Omahub
← All plugins
P

Plugin Manager

by Peter Szarvas

Manage Omarchy shell plugins.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
b267f4d
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
b267f4d
Reviewed
1 month ago

The sampled code is a transparent plugin-management UI with no hidden network, persistence, obfuscation, or install-time side effects. Actions are dispatched through a fixed bash script with plugin IDs passed as quoted positional parameters, so no command injection path is apparent. The low rating reflects only the inherent destructive capability of managing plugins, which is user-initiated and confirmed.

  • The plugin can disable or remove other installed plugins without elevated privileges; this is its stated purpose but could alter the shell environment if misused.
  • The full clone branch of runPluginAction was partially truncated in the sampled file, so the exact command construction should be spot-checked before publication.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/peterszarvas94/omarchy-plugin-manager --enable
System #system

Omarchy Plugin Manager

Plugin Manager preview

Browse and manage installed Omarchy shell plugins from one bar panel.

Features

  • Browse built-in and third-party plugins
  • Search by plugin name or ID
  • Enable, disable, clone, and remove plugins
  • Open plugin interfaces and source directories
  • Rescan the plugin registry

Requirements

  • Omarchy with the Quattro plugin runtime
  • xdg-open for opening plugin directories
  • omarchy-launch-config-editor for editing plugin source directories

The plugin runs inside the existing omarchy-shell process. It does not start services, make network requests, require elevated privileges, or overwrite user configuration. Plugin actions use Omarchy's native omarchy-plugin-* commands.

Install

omarchy plugin add https://github.com/peterszarvas94/omarchy-plugin-manager.git --enable
omarchy bar move io.github.peterszarvas94.plugin-manager --section right

If necessary, rescan the plugin registry:

omarchy-shell shell rescanPlugins

Usage

Click the bar icon or summon the manager through shell IPC:

omarchy-shell shell summon io.github.peterszarvas94.plugin-manager '{}'

Use the search field to filter plugins. Arrow keys and Tab navigate; / focuses the search field; Escape closes the panel.

Optional Shortcut

Add this to ~/.config/hypr/bindings.lua:

o.bind("SUPER + CTRL + SHIFT + M", "Plugin Manager", "omarchy-shell shell summon io.github.peterszarvas94.plugin-manager '{}'")

The plugin does not install or overwrite keybindings automatically.

Remove

omarchy plugin disable io.github.peterszarvas94.plugin-manager
omarchy plugin remove io.github.peterszarvas94.plugin-manager

License

MIT. See LICENSE.