Omahub
← All plugins
R

Omarchy Codex

by Rooke Poole

Launch and diagnose graphical OpenAI Codex, or review its releases, from the Omarchy bar.

Security review

Review recommended · 15 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
67b3dbc
Scanned
4 weeks ago
  • Downloads or connects to an external HTTP(S) host.

    git clone --quiet --depth 1 --branch quattro https://github.com/basecamp/omarchy.git "${omarchy}"
  • medium external_hosts tests/test-upstream.sh:12

    Downloads or connects to an external HTTP(S) host.

    curl -fsSL "https://persistent.oaistatic.com/codex-app-prod/linux/deb/dists/stable/main/binary-${repository_arch}/Packages")"
  • medium package_manager …/workflows/test.yml:17

    System package manager operation.

    apt-get install -y desktop-file-utils jq shellcheck
  • medium package_manager …/workflows/release.yml:18

    System package manager operation.

    apt-get install -y desktop-file-utils jq shellcheck
  • medium sudo uninstall.sh:11

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -R --noconfirm omarchy-codex
  • medium sudo install.sh:44

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo is required"
  • medium sudo install.sh:76

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed --noconfirm base-devel git libarchive
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y desktop-file-utils jq shellcheck
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y desktop-file-utils jq shellcheck
  • Docs external_hosts README.md:10

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/rookepoole/omarchy-codex.git
  • Docs external_hosts README.md:37

    Downloads or connects to an external HTTP(S) host.

    curl -fLO https://github.com/rookepoole/omarchy-codex/releases/download/v0.1.10/omarchy-codex-0.1.10.tar.gz
  • Docs external_hosts README.md:38

    Downloads or connects to an external HTTP(S) host.

    curl -fLO https://github.com/rookepoole/omarchy-codex/releases/download/v0.1.10/omarchy-codex-0.1.10.tar.gz.sha256
  • Docs package_manager docs/verification-0.1.0.md:28

    System package manager operation.

    Pacman install and package ownership
  • Docs package_manager CHANGELOG.md:69

    System package manager operation.

    pacman install, dynamic linkage, and sandboxed graphical startup in a clean Arch container.
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo dependency installation

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
67b3dbc
Reviewed
4 weeks ago

The plugin is a well-documented, transparent integration that packages OpenAI's official ChatGPT/Codex desktop app for Arch and adds a bar widget. The deterministic scan flags are mostly documentation, CI, and expected sudo-based package operations; the actual runtime code is conservative, checksum-pinned, and avoids remote code execution or credential handling. The main residual risk is that installation runs privileged pacman/makepkg operations and modifies the user's Hyprland keybindings, but these are clearly disclosed and guarded.

  • install.sh runs sudo pacman and makepkg with --install, which is a privileged system-level operation; this is expected for an Arch package installer but should be reviewed by the user before running.
  • scripts/manage-keybinding.sh edits ~/.config/hypr/bindings.lua and replaces the Super+Shift+A shortcut; it has idempotence, marker validation, and rollback logic, but it does modify user configuration.
  • The installer downloads the OpenAI .deb from persistent.oaistatic.com during build; checksums are pinned in PKGBUILD and verified by makepkg, but the download is a large third-party binary.
  • The QML panel runs unsandboxed with user permissions and executes omarchy-codex commands, but only after explicit user action and only for launch/update/doctor/docs operations.
  • The deterministic scan's medium findings are mostly in README/docs/CI and represent documentation or test-only operations, not runtime risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rookepoole/omarchy-codex --enable
Developer Tools #quickshell #launcher #ai

Omarchy Codex

The real graphical OpenAI Codex experience on Omarchy—not a terminal UI and not a web-app shortcut.

This project repackages OpenAI's official Linux ChatGPT desktop application, which includes Codex, into a native Arch package and connects it to Omarchy's app launcher and Super + Shift + A shortcut.

Install

git clone https://github.com/rookepoole/omarchy-codex.git
cd omarchy-codex
./install.sh

Each GitHub release also includes a checksumed, payload-free installer bundle. It contains this integration code—not OpenAI's proprietary application—and downloads the pinned official package during installation.

Then open Codex from Omarchy's Apps menu or press Super + Shift + A. Choose Continue to sign in and complete the ChatGPT browser login. No API key is created or required.

To open the current repository directly in the same graphical app, choose Work mode and run:

chatgpt .

omarchy-codex open . is the explicit equivalent. Both use the app's project deep link; neither opens the terminal Codex interface.

The first build downloads about 390 MB from OpenAI and installs about 1.3 GB. The downloaded .deb is checksum-verified by makepkg before packaging.

Update an existing installation

omarchy-codex update does not install updates. It only opens the releases page so you can review the new version. To update to the current release, run:

mkdir -p ~/Downloads/omarchy-codex-0.1.10-update
cd ~/Downloads/omarchy-codex-0.1.10-update
curl -fLO https://github.com/rookepoole/omarchy-codex/releases/download/v0.1.10/omarchy-codex-0.1.10.tar.gz
curl -fLO https://github.com/rookepoole/omarchy-codex/releases/download/v0.1.10/omarchy-codex-0.1.10.tar.gz.sha256
sha256sum -c omarchy-codex-0.1.10.tar.gz.sha256
tar -xzf omarchy-codex-0.1.10.tar.gz
cd omarchy-codex-0.1.10
./install.sh
reboot

The checksum command must report OK before you run the installer. Updating preserves the ChatGPT login, Codex settings, and optional Omarchy panel.

Optional Omarchy panel

Omarchy Quattro users can add the companion bar panel after installing the app:

  1. Open Setup → Plugins → Add.
  2. Paste https://github.com/rookepoole/omarchy-codex.
  3. Confirm the repository, enable Omarchy Codex, and choose its bar position.

The panel shows the installed integration, pacman package, and OpenAI app versions. It provides explicit actions to launch Codex, review available releases, run diagnostics, or read the documentation. The panel depends on Omarchy Quattro's shell plugin API and the separately installed omarchy-codex command.

Like every Omarchy shell plugin, it runs unsandboxed with your user permissions. Its QML source only checks omarchy-codex version and starts an action after you explicitly choose it.

Removing the panel does not uninstall the app, change its settings, touch ChatGPT authentication, or remove the existing shortcut. Use Setup → Plugins → Remove and choose Omarchy Codex.

What it changes

  • Installs OpenAI's graphical app as the pacman package omarchy-codex.
  • Replaces Omarchy's default Super + Shift + A ChatGPT web shortcut with the desktop app.
  • Adds a native Codex application entry.
  • Uses native Wayland automatically on Omarchy to avoid current Mesa/XWayland GPU crashes.
  • Preserves ChatGPT sign-in data across upgrades and normal uninstall.

It does not install Codex CLI, request an API key, modify ~/.codex/auth.json, or commit/redistribute OpenAI's application binary.

Diagnostics and rendering

omarchy-codex doctor
omarchy-codex version

Force native Wayland explicitly with:

omarchy-codex rendering wayland

Return to Omarchy's automatic behavior with:

omarchy-codex rendering auto

Fully quit and reopen Codex after changing rendering mode.

If the app says 100% zoom but the entire native-Wayland interface is oversized, set the Electron device scale to 1 without returning to XWayland:

omarchy-codex scale 1
pkill -f '/usr/lib/chatgpt/ChatGPT' 2>/dev/null || true
omarchy-codex launch

Other fractional values such as 1.25 and 1.5 are supported. Restore automatic display scaling with omarchy-codex scale auto.

If a previous build crashes during GPU initialization, recover without opening the app first:

omarchy-codex rendering wayland
pkill -f '/usr/lib/chatgpt/ChatGPT' 2>/dev/null || true
omarchy-codex launch

Uninstall while preserving sign-in data:

./uninstall.sh

The app uninstaller does not remove the optional Quattro panel. Remove each component with its own command when you want both gone.

Support boundary

OpenAI currently supports the Linux preview on Ubuntu, Debian, and Fedora—not Arch. This is an independent Omarchy compatibility package, not an OpenAI product and not an official Arch package. The app itself is downloaded from OpenAI's versioned package repository during the local build.

The packaging and Omarchy integration code in this repository is MIT licensed. OpenAI's downloaded application remains under its own terms.