Omahub
← All plugins
S

Typist

by sanjuanjor

Types the current clipboard once with pause settings, a bar button, and a right-click config action.

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
2d2e0e3
Scanned
1 month ago
  • high persistence typist:69

    Registers scheduled or boot-time system tasks.

    systemd-run --user \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2d2e0e3
Reviewed
1 month ago

The plugin is a clipboard typer that runs a worker as a transient systemd user unit. The use of systemd-run is a standard way to run a background process and is not inherently malicious. The code is straightforward, uses only standard tools (wl-paste, ydotool, systemctl, jq), and does not perform any network, file, or destructive operations beyond what is documented. The deterministic scan's 'persistence' flag is a false positive in this context.

  • The plugin creates a transient systemd user unit, which is a form of persistence, but it is expected for a background worker and is properly managed with stop commands.
  • The worker reads the clipboard and types it, which could inadvertently expose sensitive data if the user triggers it while a sensitive field is focused, but this is user-initiated and clearly described.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/sanjuanjor/typist --enable
Productivity #bar

Typist

Typist types the current clipboard content once, with character-specific timing for plain text, newlines, and punctuation.

Install

Typist types through ydotool, which is not part of a stock Omarchy install and needs its daemon running:

omarchy pkg add ydotool
systemctl --user enable --now ydotool.service

Then add the plugin:

omarchy plugin add https://github.com/sanjuanjor/typist.git --enable

Without ydotoold running, ydotool cannot inject keys and nothing is typed; Typist reports this rather than failing quietly.

Remove

Stop it first if it is mid-run, then remove the plugin:

omarchy plugin remove io.github.sanjuanjor.typist

That deletes the plugin and its settings, which live on its shell.json entry. Two things it cannot remove, because they are not part of the plugin:

  • Any Typist keybindings you added to ~/.config/hypr/bindings.lua.

  • ydotool, if you installed it for this. Drop it only if nothing else uses it, since other tools share it:

    systemctl --user disable --now ydotool.service
    omarchy pkg drop ydotool
    

Removing the plugin folder mid-run does not stop a run already in flight. If typing is stuck and the bar button is gone, stop the unit directly:

systemctl --user stop io.github.sanjuanjor.typist.service

Use

  • Left click the bar button to type the clipboard once, or to stop a run in progress. The button highlights while typing.
  • Right click the bar button to pick a setting to change.
  • Use the hotkeys below if you want a keyboard shortcut.

Dependencies

  • python3
  • jq
  • wl-paste (from wl-clipboard)
  • ydotool, with ydotool.service enabled (for keyboard injection in Wayland)
  • libxkbcommon (to read the keyboard layout; already required by Hyprland)
  • systemd (the worker runs as a transient user unit)

Hotkeys

The bar button is enough on its own. For keyboard shortcuts, add these to ~/.config/hypr/bindings.lua (Hyprland reloads on save):

o.bind("SUPER + ALT + V", "Typist start", "$HOME/.config/omarchy/plugins/io.github.sanjuanjor.typist/typist start")
o.bind("SUPER + ALT + SHIFT + V", "Typist stop", "$HOME/.config/omarchy/plugins/io.github.sanjuanjor.typist/typist stop")
o.bind("SUPER + ALT + CTRL + V", "Typist config", "$HOME/.config/omarchy/plugins/io.github.sanjuanjor.typist/typist config")

typist toggle starts or stops in one binding, if you prefer a single key.

Configuration

Settings live on this widget's entry in ~/.config/omarchy/shell.json, the same place the Omarchy settings panel writes to. Changes take effect on the next run; no restart is needed.

Key Default Meaning
delayMs 35 Pause between ordinary keystrokes
newlineDelayMs 90 Extra pause after a line break
punctuationDelayMs 60 Extra pause after punctuation
startupDelayMs 250 Wait before typing starts, so a held hotkey can be released
maxClipboardBytes 65536 Clipboard contents larger than this are refused

Right click the bar button (or press the config hotkey) to get a menu listing just these settings with their current values; pick one to change it. The menu is built from the manifest schema, so it always matches what the plugin actually reads.

You can also set them from the command line:

omarchy bar set io.github.sanjuanjor.typist delayMs 50 --json

How it works

The clipboard is piped into the worker on stdin, so its contents never appear in /proc/<pid>/cmdline. Key codes come from a table built once from the keyboard layout alone, so no clipboard character is ever passed to another program as an argument either. The worker runs as a transient systemd user unit (io.github.sanjuanjor.typist.service), so stopping it never involves reading a process id from disk.

License

This project is licensed under the MIT License. See LICENSE for details.