Omahub
← All plugins
E

ngrok

by ejames-dev

Shows active ngrok tunnels in the bar by polling the local ngrok agent's API (127.0.0.1:4040). Click the pill to list tunnel URLs, copy one, or open the local ngrok inspector.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
7a1cfec
Scanned
1 month ago
  • medium external_hosts bin/omarchy-ngrok:12

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-time 2 "http://127.0.0.1:4040/api/tunnels" 2>/dev/null || echo '{"tunnels":[]}'

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
7a1cfec
Reviewed
1 month ago

The plugin is a read-only bar widget that polls the local ngrok agent's loopback API (127.0.0.1:4040) to display tunnel status. The deterministic scan flagged an external host, but the URL is loopback-only and the script performs no writes, credential access, or destructive actions. All user interactions (copy URL, open inspector) are safely handled with proper quoting and standard helpers.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ejames-dev/ngrok-omarchy-plugin --enable
Developer Tools #bar #quickshell #system

ngrok — Omarchy bar widget

Shows active ngrok tunnels in the bar by polling the local ngrok agent's own API at http://127.0.0.1:4040/api/tunnels — the same interface ngrok's own web inspector uses. Click the pill to see each tunnel's public URL, copy one to the clipboard, or jump to the local inspector.

This widget only reads tunnel metadata already exposed by the local agent — it never touches your ngrok auth token or account.

Prerequisites

A local ngrok agent with at least one tunnel running, e.g.:

ngrok http 3000

The bar pill shows "ngrok" with no count when nothing is running, and "ngrok · N" once N tunnels are active.

Install

omarchy plugin add https://github.com/ejames-dev/ngrok-omarchy-plugin --enable

Uninstall

omarchy plugin remove io.github.ejames-dev.ngrok

Security notes

  • Makes a single GET http://127.0.0.1:4040/api/tunnels request on a 2-second timeout — loopback-only, read-only, no credentials.
  • Copying a tunnel URL runs wl-copy with the URL passed through a single-quoted, escaped argument (never interpolated unescaped into a shell string).
  • "Open inspector" launches http://127.0.0.1:4040 (ngrok's own local inspector) via the same browser-launch helper other Omarchy plugins use.
  • No external dependencies beyond curl and wl-copy, both of which ship with Omarchy.