Omahub
← All plugins
J

Foundry

by Jeremy Longshore

Foundry creates a local Omarchy bar-widget draft from your ID, name, and 500-char description. It generates identity, matched copy, a unique SVG banner, offline tests, CI, security, and install/removal guidance. Its descriptor-pinned generator stages privately and publishes only to a new target, never overwriting it. The draft begins UNPROVEN. Validate and capture real-shell evidence before release. Foundry never installs, enables, commits, pushes, publishes, calls a network service, or uses AI.

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
3149654
Scanned
1 week ago
  • high destructive_filesystem scripts/rig-verify.sh:79

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME && mkdir -p /tmp/$NAME && tar xzf /tmp/$NAME.tgz -C /tmp/$NAME' || exit 3
  • high destructive_filesystem scripts/rig-verify.sh:100

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME /tmp/$NAME.tgz >/dev/null 2>&1
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n" or raw[12:16] != b"IHDR":

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
3149654
Reviewed
1 week ago

The plugin is a local scaffold generator that runs only user-initiated commands, with strict input validation, atomic writes, and no network or AI use. The deterministic scan flagged destructive commands in development-only rig scripts that are not part of the installed runtime, and the obfuscation finding is a false positive (PNG header detection).

  • Destructive `rm -rf` commands in scripts/rig-verify.sh are dev/rig tooling, not executed by the installed plugin; they only clean /tmp staging dirs on a remote test rig.
  • The octal/hex escape snippet flagged as obfuscation is actually a PNG signature check in a validation gate, not obfuscated code.
  • Plugin runtime (QML + Perl helper) only reads a receipt and generates drafts; no privileged operations, network, or persistence outside the user-specified workspace.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jeremylongshore/omarchy-foundry-entry --enable
Developer Tools #bar #quickshell #security

Foundry

Foundry banner

Foundry turns one Omarchy bar-widget idea into a reviewable local project. The starter arrives with exact marketplace copy, its own deterministic visual identity, offline tests, pinned CI, security guidance, and an honest UNPROVEN receipt. Foundry is a scaffold and proof boundary, not an autonomous agent, installer, Git client, or publisher.

What it does

  • Requires a namespaced plugin id, safe display name, and exactly 500 characters of specific marketplace copy.
  • Pins the allowed root, workspace, and private staging tree by open directory descriptor so a live path swap cannot redirect its writes.
  • Publishes the complete draft with stock coreutils' atomic no-clobber move, so a concurrent creator or planted target cannot be merged or overwritten.
  • Creates a manifest, accessible QML entry point, pure model, offline tests, contract checks, README, security notes, license, pinned CI, and a named SVG banner whose palette is derived from that plugin identity.
  • Reports UNPROVEN until separate validation and real-shell evidence exist.
  • Never installs, enables, commits, pushes, publishes, calls AI, sends telemetry, or reaches the network.

Runtime dependencies

The installed helper uses Perl modules shipped by Arch's core Perl package and GNU coreutils, both present on stock Omarchy. The panel uses Omarchy's QML and Quickshell runtime. Node is development-only and never runs in the graphical session.

Create a draft

Write one single-line, plugin-specific description using the complete 500 character marketplace allowance. Choose a workspace inside your home directory, or set FOUNDRY_ALLOWED_ROOT to an explicit development root. Review a dry run before creating anything.

bin/omarchy-foundry create \
  --workspace "$HOME/Projects" \
  --id io.github.you.hello-widget \
  --name "Hello Widget" \
  --description-file "$HOME/hello-widget-marketplace-copy.txt" \
  --dry-run

The description file may contain one trailing newline, but the description itself must be exactly 500 characters. Remove --dry-run only after reviewing the target path. The generated project is not installed. Run its tests, omarchy plugin validate ., and qmllint *.qml; then inspect every file before creating a Git repository or installing the plugin.

Install Foundry

omarchy plugin add https://github.com/jeremylongshore/omarchy-foundry-entry --enable

The panel displays a receipt and the terminal command. It does not expose an arbitrary command field, because Omarchy plugins share the long-running shell process and run with the current user permissions.

Remove Foundry

omarchy plugin remove io.github.jeremylongshore.foundry

Development

npm test
npm run test:race
npm run test:mutation
npm run audit
bash scripts/run-plugin-gates.sh .
bash scripts/rig-verify.sh .
bash scripts/rig-render.sh . preview.png

The final two commands use the Buzz production-boundary rig. Static validation is not a render, and a missing rig is UNPROVEN, not a pass. npm run test:e2e also creates a disposable project through the shipped generator, installs that project locally on the rig, shadows Node, and loads it in a real Omarchy shell.

Proof model

Foundry deliberately does not turn a generated draft green. The generated receipt says UNPROVEN; validation, live-shell loading, screenshot inspection, clean exact-SHA CI, and marketplace review belong to the generated repository's own release lane. This prevents a template's evidence from being laundered into evidence for a different plugin.

Security

See SECURITY.md for the write boundary, rejected inputs, runtime capabilities, and vulnerability reporting guidance.

Maintainers wanted

These plugins are growing, and we are looking for dependable Omarchy users who want to review issues, test releases, and keep a plugin healthy over time. Start with a small pull request or open a maintainer interest issue titled Maintainer interest. Tell us which plugin you use and how you want to help. Consistent contributors can earn maintainer responsibility.

License

MIT.