Omahub
← All plugins
D

Herdr Collie

by Daniel Garcia Pulpeiro

Monitor and toggle the Collie bridge and its Tailscale endpoint from the Omarchy bar.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
ef1e649
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:67

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/dpulpeiro/omarchy-herdr-collie.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
ef1e649
Reviewed
1 month ago

The plugin is a straightforward bar widget that queries Collie status and delegates enable/disable to Collie's own collie-ctl.sh. The code is clear, uses standard tools, and contains no obfuscation, hidden persistence, or destructive actions. The only flagged finding is a git clone command in the README, which is documentation only and not executed by the plugin.

  • The plugin can enable/disable a systemd user service and modify Tailscale serve configuration, but only via Collie's own collie-ctl.sh, which is the intended and documented behavior.
  • The README clearly warns that Collie provides remote shell access and that enabling it exposes the machine to the tailnet; this is a user decision, not a plugin vulnerability.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/dpulpeiro/omarchy-herdr-collie --enable
Productivity #bar #system #security

Herdr Collie

An Omarchy bar widget for Collie, the mobile web UI for Herdr.

The widget shows whether both the Collie user service and its Tailscale Serve endpoint are active. Its panel displays the tailnet URL and can enable or disable both components together.

The Herdr Collie bar icon and its open panel, showing a running status, the tailnet URL, and the disable action

Read this before enabling

Collie is remote shell access to this machine. It drives your Herdr panes, which means typing into your terminals. Enabling it from this widget publishes that surface to every device on your tailnet.

  • This plugin only ever uses tailscale serve, which is tailnet-only. It never enables tailscale funnel, so Collie is never exposed to the public internet.
  • How well that surface is protected is Collie's configuration, not this plugin's. Collie only enforces a Tailscale identity check when COLLIE_TRUSTED_USER is set, and nothing sets it for you. With it unset, any tailnet peer that can reach the host gets full read and write access to your terminals.

Set it before you enable the widget, in ~/.config/herdr/plugins/config/herdr.collie/.env:

COLLIE_TRUSTED_USER=you@example.com

Omarchy plugins run unsandboxed with your full user permissions. There is no plugin permission model, so installing this plugin is a decision to trust its code.

How enable and disable work

Both actions delegate to Collie's own collie-ctl.sh, which this plugin locates under ~/.config/herdr/plugins/github/herdr.collie-*/scripts/collie-ctl.sh. That script is the only safe way to manage the tailnet front door:

  • It refuses to publish over a tailscale serve root mount it does not own, so enabling Collie cannot silently unpublish another service.
  • On teardown it removes only the mapping it recorded as its own, rather than clearing the whole HTTPS listener.
  • When upgrading from an older widget that created the Collie mapping directly, it first adopts a matching Collie proxy through collie-ctl.sh, then removes it through the same ownership check.
  • It refreshes COLLIE_TAILSCALE_HOSTS on every start, so Collie's fail-closed Host allowlist stays correct after a tailnet address change.

If collie-ctl.sh is not present, enable and disable fail with an error instead of falling back to raw tailscale serve calls.

Note that enable and disable also control autostart at login, because collie-ctl.sh uses systemctl --user enable --now and disable --now.

Requirements

  • Omarchy with the Quattro shell plugin system
  • Collie installed as the herdr.collie Herdr plugin, including its collie-ctl.sh
  • The collie.service systemd user unit created by Collie
  • Tailscale with Serve enabled
  • Bash, systemd, and jq

Install

From GitHub:

omarchy plugin add https://github.com/dpulpeiro/omarchy-herdr-collie.git --enable

For local development:

git clone https://github.com/dpulpeiro/omarchy-herdr-collie.git
cd omarchy-herdr-collie
omarchy plugin validate .
omarchy plugin add "$PWD" --enable

Place it near the Tailscale widget:

omarchy bar move io.github.dpulpeiro.collie --after omarchy.tailscale

Usage

Click the Collie icon to open its panel. The icon is green when both the service and tailnet endpoint are active, urgent-colored when only one of the two is active, and dim otherwise. If the Tailscale daemon cannot be queried the panel reports an unknown state rather than claiming the endpoint is off.

Click the displayed tailnet URL to open Collie. Use the panel button to enable or disable the service and endpoint together.

The first enable after an update may take a while, because collie-ctl.sh builds Collie's web bundle before starting.

Configuration

The widget reads Collie's port from COLLIE_PORT in ~/.config/herdr/plugins/config/herdr.collie/.env, falling back to 8787. To override it for the widget alone, export COLLIE_PORT in the Omarchy shell environment before loading the plugin.

Validate

omarchy plugin validate .
qmllint -I /usr/share/omarchy/shell BarWidget.qml Panel.qml
bash -n scripts/collie-control

Remove

omarchy plugin remove io.github.dpulpeiro.collie

Removing this widget does not stop or uninstall Collie.

License

MIT