Omahub
← All plugins
A

Catch

by Archie

Save what just happened. A private, hardware-aware instant replay buffer for the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
c539725
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c539725
Reviewed
1 month ago

Catch is a screen-recording bar widget that launches gpu-screen-recorder through a bounded helper script and writes clips only on explicit user action. The code is defensive and well-tested, with no network behavior, no install-time destructive commands, and no hidden persistence or credential theft. The main residual risk is inherent to any unsandboxed screen recorder: while armed it continuously captures the selected monitor, and the plugin runs with the user's full permissions.

  • The plugin runs unsandboxed with the user's permissions and continuously records the selected monitor while armed, so sensitive on-screen content can exist in process/GPU memory; this is disclosed in the README and is inherent to the plugin's purpose.
  • The helper script and QML invoke external binaries (gpu-screen-recorder, gsr-cli, hyprctl, jq, lspci, pgrep, dbus-monitor, ffmpeg, mpv, wl-copy, xdg-open) from PATH; a compromised PATH could redirect these, but that is a general environment risk rather than a plugin-specific flaw.
  • The sampled repository does not include the full Service.qml or the remainder of catch-helper, so the complete subprocess/argument construction was not directly audited; the included tests and defensive parsing mitigate this, but a human may want to review the full files before publishing.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/homie10/Catch --enable
Widgets #bar #quickshell #media

Catch

Save what just happened. Catch is a private, hardware-aware instant replay buffer for the Omarchy bar. Arm it, work normally, and save the previous 15, 30, or 60 seconds only when something worth keeping occurs.

The icon is a rewind ring shaped like a C wrapped around a capture dot. Its arc fills with the live replay buffer, sparkles when Catch is ready, and spins while a clip is being finalized.

Catch preview

Why Catch feels instant

Catch continuously sends one selected monitor through GPU Screen Recorder's hardware encoder into a compressed circular buffer in RAM. Saving is a fast buffer write, not a real-time re-encode:

monitor → hardware H.264 encoder → RAM replay ring → Catch → finished MP4

No replay file is intentionally written before the user presses Catch. The ring keeps rolling after a save.

Highlights

  • One-click save of the previous 15, 30, or 60 seconds
  • Auto, Efficient, Balanced, Crisp, Smooth, and Custom quality profiles
  • Hardware and monitor capability detection
  • Live memory and default clip-size estimates
  • Resolution, frame rate, bitrate, codec, history, cursor, and monitor controls
  • Desktop audio as an explicit opt-in; microphone capture is intentionally absent
  • Lock and suspend privacy shutter: stop the recorder and discard history
  • Automatic yielding to Omarchy's regular screen recorder
  • Private runtime socket and a shell-owned recorder process that cannot become an orphan
  • Recent clips with Play, Reveal, and Copy Path actions
  • Theme-native popup and a stateful buffer-progress icon

Requirements

  • Omarchy 4.0 or newer with the Quickshell plugin host
  • GPU Screen Recorder 6.0 or newer: gpu-screen-recorder and gsr-cli
  • A supported Intel, AMD, or NVIDIA hardware encoder
  • Capture detection: hyprctl, jq, lspci, pgrep, and dbus-monitor
  • Clip integration: ffmpeg, mpv, wl-copy, and xdg-open
  • Optional: Nautilus enables selecting the saved clip instead of opening only its containing directory

These are present in a standard current Omarchy installation.

Install

omarchy plugin add https://github.com/homie10/Catch.git --enable

Catch installs disarmed. It never starts capturing merely because it was installed. To place its bar icon immediately before Omarchy's power widget:

omarchy bar move io.github.homie10.catch --section right --before omarchy.power

Remove

omarchy plugin remove io.github.homie10.catch

Removal stops Catch through the normal Omarchy plugin lifecycle. Saved clips are deliberately preserved under ~/Videos/Catch; delete that directory separately only if you also want to remove your recordings.

Controls

Gesture or command Result
Left-click while ready Save the configured default duration
Left-click while off Open Catch
Right-click Open Catch settings
Middle-click Arm or disarm
omarchy-shell catch arm Arm using the configured/focused monitor
omarchy-shell catch save 30 Save the previous 30 seconds
omarchy-shell catch disarm Stop and discard history
omarchy-shell catch status Print JSON status

Suggested optional Hyprland binding:

Super + Shift + R → omarchy-shell catch save 30

Catch documents the binding but never edits a user's keybindings itself.

Adaptive profiles

Auto resolves to Efficient when the computer is on battery and Balanced while connected to AC. A live buffer is never silently restarted when power or settings change. Instead, Catch shows Apply & clear, because changing an encoder profile necessarily discards the current history.

Profile Default target Intent
Efficient Up to 1080p24, approximately 8 Mbps Longer battery life
Balanced Up to 1080p30, approximately 12 Mbps Everyday capture
Crisp Native/4K30, resolution-scaled bitrate Text and fine detail
Smooth Up to 1080p60, approximately 24 Mbps Games and animation
Custom User-selected resolution/FPS/bitrate/codec Full control

Bitrates scale with the actual output pixel count. Auto also reduces a 60-second history to 30 seconds on machines with less than 5 GiB of RAM.

Privacy model

  • First use is always disarmed.
  • A visible bar icon communicates every state.
  • Lock and suspend stop the recorder and discard the replay ring.
  • Resume after unlock is off by default and must be explicitly enabled.
  • Desktop audio is off by default; microphone recording is not implemented.
  • Catch records exactly one selected monitor and never silently switches to a different one.
  • Catch has no network behavior.
  • Saved files are created under ~/Videos/Catch with a restrictive process umask and personal metadata excluded.

“RAM-only” is not encryption. Sensitive pixels can still exist in process/GPU memory while Catch is armed, and whole-monitor capture cannot exclude a password manager or individual private window.

Permissions and system changes

Like every Omarchy shell plugin, Catch runs unsandboxed with the current user's permissions. It never requests administrator privileges, installs packages, modifies system services, changes Hyprland configuration, or downloads remote code.

Catch executes only the dependencies listed above plus Omarchy's own notification command. It creates an owner-only runtime directory under $XDG_RUNTIME_DIR, creates ~/Videos/Catch with restrictive permissions, and writes a video only after an explicit Catch action. It has no network behavior.

Architecture

Service.qml is the single recorder owner. It launches one non-detached GPU Screen Recorder child through a private socket under $XDG_RUNTIME_DIR. The Omarchy/Quickshell lifecycle therefore kills capture if the plugin is disabled, removed, hot-reloaded, or the shell exits.

BarWidget.qml and Panel.qml are views/controllers over that singleton. They never search for or kill arbitrary recorder processes. Catch uses only its own socket, and its executable argv begins with the absolute path so Omarchy's regular recorder remains independently controllable.

Bounded subprocess protocol

No raw recorder or system-command stream enters the long-lived Omarchy Shell process. catch-helper applies the following producer-side contracts before QML can collect or parse anything:

Boundary Hard limit
Each finite capability producer 64 KiB and a 2–4 second deadline
Capability document 32 KiB, 16 monitors, 24 audio devices
Monitor/device fields 64–160 characters depending on the field
Recorder status document 128 bytes
Save result document 8 KiB; saved path must resolve inside ~/Videos/Catch
Recent-clips document 48 KiB, 5 results from at most 512 candidates
Suspend monitor 512-byte input chunks, 4 KiB parser state, fixed JSON events

GPU Screen Recorder stdout and stderr are discarded at the producer while it runs. Status, save, and stop commands are deadline-bound; only versioned, field-bounded JSON results reach QML. CatchModel.js independently validates the document sizes, schemas, counts, numeric ranges, and string lengths before retaining them.

Development checks

omarchy plugin validate .
bash -n catch-helper
tests/test_helper.sh
qmllint -I /usr/share/omarchy/shell *.qml
QT_QPA_PLATFORM=offscreen /usr/lib/qt6/bin/qmltestrunner \
  -input tests -import . -import /usr/share/omarchy/shell

License

MIT © 2026 Archie