Omahub
← All plugins
D

Omacookie

by Doctor

A fortune cookie that cracks open right in the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
41791f5
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
41791f5
Reviewed
1 month ago

Omacookie is a self-contained bar-widget fortune cookie with no network access, telemetry, install scripts, or privileged operations. Its only external effects are creating and maintaining a small state file under XDG_STATE_HOME, with defensive handling in the bundled Python reader (regular-file check, symlink rejection, 64 KiB cap). The deterministic scan's finding of no issues matches this independent review.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/doctor/omacookie --enable
Widgets #bar #quickshell #games

Omacookie

Omacookie etching a fortune in the Omarchy bar

Omacookie is a fortune cookie that lives entirely in the Omarchy bar. Click the icon and a small popup drops down under it. Click the cookie and it bursts into crumbs that arc away under gravity, then a laser cuts your fortune into the empty slip: a beam angles down from above onto the paper, tracks across the sentence throwing sparks, and each character burns into existence where the beam touches it and cools from hot yellow to ember to ink. Nothing slides in — the letters are cut in place.

Both animations are modelled on the ttfx effects the Omarchy screensaver uses: crumble for the cookie's dust glyphs and dimming, and laseretch for the beam, the sparks, and the cooling ramp. No new window ever opens.

It has no network, account, or telemetry. Fortunes are a bundled, original list shipped in the plugin itself. It uses the Python 3 runtime included with Omarchy to safely load its small state file.

Install

omarchy plugin add https://github.com/doctor/omacookie.git --enable

Then click the cookie in the Omarchy bar. Omacookie is a bar widget with no overlay or panel surface, so there is nothing to summon from the CLI — the bar icon is the whole entry point. If you don't see it, check that it's enabled and placed:

omarchy plugin list | grep omacookie
omarchy bar move io.github.doctor.omacookie --section right

Controls

  • Click the bar icon: open or close the popup
  • Click the cookie: crack it open and reveal your fortune
  • Click anywhere outside the popup: dismiss it

Reopening the popup always starts fresh with a whole cookie and a new fortune. There are 200 fortunes, and the last 30 you were shown are held back from the draw, so you won't see the same one twice in a sitting. That short history and a running "cookies cracked" count are stored in ${XDG_STATE_HOME:-~/.local/state}/omacookie/state.json.

Update and remove

omarchy plugin update io.github.doctor.omacookie
omarchy plugin remove io.github.doctor.omacookie

Removing the plugin does not remove its small state file. Delete that file manually if you also want to reset the cracked-cookie count.

Development

node --test
npm run assets     # regenerate assets/crack.wav
omarchy plugin validate .

Plugins run as unsandboxed code inside the long-lived Omarchy shell. Review the source before enabling third-party plugins. Omacookie writes only its state file and invokes no privileged or network commands.

License

MIT © 2026 Doctor