Omahub
← All plugins
O

Popup Terminal

by Omarchy Community

Lightweight popup terminal for the Omarchy status bar with command history, Polkit graphical authentication, and working directory persistence.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
e0269da
Scanned
1 month ago
  • medium sudo bin/sudo:2

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo wrapper
  • medium sudo bin/sudo:3

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo calls to pkexec to trigger Polkit graphical authentication.
  • Docs external_hosts README.md:36

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/Rizmi/omarchy-terminal-plugin.git \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e0269da
Reviewed
1 month ago

This is an intentionally user-facing popup terminal: commands typed by the user run with normal user privileges, and `sudo` is routed through a `pkexec` wrapper that still requires Polkit authorization. The deterministic scan's medium findings are explained by the README's `git clone` install instruction and the documented sudo-to-pkexec wrapper, not by hidden elevation or malicious behavior. No obfuscation, install-time destructive actions, credential theft, persistence, or unauthorized network activity were found.

  • As with any terminal widget, the plugin executes arbitrary shell commands entered by the user, so abuse would require the user to run a malicious command; this is the plugin's documented purpose.
  • The `bin/sudo` wrapper can trigger Polkit elevation for privileged commands, but authentication is required and the behavior is clearly described in the README and manifest.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Rizmi/omarchy-terminal-plugin --enable
Widgets #bar #system

Popup Terminal — Omarchy Bar Widget

A lightweight, persistent popup terminal plugin for the Omarchy Linux desktop status bar with command history, Polkit graphical authentication, and working directory persistence.


<p align="center"> <img width="537" height="537" alt="Popup Terminal Preview" src="https://imglink.cc/cdn/hiOwt5ysrb.png" /> </p>

Features

  • Fast & Lightweight: Clean QML popup integrated seamlessly into Omarchy's status bar.
  • Working Directory Persistence: Automatically tracks and preserves your active working directory across commands (including cd).
  • Native Polkit/Sudo Support: Seamlessly routes sudo commands through Omarchy's graphical authentication dialog (pkexec).
  • Command History: Use ↑ and ↓ arrow keys to quickly cycle through previous commands.
  • Clean UI & Auto-Scrolling: Color-coded prompts, command block dividers, execution status indicator, and automatic output scrolling.
  • Omarchy Theme Integration: Uses Omarchy's native Style and Color tokens matching your active system theme.

Installation

Option 1: Using omarchy plugin (Recommended)

omarchy plugin add https://github.com/Rizmi/omarchy-terminal-plugin.git --enable

Option 2: Manual Installation

  1. Clone the repository into your Omarchy plugins directory:

    git clone https://github.com/Rizmi/omarchy-terminal-plugin.git \
      ~/.config/omarchy/plugins/io.github.rizmi.terminal
    
  2. Validate and enable the plugin on your status bar:

    omarchy plugin validate ~/.config/omarchy/plugins/io.github.rizmi.terminal
    omarchy plugin enable io.github.rizmi.terminal --section right
    
  3. Reload the shell if necessary:

    omarchy restart shell
    

Removal

omarchy plugin disable io.github.rizmi.terminal
rm -rf ~/.config/omarchy/plugins/io.github.rizmi.terminal
omarchy restart shell

Usage & Shortcuts

  • Click icon or use IPC (omarchy shell io.github.rizmi.terminal toggle) to open/close the popup.
  • Enter: Run command
  • Kill button: Kill running command
  • ↑ / ↓: Navigate command history
  • Esc: Close popup
  • Clear button: Clear terminal output history

Configuration

You can customize dimensions directly in your ~/.config/omarchy/shell.json:

{
  "id": "io.github.rizmi.terminal",
  "width": 440,
  "maxHeight": 560
}

License

MIT License © 2026 Omarchy Community