Omahub
← All plugins
E

Quicksearch

by equa-tory

Type anywhere, land in your browser. Bare-keyword quicklinks with a configurable default engine.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
0a43b43
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
0a43b43
Reviewed
1 month ago

The plugin is a straightforward search overlay with no malicious code. It modifies Hyprland bindings and config files with user consent and includes careful file-handling safeguards. The deterministic scan found no issues, and my review confirms the code is safe, though it does execute external commands and modify system config files.

  • The plugin automatically edits ~/.config/hypr/bindings.lua and reloads Hyprland on first run, which could be surprising but is clearly documented and consented to via installation.
  • It executes python3 scripts and shell commands (omarchy, omarchy-shell) which could be a vector if the plugin directory is tampered with, but the code itself is benign.
  • The bindings.py script uses advanced file operations (O_NOFOLLOW, atomic replace) which are safe but complex; a human should verify no edge cases lead to unintended file modifications.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/equa-tory/omarchy-quicksearch --enable
Productivity #media

Quicksearch

A keyboard-summoned search bar for the Omarchy shell. Press a key anywhere, type, hit Enter, land in your browser.

  • One key, from anywhere. Default ALT + SPACE. No bar icon.
  • Bang quicklinks. v cats → YouTube, g rust traits → Google. You define the keyword and the URL template.
  • Bang-only bookmarks. A quicklink with no {input} just opens its page — hn → Hacker News, no query needed.
  • Configurable default engine. DuckDuckGo out of the box.
  • URLs pass straight through. github.com opens the site, not a search.
  • Settings without a mouse. Ctrl+, or the gear icon: edit bangs, pick the default, rebind the shortcut.
  • No setup step. omarchy plugin add … --enable also binds ALT + SPACE and seeds the config on first run.

preview

Install

omarchy plugin add https://github.com/equa-tory/omarchy-quicksearch.git --enable

That's it. On first run the plugin seeds ~/.config/omarchy/quicksearch.json and binds ALT + SPACE — it edits ~/.config/hypr/bindings.lua (with a timestamped backup) and reloads Hyprland, then shows a notification telling you the key. If ALT + SPACE is already taken it won't steal it; the notification says so and you pick a key from the Settings pane instead.

Prefer a different key from the start, or want to do it by hand:

~/.config/omarchy/plugins/io.github.equa-tory.quicksearch/install.sh "SUPER + P"
# or
python3 ~/.config/omarchy/plugins/io.github.equa-tory.quicksearch/scripts/bindings.py set "SUPER + P"
# or add the line yourself:
#   o.bind("ALT + SPACE", "Quicksearch", "omarchy-shell shell toggle io.github.equa-tory.quicksearch {}")

Uninstall

~/.config/omarchy/plugins/io.github.equa-tory.quicksearch/uninstall.sh

Removes the managed keybinding block, then the plugin. Running omarchy plugin remove on its own leaves the binding behind as a dead key (the installer never runs plugin code, so it can't clean up) — bindings.py remove or the Settings pane's remove path fixes that.

Using it

Key Action
Enter Search / open. A leading bang routes to that quicklink.
Ctrl+Enter Force the default engine, ignoring any bang (v for vendetta).
Ctrl+, Open Settings (also the gear icon).
Esc Clear the field, then close.
click a bang chip Prefill its keyword.

Routing, in order:

  1. Empty input → nothing.
  2. A URL (https://…, or a bare host.tld/…) → opens directly.
  3. First word matches a bang keyword →
    • bookmark bang (URL has no {input}): opens the page, with or without anything after it.
    • template bang: routes when there's a query after the keyword; a lone g with nothing after it is just searched.
  4. Everything else → the default engine.

A leading ! (!v, !g cats) forces the bang either way.

Configuration

~/.config/omarchy/quicksearch.json, created on first run, reloaded when you save it. The Settings pane writes the same file.

{
  "version": 1,
  "defaultEngine": "ddg",
  "engines": [
    { "keyword": "ddg", "name": "DuckDuckGo", "url": "https://duckduckgo.com/?q={input}" },
    { "keyword": "g",   "name": "Google",     "url": "https://www.google.com/search?q={input}" },
    { "keyword": "hn",  "name": "Hacker News","url": "https://news.ycombinator.com" }
  ]
}
  • {input} is replaced with the URL-encoded query.
  • A URL with no {input} is a bookmark — the keyword opens it directly.
  • icon is one Nerd Font glyph (optional).
  • defaultEngine is a keyword. If it is missing or wrong, the first engine wins.
  • A broken file falls back to the built-in defaults and shows a warning in the panel rather than breaking the key.

Bundled defaults: ddg DuckDuckGo (default), g Google, gg ChatGPT, x X, v YouTube, gh GitHub, w Wikipedia, aur AUR.

The shortcut

Auto-bound to ALT + SPACE on first run. Change it from the Settings pane (gear icon → SHORTCUT → Rebind), or:

python3 scripts/bindings.py set "SUPER + P"   # rebind
python3 scripts/bindings.py status            # show current
python3 scripts/bindings.py remove            # remove the managed block

Delete ~/.config/omarchy/quicksearch.json and the plugin treats the next start as a fresh install again (re-seeds, re-checks the binding).

Known limitations

  • The panel appears on one monitor (the primary), like Omarchy's own emoji and clipboard overlays.

Development

node tests/test_router.mjs                                    # routing table
omarchy plugin validate .                                     # manifest
omarchy-shell shell toggle io.github.equa-tory.quicksearch '{}'
omarchy-shell shell toggle io.github.equa-tory.quicksearch '{"view":"settings"}'

Editing QML hot-reloads on save. Editing Router.js needs rm -rf ~/.cache/quickshell/qmlcache && omarchy-restart-shell — the compiled JS is cached by path, not invalidated on change.

License

MIT — see LICENSE.