Omahub
← All plugins
S

Air Quality

by selenophilezh

US AQI pill in the bar with a pollutant breakdown popup, powered by Open-Meteo's free air quality API.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
663e5de
Scanned
1 month ago
  • medium external_hosts aqi-status.sh:26

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-time 4 --max-filesize 2000000 --limit-rate 512k "https://wttr.in/?format=j1" 2>/dev/null | head -c 2000000)
  • medium external_hosts aqi-status.sh:37

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-time 5 --max-filesize 2000000 --limit-rate 512k "https://air-quality-api.open-meteo.com/v1/air-quality?latitude=${lat}&longitude=${lon}&current=us_aqi&timezone=auto" 2>/dev/null | head
  • medium external_hosts Panel.qml:277

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "5", "--max-filesize", "2000000", "--limit-rate", "512k", "https://wttr.in/?format=j1"]

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
663e5de
Reviewed
1 month ago

The plugin fetches air quality data from well-known public APIs (Open-Meteo, wttr.in) using curl with bounded time and size limits. It reads a shared location file and uses a standard CLI to update it. No malicious or suspicious behavior was found; the external network calls are expected for its functionality.

  • External network requests to wttr.in and Open-Meteo are made, but they are legitimate and documented.
  • The plugin reads and writes location state via a standard CLI, which is consistent with its purpose.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/selenophilezh/omarchy-plugin-aqi --enable
Widgets #bar #system

Air Quality (Omarchy plugin)

A bar pill showing the current US AQI (Air Quality Index), color-coded by EPA category, with a popup panel breaking it down by pollutant (PM2.5, PM10, O₃, NO₂, SO₂, CO). Data comes from Open-Meteo's free Air Quality API — no API key required.

Air Quality plugin preview

Install

omarchy plugin add https://github.com/selenophilezh/omarchy-plugin-aqi

Then add it to your bar:

omarchy bar put io.github.selenophilezh.aqi --section right

(or edit ~/.config/omarchy/shell.json directly — see plugin docs).

Usage

  • Left-click the pill to open the breakdown panel.
  • Click the location name in the panel to search and set a new location (autocomplete via Open-Meteo's geocoding API). Click the ✕ to clear back to IP-based auto-detect.
  • Middle-click the pill to force an immediate refresh.
  • Right-click the pill to send the current reading as a desktop notification.

Location

This plugin reuses the same location as the built-in Weather plugin (~/.local/state/omarchy/settings/weather.json), so if you've already set a location for Weather, Air Quality picks it up automatically — no separate setup needed. Changing the location from either plugin's popup updates both. With no location configured, it falls back to IP-based auto-detect.

Configuration

Available via the plugin's settings form (or directly in shell.json's bar layout entry for this widget):

Key Type Default Description
refreshMinutes integer 15 How often to poll for a new reading (5–180 min).

Removal

omarchy plugin remove io.github.selenophilezh.aqi

Dependencies

curl and jq (both ship with Omarchy by default) — used for HTTP requests and the right-click notification script. No API key or account needed for Open-Meteo's free, non-commercial tier.

Privilege / network notes

This plugin makes outbound HTTPS requests to air-quality-api.open-meteo.com, geocoding-api.open-meteo.com (only while editing the location), and wttr.in (only as an IP-geolocation fallback when no location is configured). It reads (never writes directly to) Weather's location state file, and writes location changes only through the official omarchy-weather-location CLI. No elevated privileges are required.

License

MIT — see LICENSE.