Omahub
← All plugins
F

OmaHome

by FishMacc

Read sensors and control lights, switches, and fans on your Home Assistant server from the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
1272426
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
1272426
Reviewed
1 month ago

The plugin is a Home Assistant widget that securely stores and uses a user-provided token via curl with proper file permissions and stdin handling. No malicious behavior, obfuscation, or suspicious network activity was found; the code is transparent and well-documented.

  • The plugin handles a sensitive token, but it is stored with mode 600 in a mode 700 directory and passed to curl via stdin, not command line, which is secure.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/FishMacc/omahome --enable
Widgets #bar #system

OmaHome — Home Assistant for Omarchy

Read sensors and control lights, switches, and fans on your Home Assistant server from the Omarchy bar.

preview

Install

omarchy plugin add https://github.com/FishMacc/omahome.git --enable

Connect to your Home Assistant

  1. In Home Assistant, create a token: click your profile (bottom left) → Security → Long-lived access tokens → Create token, and copy it.
  2. Click the house icon in the Omarchy bar.
  3. Enter the address of your server — the same URL you use to open the Home Assistant web interface, for example http://homeassistant.local:8123 or http://192.168.1.10:8123 — and paste the token.
  4. Click Connect, then pick the devices and sensors you want to see.

Plain HTTP on your local network is fine: requests go only to the address you enter, nowhere else.

Usage

  • Click the house icon to open the panel; Escape closes it.
  • Toggles switch devices on and off. Dimmable lights get a brightness slider (drag, or scroll over it).
  • Add devices reopens the picker. The gear button returns to the connection setup, where Disconnect deletes the stored token and the server address — your device selection is kept for the next connect.
  • A device you deleted in Home Assistant stays listed with a Remove button so you can drop it.

Remove

omarchy plugin remove io.github.fishmacc.omahome

This does not delete your stored token. Remove it separately:

rm -r ~/.config/omarchy/homeassistant

What it does with your data

  • Requests go only to the Home Assistant address you configure. Nothing is sent anywhere else.
  • Your token is stored in ~/.config/omarchy/homeassistant/auth.header, mode 600, in a mode-700 directory.
  • The token is never written to shell.json and never appears on a command line, so it cannot be read out of the process list.
  • The only external program the plugin uses to talk to Home Assistant is curl. Writing and managing the credential file locally (never over the network) uses a handful of standard POSIX utilities: sh, mkdir, chmod, cat, stat, mv, rm.

Supported entities

light (on/off and brightness), switch, fan, input_boolean, sensor, binary_sensor.

Requirements

Omarchy 4 or newer, with omarchy-shell.