Omahub
← All plugins
J

Flow Boundary

by Jeremy Longshore

Mark a boundary when you arrive at focused work or leave it behind. Flow Boundary puts Arrive and Leave actions in the Omarchy bar, changes the pill from FLOW to PAUSE, and shows your eight newest color-coded transitions with ages that refresh every 30 seconds. It retains only the latest 32 timestamp-only records in local widget settings, survives shell restarts, and runs without a helper. Nothing is inferred from calendars, projects, apps or notifications; no account, telemetry, or network use.

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
07eade2
Scanned
1 week ago
  • high destructive_filesystem scripts/rig-verify.sh:78

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME && mkdir -p /tmp/$NAME && tar xzf /tmp/$NAME.tgz -C /tmp/$NAME' || exit 3
  • high destructive_filesystem scripts/rig-verify.sh:99

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME /tmp/$NAME.tgz >/dev/null 2>&1
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n" or raw[12:16] != b"IHDR":

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
07eade2
Reviewed
1 week ago

The shipped plugin is a self-contained QML bar widget that only stores timestamped arrive/leave records in Omarchy's inline widget settings; the runtime code (BarWidget.qml, Panel.qml, Model.js) performs no network access, no subprocess execution, and no filesystem writes outside the shell's own settings API. The deterministic scan's high-risk findings are false positives: the `rm -rf` operations in scripts/rig-verify.sh are developer-only rig tooling that runs against a temporary directory on a remote CI container, and the octal/hex escape in c43-omarchy-marketplace-presentation.sh is a PNG magic-byte check inside a vendored gate script, not executable plugin code. The only minor note is that the repository ships a large vendored gate-lane and rig tooling, but none of it is invoked by the plugin at install or runtime.

  • scripts/rig-verify.sh contains `rm -rf` on /tmp paths, but it is developer/CI rig tooling that never ships to or runs on an end-user machine; the plugin's runtime entry points (BarWidget.qml, Panel.qml, Model.js) contain no destructive operations.
  • The vendored scripts/gates/ directory is large and includes gate scripts with embedded examples of dangerous patterns, but these are development-time checks and are not part of the installed plugin runtime.
  • The plugin relies on Omarchy's inline widget-settings API for persistence; this is consistent with the manifest's privacy claims and no credential handling, network use, or hidden persistence was found.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jeremylongshore/omarchy-flow-boundary-entry --enable
Productivity #bar #quickshell

Flow Boundary

Flow Boundary banner

ko-fi

Flow Boundary marks the moment you enter or leave a focus block without handing your schedule, projects, or notifications to another service. Its Omarchy bar widget gives you explicit Arrive and Leave actions and a color-coded timeline of recent context changes, helping you close one task cleanly before opening the next and reconstruct where the day changed direction.

It does not inspect calendar events, project contents, or notification history. The bounded history is stored through Omarchy's own inline widget-settings API, so Flow Boundary opens no state pathname and needs no helper interpreter. There is no account, cloud sync, telemetry, or background network access.

Install

omarchy plugin add https://github.com/jeremylongshore/omarchy-flow-boundary-entry --enable

Use the panel's Arrive and Leave actions to create a local boundary record.

Verify

npm test
bash scripts/run-plugin-gates.sh
bash scripts/check-lane-freshness.sh
bash scripts/rig-verify.sh .
bash scripts/rig-render.sh . preview.png

Maintainers wanted

These plugins are growing, and we are looking for dependable Omarchy users who want to review issues, test releases, and keep a plugin healthy over time. Start with a small pull request or open a maintainer interest issue titled Maintainer interest. Tell us which plugin you use and how you want to help. Consistent contributors can earn maintainer responsibility.

License

MIT