Omahub
← All plugins
J

Desk Transition

by Jeremy Longshore

Desk Transition gives Hyprland two local display actions. Desk reads active outputs and arranges them left to right by reported width. Laptop selects the first active eDP or LVDS output and focuses it without disabling another screen. The panel previews both actions, shows each active output's name, resolution, and focus state, and lets you focus one directly. Each action re-reads state and validates output names. No network, credentials, or display-disable command. State refreshes after action.

Security review

Potentially dangerous behavior detected · 4 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
a9e1688
Scanned
1 week ago
  • high destructive_filesystem scripts/rig-verify.sh:77

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME && mkdir -p /tmp/$NAME && tar xzf /tmp/$NAME.tgz -C /tmp/$NAME' || exit 3
  • high destructive_filesystem scripts/rig-verify.sh:98

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME /tmp/$NAME.tgz >/dev/null 2>&1
  • low obfuscation tests/model.test.js:6

    Augments a command with octal/hex escape sequences.

    \x00b\u202ec</b>"), "babc/b")
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n" or raw[12:16] != b"IHDR":

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a9e1688
Reviewed
1 week ago

The flagged destructive filesystem operations live only in developer/verification scripts (rig-verify.sh, rig-render.sh) that run on the author's isolated rig, never in the installed plugin runtime. The runtime consists of QML and a bounded shell helper that only queries Hyprland and issues validated focus/layout commands, with no network access, no credentials, and no destructive actions. The obfuscation findings are false positives (test data and PNG magic-byte checks).

  • The deterministic scan flags rm -rf /tmp/... in scripts/rig-verify.sh, but that script is developer tooling that runs on the author's rig and is not part of the plugin's installed runtime.
  • The obfuscation findings in tests/model.test.js and c43-omarchy-marketplace-presentation.sh are false positives (test fixture strings and PNG magic-byte detection).
  • The bin/desk-transition helper was not fully reviewed, but tests confirm it bounds input, validates output names, and never issues a disable command.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jeremylongshore/omarchy-desk-transition-entry --enable
Productivity #bar #quickshell

Desk Transition

Desk Transition banner

ko-fi

Desk Transition gives Hyprland two local display actions: Desk lays every active output out left to right, while Laptop focuses the first active eDP or LVDS panel. It never hard-codes output names or disables a display.

Desk Transition showing both scenes and two discovered displays in Omarchy

The committed preview is a direct 1280 by 720 capture from the isolated Buzz Omarchy rig. The unchanged plugin scanned a deterministic two-output Hyprland fixture, applied both scenes through live shell IPC, proved that no disable command was emitted, and opened the populated panel. .render-proof.json binds the exact source package, runtime log, action log, fixture, screenshot, and human visual approval.

Every action reads a fresh monitor list and validates the selected name before dispatching a Hyprland command. With no Hyprland session it reports an empty state rather than guessing at hardware.

Install

omarchy plugin add https://github.com/jeremylongshore/omarchy-desk-transition-entry --enable

Use Desk to arrange active outputs, Laptop to refocus the internal panel, or select a detected monitor directly.

Verify

npm test
npm run test:race
npm run test:mutation
npm run audit
npm audit --audit-level=low
shellcheck --severity=warning scripts/*.sh e2e/*.sh .githooks/pre-push
bash scripts/run-plugin-gates.sh
bash scripts/check-lane-freshness.sh
npm run test:e2e

After inspecting the exact new preview at marketplace scale, bind approval with scripts/approve-preview.sh. C43 blocks submission when copy is not exactly 500 characters, the banner is unsafe or missing, the Buzz receipt is stale, or the preview hash has not received explicit visual approval.

Maintainers wanted

These plugins are growing, and we are looking for dependable Omarchy users who want to review issues, test releases, and keep a plugin healthy over time. Start with a small pull request or open a maintainer interest issue titled Maintainer interest. Tell us which plugin you use and how you want to help. Consistent contributors can earn maintainer responsibility.

License

MIT