Omahub
← All plugins
R

Omarchy X-Ray

by RandaZraik

Trace any window, process, service, container, port, file, or device to the process behind it, how it started, and what it is using.

Security review

Potentially dangerous behavior detected · 11 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
520c1da
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
520c1da
Reviewed
1 month ago

The deterministic scan's high rating is driven by test and CI files—`systemd-run` in system tests, `sudo apt-get` in GitHub Actions, and escaped byte strings in test fixtures—none of which run when the plugin is installed. The sampled runtime code is a local system inspector that reads /proc and standard tools, redacts sensitive values, and guards process control behind identity checks and user confirmation. The main residual risk is the plugin's intentionally powerful same-user process actions and optional window preview capture, which should remain clearly user-initiated.

  • The high-severity deterministic findings are false positives for install-time risk: they refer to test fixtures and CI setup, not to code executed on a user's desktop.
  • The plugin can pause, resume, terminate, and restart same-user processes and user services/containers, so these actions must keep the documented confirmation and ownership checks.
  • Optional window previews capture screen content locally; the code appears to restrict permissions and exclude previews from exports, but this privacy-sensitive feature should be clearly disclosed.
  • No network exfiltration, hidden persistence, or obfuscated runtime behavior was found in the sampled executable code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/RandaZraik/omarchy-xray --enable
System #bar #quickshell #system

Omarchy X-Ray

A live system inspector for the Omarchy bar.

Trace a window, process, service, container, port, file, or device to the exact process behind it—then see how it started, what it is using, and the actions you can take in one focused view.

<p align="center"> <img src="preview.png" alt="Omarchy X-Ray inspecting an application" width="100%"> </p>

Search for an app, choose a window, or enter a PID, port, file, service, container, or device. X-Ray follows it to the exact process and brings together its process tree, performance, connections, open files, device use, and runtime details.

Install

omarchy plugin add https://github.com/RandaZraik/omarchy-xray --enable

Click the X-Ray icon in the Omarchy bar and choose what to inspect:

Target Example
Running application ghostty
Process 4242 or pid:4242
systemd service or scope service:user:demo.service
Docker, Podman, or nerdctl container container:docker:postgres
Listening or connected port :5173
Open file /path/to/file
Device activity microphone, camera, audio, or gpu
Window Use the window picker

Features

  • Finds the exact process tree behind the selected target.
  • Opens the tree as a searchable evidence table with full redacted commands, PID, user, state, threads, memory, total-capacity CPU, and disk read/write rates. Keep lineage order or sort and reverse by CPU, memory, disk activity, and individual columns.
  • Keeps open apps, processes, ports, and system targets in a searchable side browser, so you can inspect several matches without rebuilding the search.
  • Shows how it started through sessions, shells, systemd units, supervisors, and containers.
  • Shows CPU, memory, disk activity, connections, files, locks, devices, and runtime security together.
  • Links noteworthy activity to its source and the next useful check.
  • Optionally captures a private local preview of the selected window.
  • Opens complete lists in focused drawers while keeping the important details on one screen.
  • Focuses windows, reveals files, opens a terminal in context, and can pause, resume, or terminate same-user processes. It can also restart targets owned by a user service or supported container runtime. Terminate and restart require confirmation, and every process action rechecks identity first.
  • Exports private .xray.zip reports for offline inspection and comparison.

Controls

  • Ctrl+K — choose another target
  • Ctrl+R — refresh now
  • Ctrl+P — pause or resume the inspected process
  • Ctrl+Shift+X — terminate the inspected process (confirmation required)
  • Esc — close the topmost target browser, drawer, confirmation, or X-Ray
  • Click a process — inspect that process and its subtree
  • Click VIEW ALL in a card — open the complete list

X-Ray settings control the refresh interval, timeline window, and optional window preview. X-Ray works with partial system capabilities and clearly labels information it could not read.

Privacy

X-Ray runs locally, has no analytics, and never requests elevated privileges. Environment variable names may be shown, but their values are never retained, displayed, or exported. Optional window previews stay in a private temporary directory and are excluded from exported reports. Reports are redacted before export or copy.

Omarchy's standard tools provide more detail when available, including hyprctl, grim, slurp, pw-dump, journalctl, systemctl, container runtimes, and systemd-inhibit.

Update or remove

omarchy plugin update io.github.randazraik.xray
omarchy plugin remove io.github.randazraik.xray