Omahub
← All plugins
C

SRD Lookup

by Christoffer Celorico-Berglund

Summon-search the 5.2 SRD (2024 / 5.5): conditions, spells, monsters, rules, feats, items, and magic items. Offline snapshot from Open5e.

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
cb47de3
Scanned
5 days ago
  • high destructive_filesystem data/srd.json:1

    Low-level disk manipulation or write command.

    Shred attacks.\nShred. Melee Attack Roll: +6, reach 5 ft. 10 (2d6 + 3) Piercing damage plus 10 (3d6) Poison damage.\nSpores. Constitution Saving Throw: DC 15, each creature in a 20-foot Emanation orig

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
cb47de3
Reviewed
5 days ago

The deterministic high finding is a false positive: the flagged "Shred attacks" text in data/srd.json is D&D SRD monster content, not the Linux shred command. The plugin reads a bounded local JSON snapshot through a hardened helper, writes a small pins file safely, and copies text via wl-copy without shell interpolation; no destructive, hidden, or credential-harvesting behavior was found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Cozidian/omarchy-dnd --enable
Widgets #bar #quickshell #games

SRD Lookup

Summon, type, read, dismiss. A 5e SRD search overlay for the Omarchy bar — the emoji picker, but for prone, counterspell, and goblin.

SRD Lookup on Fireball, with search results, spell stats, and an 8d6 roll

Plugin id: io.github.cozidian.dnd

D&D Beyond has no public API, so this does not talk to your character sheet. It searches a local snapshot of the System Reference Document 5.2 (the 2024 / “5.5” rules, CC BY 4.0) via Open5e: conditions, spells, monsters, rules, feats, mundane items, weapons, armor, and magic items.

Install

omarchy plugin add https://github.com/Cozidian/omarchy-dnd.git --enable

From this checkout:

rsync -a --delete ./ ~/.config/omarchy/plugins/io.github.cozidian.dnd/
omarchy-shell shell rescanPlugins
omarchy plugin enable io.github.cozidian.dnd --section center

Usage

Click the book on the bar, or:

omarchy-shell shell toggle io.github.cozidian.dnd

Suggested Hyprland bind (pick a chord that is free):

o.bind("SUPER + SHIFT + D", "SRD lookup", "omarchy-shell shell toggle io.github.cozidian.dnd")

Type to search. Prefixes narrow the index (mon, sp, co, ru, fe, weap, item, mag work too):

  • spell fireball / sp fire
  • monster goblin / mon gob
  • weapon dagger / weap dag
  • magic bag of holding / mag bag
  • item rope
  • armor plate
  • rule cover
  • feat alert
  • condition prone

Spaces split tokens, so red drag matches Adult Red Dragon and fire ball matches Fireball.

With an empty query, the list is the conditions — the thing you look up mid-turn. Ctrl+P pins the current entry at the top (up to eight). Pins are kind+name refs in ~/.local/state/omarchy/dnd-recents.json, resolved against the current snapshot.

  • Up / Down move the result list
  • Ctrl+Up / Ctrl+Down scroll the entry on the right
  • Enter or Ctrl+C copies the entry
  • [ / ] or Tab picks which roll Ctrl+R fires
  • Ctrl+R rolls the selected dice expression; Ctrl+Shift+R rolls an attack with Advantage
  • Ctrl+P pins or unpins the current entry
  • Ctrl+U or Esc clears the query; Esc again closes

Data

data/srd.json is generated from Open5e (srd-2024 / SRD 5.2). Refresh it with:

python3 scripts/fetch-srd.py

The refresh path is HTTPS-only to api.open5e.com, with response-byte, page, entry, and string-length ceilings. Redirects are refused before they are followed unless the next URL is still HTTPS api.open5e.com. Names, summaries, and bodies are stripped of markup and control characters before they are written. The overlay loads the snapshot through an isolated (python3 -I) helper that opens one no-follow, nonblocking regular-file descriptor (byte-capped, 2s deadline), keeps at most 4000 entries, searches a 1 KiB haystack per entry, and renders every Text sink as Text.PlainText. Copy feeds /usr/bin/wl-copy -- on stdin; snapshot text never reaches a shell.

python3 tests/test_fetch.py
python3 tests/test_read_index.py
node tests/test_search.js

The plugin code is MIT. SRD 5.2 text is CC BY 4.0, as published by Wizards of the Coast and redistributed by Open5e.

Remove

omarchy plugin remove io.github.cozidian.dnd