Omahub
← All plugins
R

Keeply

by Rolf Koenders

Search and browse your Keeply bookmarks from the Omarchy menu bar.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
593133a
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:32

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/Keeply-link/keeply-omarchy.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
593133a
Reviewed
1 month ago

The plugin is a bookmark search widget that uses OAuth with PKCE and stores the access token in the system keyring via secret-tool. All network calls go to the official Keeply API, and the code includes proper safeguards like redirect blocking, response size caps, and state validation. The only flagged finding is a git clone command in the README, which is documentation and not executed by the plugin.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Keeply-link/keeply-omarchy --enable
Widgets #bar #quickshell

Keeply for Omarchy

Search and browse your Keeply bookmarks right from the Omarchy menu bar.

Click the bookmark icon, type to search, hit enter to open. Built for the moment you want a link you saved last week without alt-tabbing to a browser tab and digging through folders.

Screenshot

Keeply for Omarchy

Keyboard

With the panel open, type to search and results update as you type. Arrow keys move the highlighted result, Enter opens it (closing the panel), Escape closes the panel. Click a result with the mouse to open it directly.

What you get

  • Recent bookmarks: your latest saves, right under the search field, with no query needed
  • Full-text search: type to search title, URL, folder, and tags
  • One-click open: click or press Enter on any result to open it in your default browser
  • Folder and tag context: each result shows which folder it's in and its first few tags
  • Settings screen: click the gear icon to see your connected account and sign out

Install

omarchy plugin add https://github.com/Keeply-link/keeply-omarchy.git --enable

Or for local development:

git clone https://github.com/Keeply-link/keeply-omarchy.git
cd keeply-omarchy
ln -sfn "$PWD" ~/.config/omarchy/plugins/io.github.rolfkoenders.keeply
omarchy restart shell
omarchy plugin enable io.github.rolfkoenders.keeply

Setup

  1. Click the Keeply icon in your menu bar
  2. Click "Connect" to start the OAuth flow
  3. Sign in to Keeply in your browser and authorize the plugin
  4. You're connected, start searching your bookmarks

Configure

The bar icon defaults to the right side of the bar. To move it:

omarchy bar move io.github.rolfkoenders.keeply --section right

Remove

omarchy plugin remove io.github.rolfkoenders.keeply

This disconnects the plugin. Your saved token is removed from the system keyring on sign-out; if you remove the plugin while still signed in, clear it manually:

secret-tool clear application io.github.rolfkoenders.keeply

Requirements

  • Omarchy
  • Python 3 (for the OAuth flow's local callback server)
  • A Keeply account (free)

Privacy

  • Authentication uses OAuth with PKCE, so no client secret is ever stored, on your machine or anywhere else
  • Your access token is stored only in the system keyring (via secret-tool), never in a config file or log
  • All API calls go directly to https://api.keeply.tools

License

MIT, see LICENSE.