Omahub
← All plugins
G

OmaGrid

by GrzeskoByte

Turn the whole monitor into a lettered grid and click without the mouse.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
bc590a6
Scanned
1 month ago
  • medium sudo OmaGrid.qml:333

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S ydotool && systemctl --user enable --now ydotool · Esc close"
  • Docs sudo README.md:29

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S ydotool

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bc590a6
Reviewed
1 month ago

The plugin is a keyboard-driven grid overlay that moves and clicks the mouse via ydotool. The deterministic scan flagged sudo commands, but those appear only in the README and as a user-facing hint string in the QML; the plugin itself never executes sudo or any elevated command. The only shell commands it runs are safe checks and config reads from the user's home directory.

  • The README and an in-app hint string mention `sudo pacman -S ydotool`, but this is documentation/UI text, not executed by the plugin.
  • The plugin relies on ydotool, which requires a system package and a user daemon; this is a legitimate dependency, not a security issue.
  • No obfuscation, persistence, credential access, or destructive operations were found in the reviewed source.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/GrzeskoByte/OmaGrid --enable
Productivity #Hyprland #quickshell

OmaGrid

Press a key → the screen becomes a lettered grid → type a label → the mouse jumps there and clicks. A mouse-free keyboard interaction layer for Omarchy (Hyprland).

OmaGrid grid overlay

  • Full-monitor grid — the focused monitor is divided into cells, each labeled with a two-letter combo (row letter + column letter, e.g. AQ).
  • Precision zoom — hold Shift and type a label to zoom into that cell for a more precise click. Up to 3 levels (8×8 → 4×4 → 2×2 by default).
  • Keyboard-only — no mouse needed to open, navigate, or click. Arrow keys move a selection highlight, Enter clicks it.
  • Fully configurable — grid size per zoom level, letter sets, uneven cell proportions, and single-letter mode, all via a config.json you edit live.

Requirements

  • Omarchy (Quickshell-based shell) with Hyprland
  • ydotool — the synthetic mouse driver used to move and click. Install it before the plugin, or the grid will open but clicking will be disabled (the overlay shows the install command in that case).

Install

# 1. Required: ydotool (synthetic mouse)
sudo pacman -S ydotool
systemctl --user enable --now ydotool

# 2. Install the plugin (fetches from git, validates, and enables it)
omarchy plugin add https://github.com/GrzeskoByte/OmaGrid.git --enable

# 3. Add the activation keybinding to ~/.config/hypr/bindings.lua
o.bind("SUPER + SHIFT + T", "OmaGrid", "omarchy-shell shell toggle io.github.grzeskobyte.omagrid")
#    then reload Hyprland: hyprctl reload

If the plugin doesn't respond after a while, restart the shell: omarchy restart shell.

Update / remove

omarchy plugin update io.github.grzeskobyte.omagrid   # pull the latest version
omarchy plugin remove io.github.grzeskobyte.omagrid   # uninstall

Usage

Press SUPER + SHIFT + T. The screen dims and the focused monitor becomes a grid. Type a cell's label to click it; the overlay closes.

Goal Keys
Show grid SUPER + SHIFT + T
Click a cell type its label (e.g. AQ)
Zoom into a cell (precision) Shift + label
Step back one zoom level Esc
Select a cell (highlight) ↑ / ↓ / ← / →
Click the selected cell Enter
Close without clicking Esc

Typing is typeahead-based: type just enough letters to identify a cell, Backspace corrects, Esc clears the buffer.

Configuration

The plugin reads config.json from its plugin folder (~/.config/omarchy/plugins/io.github.grzeskobyte.omagrid/config.json) on every open — edits apply immediately, no shell restart needed:

{
  "rowLetters": "ASDFGHJK",
  "colLetters": "QWERTYUI",
  "levels": [
    { "cols": 8, "rows": 8, "labelSize": 16 },
    { "cols": 4, "rows": 4, "labelSize": 24 },
    { "cols": 2, "rows": 2, "labelSize": 48, "singleLetter": true }
  ]
}
  • levels — one entry per zoom level; level 0 covers the whole monitor, each Shift+label zoom steps to the next entry. Any cols × rows up to 676 cells works. labelSize sets that level's label font size in pixels.

  • singleLetter: true — use one-key selection (A–Z) instead of two-letter labels, handy on small grids.

  • rowLetters / colLetters — override the label letters (up to 26 chars each; grids larger than your sets fall back to AA, AB, …).

  • colWeights / rowWeights — uneven cells; weights are scaled to the grid, so [1, 2, 1] makes the middle column twice as wide. Cells keep their proportions through zoom and clicks:

    { "cols": 3, "rows": 2, "colWeights": [1, 2, 1], "rowWeights": [1, 3] }
    
  • labels — an explicit per-level label array; must contain exactly cols × rows entries.

How it works

Cell centers are computed from the focused monitor's geometry. Picking a cell runs:

ydotool mousemove --absolute -x <cx> -y <cy> && ydotool click 0xC0

ydotool needs its daemon ydotool running (a user systemd service) with /dev/uinput access. If the binary or the daemon socket is missing, the overlay shows an install hint and clicks are disabled until it's available.

Troubleshooting

  • Overlay won't open — omarchy-shell shell ping, then omarchy plugin list to confirm the id is enabled, and check the bindings.lua line; the binding only fires after a hyprctl reload. If the plugin was changed on disk while running, omarchy restart shell picks up the new code.
  • Grid shows but clicking does nothing — ydotool is missing or the ydotool daemon isn't running: systemctl --user status ydotool; the socket should exist at $XDG_RUNTIME_DIR/.ydotool_socket.
  • Typed label didn't register — the overlay grabs the keyboard exclusively; make sure no other overlay is open.

Development

sync.sh copies the repo files into the installed plugin folder (~/.config/omarchy/plugins/io.github.grzeskobyte.omagrid) — useful while iterating, since symlinks are rejected by plugin validation.

License

MIT — see LICENSE.