Omahub
← All plugins
J

Workspace Storyboard

by Jeremy Longshore

Workspace Storyboard turns your Omarchy bar into a local map of live Hyprland workspaces. See workspace window counts and the active window title, then click or use Up/Down, Enter, or 1-9 to jump back into context. It retains a clearable, capped re-entry trail of workspace IDs, titles, application classes, and timestamps in private local state. It makes no network requests, and its Hyprland reads and panel payload are time and byte bounded. It stores 40 events and shows the newest eight locally.

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
fadbe46
Scanned
1 week ago
  • high destructive_filesystem scripts/rig-verify.sh:76

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME && mkdir -p /tmp/$NAME && tar xzf /tmp/$NAME.tgz -C /tmp/$NAME' || exit 3
  • high destructive_filesystem scripts/rig-verify.sh:97

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME /tmp/$NAME.tgz >/dev/null 2>&1
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n" or raw[12:16] != b"IHDR":

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
fadbe46
Reviewed
1 week ago

The deterministic scan's high findings are false positives: they reference `rm -rf` in scripts/rig-verify.sh, which is a developer-only verification script that runs in an isolated container on a remote rig, not part of the installed plugin. The plugin's runtime is a QML bar widget that reads local Hyprland state via bounded helper scripts and dispatches workspace switches with validated numeric IDs; it makes no network requests and stores capped local history. No malicious or destructive behavior was found in the sampled runtime files.

  • The high-severity destructive filesystem findings are confined to scripts/rig-verify.sh, a developer tool that cleans temporary directories on a remote SSH rig; they are never executed on a user's machine.
  • The bin/workspace-storyboard-scan and bin/workspace-storyboard-history helper scripts were not sampled, but the plugin's design and the project's own gates (e.g., c41, c42) enforce bounds, private state creation, and safe reads.
  • All user-facing QML text bindings use textFormat: Text.PlainText and validated numeric IDs, and workspace dispatch uses argv arrays without shell interpolation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jeremylongshore/omarchy-workspace-storyboard-entry --enable
Widgets #Hyprland #bar #workspaces

Workspace Storyboard

Workspace Storyboard banner

ko-fi

Workspace Storyboard turns the Omarchy bar into a visual map of where your work is happening. It shows live Hyprland workspaces, their window counts, the active window title, and a compact re-entry trail so returning to a project takes one click instead of a memory test.

It reads local Hyprland JSON only. Every Hyprland response and final payload is time and byte bounded. History is capped at 40 real transitions, suppresses unchanged polling duplicates, and serializes concurrent writers beneath retained state directory descriptors. Every workspace action revalidates a numeric ID. When no Hyprland session is available it returns a valid empty state.

Install

omarchy plugin add https://github.com/jeremylongshore/omarchy-workspace-storyboard-entry --enable

Click a workspace or recent entry to return to it. Keyboard users can use Up and Down to select, Enter to jump, 1 through 9 to jump directly, and C to clear the local re-entry trail.

Privacy and removal

Workspace Storyboard never sends workspace data over the network. It retains at most 40 workspace IDs, window titles, application classes, and timestamps in:

$XDG_STATE_HOME/omarchy-workspace-storyboard/history.jsonl

When XDG_STATE_HOME is unset, the path is ~/.local/state/omarchy-workspace-storyboard/history.jsonl. The directory is mode 0700 and the history and lock files are mode 0600. Use Clear Local History in the panel, press C while the panel is open, or run:

bin/workspace-storyboard-history --clear

Removing the plugin does not silently remove user state. Delete the containing omarchy-workspace-storyboard state directory if you also want to remove its empty history and lock files.

Verify

npm test
bash scripts/run-plugin-gates.sh
bash scripts/check-lane-freshness.sh
bash scripts/rig-verify.sh .
bash scripts/rig-render.sh . preview.png

The Buzz E2E lane loads the real plugin in the real Omarchy shell and opens it through IPC. Because the shared container uses headless Sway rather than a live Hyprland session, its scanner input and dispatch target are deterministic local hyprctl fixtures. Unit and smoke tests separately exercise the documented Hyprland JSON and fixed-argv dispatch contracts. The evidence does not claim a live Hyprland compositor where one was not present.

Maintainers wanted

These plugins are growing, and we are looking for dependable Omarchy users who want to review issues, test releases, and keep a plugin healthy over time. Start with a small pull request or open a maintainer interest issue titled Maintainer interest. Tell us which plugin you use and how you want to help. Consistent contributors can earn maintainer responsibility.

License

MIT