugin update io.github.camerontucker.omahero

Security

Omahero runs as unsandboxed user code, reads Hyprland window metadata, and temporarily changes window state. It does not read window contents, clipboard data, credentials, or network resources. See SECURITY.md.

Recovery

If the hero window closes, press Super + H to restore the surviving windows.

Remove

~/.config/omarchy/plugins/io.github.camerontucker.omahero/uninstall.sh
omarchy plugin remove io.github.camerontucker.omahero

Development

PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s tests -v
bash -n install.sh uninstall.sh
omarchy plugin validate .
/usr/lib/qt6/bin/qmllint -I /usr/share/omarchy/shell HeroService.qml
git diff --check

Changelog · MIT License