Omahub
← All plugins
J

Loose Ends

by Jeremy Longshore

Loose Ends turns unfinished local Git work into a quiet local Omarchy bar queue. Every five minutes it scans repositories under home for uncommitted edits, unpushed commits, old stashes, detached heads, and interrupted rebases, merges, cherry-picks, or bisects. It surfaces interrupted work urgently, otherwise oldest first. It makes no network calls and does not modify repositories. Discovery and Git reads are time and size bounded; if a cap is reached, the panel clearly says the scan is partial.

Security review

Potentially dangerous behavior detected · 5 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
ffead99
Scanned
1 week ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
ffead99
Reviewed
1 week ago

The plugin is a local-only Git scanner bar widget with no network access and no repository modification. The deterministic scan's high-risk flags are false positives: the destructive `rm -rf` commands live in developer/rig verification scripts that run only in an isolated container, not on a user's machine, and the obfuscation findings are legitimate test strings and PNG header checks. The shipped runtime (QML, Model.js, and the referenced scanner) is clean and bounded.

  • The `rm -rf` in scripts/rig-verify.sh is scoped to /tmp paths inside a disposable rig container and never runs during normal plugin use.
  • The hex/octal escape sequences flagged in tests and the c43 gate are benign test fixtures and a PNG magic-byte check, not obfuscated code.
  • The scanner binary (bin/loose-ends-scan) was not sampled, but the manifest and QML indicate it is a bounded, local-only process with no network calls.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jeremylongshore/omarchy-loose-ends-entry --enable
Productivity #bar #quickshell

Loose Ends

Loose Ends banner

ko-fi

The Git work you left unfinished, visible as a quiet queue on the Omarchy bar. Loose Ends scans local repositories under your home directory every five minutes and shows work worth returning to: stale uncommitted edits, unpushed commits, old stashes, detached heads, and interrupted Git operations.

It makes no network calls and does not intentionally modify repositories. Every Git command runs with optional locks disabled, repository-selected hooks and filesystem monitors disabled, and strict time and output limits. Repository discovery is bounded before sorting, uses no named temporary file, and reports when its safety cap makes a scan partial. The panel surfaces interrupted Git operations urgently, then orders ordinary loose ends oldest first so you can decide what to finish, push, or discard.

To scan a narrower tree, set OMARCHY_LOOSE_ENDS_ROOT in the graphical session environment before starting the Omarchy shell. The default remains $HOME.

Install

omarchy plugin add https://github.com/jeremylongshore/omarchy-loose-ends-entry --enable

Middle-click the pill to refresh. The plugin also supports the normal Omarchy panel commands: open, close, toggle, and refresh.

What counts as a loose end

Signal Why it appears
Uncommitted changes An edit has been sitting long enough to be forgotten.
Unpushed commits Finished locally, not yet safely shared.
Old stash A deferred thought that deserves a decision.
Detached HEAD Easy to lose work after a checkout.
Rebase, merge, cherry-pick, bisect An explicitly interrupted Git operation.

Fresh changes stay visually quiet. Stale work and interrupted operations are emphasized. This is a peripheral reminder, not a task manager.

Verify

npm test
bash scripts/run-plugin-gates.sh
bash scripts/check-lane-freshness.sh
bash scripts/rig-verify.sh .
bash scripts/rig-render.sh . preview.png

Maintainers wanted

These plugins are growing, and we are looking for dependable Omarchy users who want to review issues, test releases, and keep a plugin healthy over time. Start with a small pull request or open a maintainer interest issue titled Maintainer interest. Tell us which plugin you use and how you want to help. Consistent contributors can earn maintainer responsibility.

License

MIT