Omahub
← All plugins
S

Snipper

by slomo-b

Snipping tool with OCR — a bar pill that opens a keyboard panel to select a screen area and copy its text or image.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
e961207
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:138

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/slomo-b/omarchy-snipper && ls
  • Docs sudo README.md:39

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S tesseract-data-deu`, then set `lang` to

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e961207
Reviewed
1 month ago

The plugin is a screen-snipping bar widget that runs local commands (grim, convert, tesseract, wl-copy) and writes only to ~/.local/state/snipper/. The deterministic scan flagged README examples (git clone and sudo pacman) that are documentation only, not part of the executable code. No obfuscation, network access, or destructive behavior was found in the QML sources.

  • The README includes a `sudo pacman -S tesseract-data-deu` example for optional German OCR support; this is a user-initiated install step, not executed by the plugin.
  • The README's `git clone` snippet is a review suggestion, not part of the plugin runtime.
  • The plugin runs shell commands via bar.run and Process, but all commands are local and use fixed paths; no user-controlled input is passed to the shell.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/slomo-b/omarchy-snipper --enable
Productivity #bar #quickshell #system

Snipper — Omarchy Bar Widget (screen snip + OCR)

A fully standalone Omarchy shell bar widget: a small pill in the top bar (clicking it opens a polished keyboard panel). The panel is the whole app — capture, OCR and clipboard run right there, no separate process.

Pick a screen area → its text (or image) is copied to the clipboard via local OCR (tesseract).

This repo is the Omarchy plugin only. The Windows desktop app (Tauri / SvelteKit) lives in the separate slomo-b/snipper repo and is unaffected by this plugin.

Features

  • Snip it! (panel button): select an area on the full-screen overlay — the panel grabs the screen with grim, you drag a box, the region is cut via ImageMagick and recognized with tesseract. Text lands on the clipboard (wl-copy) and appears in the panel. If no text is recognized, the image is copied instead.
  • Text / image mode: toggle the extraction mode in the panel header (text = OCR, image = copy the raw region).
  • Copy text: re-copies the latest result to the clipboard (via wl-copy).
  • History: the last entries (persisted in ~/.local/state/snipper/history), scrollable inside a fixed area; click an entry to re-copy it. "Clear history" empties it.
  • Localized UI: follows the system locale (de* → German, otherwise English). The call-to-action stays "Snip it!" in both.

Built on Omarchy's standard bar-widget + KeyboardPanel structure.

Requirements (present on Omarchy)

  • grim — screen capture (Wayland)
  • convert (ImageMagick) — crop the selected region
  • wl-copy — Wayland clipboard
  • tesseract (OCR) — engine language via the panel lang (eng default)
  • omarchy-notification-send — status notifications (Omarchy bin)
  • German OCR: sudo pacman -S tesseract-data-deu, then set lang to eng+deu / deu in the panel.

Install

omarchy plugin add https://github.com/slomo-b/omarchy-snipper.git --enable

The marker is added to the center section (defaultSection). Move it with omarchy bar move.

Remove

omarchy plugin remove io.github.slomo-b.snipper

Removal removes the bar widget and its panel from the shell. The plugin keeps no system state: it only ever wrote temporary files under ~/.local/state/snipper/, which it does not delete (history may be cleared from the panel; the leftover state directory can be removed by hand if you want it gone entirely).

Keyboard shortcut (optional, host-specific)

Like any bar widget, the pill toggles the panel on click. To open/toggle it with a global key (e.g. SUPER + ALT + S), add a Hyprland binding on the host:

-- ~/.config/hypr/bindings.lua
SUPER+ALT+S = omarchy-shell shell toggle io.github.slomo-b.snipper '{}'

Repo layout

omarchy plugin add needs manifest.json at the repo root — that is the case here, so the repo is directly installable:

omarchy-snipper/
├── manifest.json      # plugin manifest (schemaVersion 1, bar-widget)
├── BarWidget.qml      # bar pill (renders the SVG cuttermesser icon, tinted)
├── Panel.qml          # the full app: snip overlay, OCR, clipboard, history
└── assets/
    └── cutter-knife.svg

Develop / validate

omarchy plugin validate .            # schema check (exit 0 = ok)
# local hot development:
cp -r . ~/.config/omarchy/plugins/io.github.slomo-b.snipper/
omarchy-shell shell rescanPlugins
# NOTE: after editing the QML, a full `omarchy restart shell` is needed for
# bar-widget changes to show (hot reload alone does not rebuild the bar pill).

Notes

  • On Wayland only one item sits on the clipboard at a time; text wins over the image. If no text is recognized, the image is copied instead.
  • The plugin is self-contained on Omarchy; it does not run or require the Tauri app.

Security & trust

Omarchy runs bar plugins as unsandboxed code inside the long-lived omarchy-shell process, with your user rights. That is how the platform works — a sandbox would remove the screen/clipboard/OCR access the tool needs. To make trusting this plugin easy, here is exactly what it does (so you can review before enabling):

External commands it runs — all local, no network:

  • grim — capture the current screen
  • convert (ImageMagick) — crop the selected region
  • tesseract — OCR, runs on your machine (text never leaves it)
  • wl-copy — put text/image on the clipboard
  • omarchy-notification-send — status notifications (via the bar)

What it touches:

  • Only files under ~/.local/state/snipper/ (history, a temp capture, a log).
  • No system directories, no /etc, no services, no autostart.

What it does NOT do:

  • No outbound network requests — no telemetry, no data leaves your machine. Recognized text is rendered as plain text (never auto-interpreted as rich text), so screen content cannot make the UI fetch a remote resource.
  • No sudo, no system changes, no persistent installs.
  • It never reads your secrets, keys, or tokens.
  • Recognized/pasted text is handed to child commands over stdin, never as a command-line argument — so it never appears in the world-readable /proc/<pid>/cmdline and cannot inject shell commands. Every file the plugin writes is created with umask 077 (owner-only).

Review before enabling (the whole plugin is ~5 small files):

git clone https://github.com/slomo-b/omarchy-snipper && ls

Releases are exact git tags (e.g. v0.3.1), so a reviewed version can be pulled and compared. This mirrors Omarchy's own guidance: inspect the few files, then run omarchy plugin add.

License

MIT. See LICENSE.