Omahub
← All plugins
T

Pebble

by thecdrz

A quiet penguin who lives in your Omarchy bar — wanders, sleeps, and collects treasures.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
80a5cc1
Scanned
1 week ago
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n" + chunk(b"IHDR", ihdr) + chunk(b"IDAT", zlib.compress(bytes(raw), 9)) + chunk(b"IEND", b"")

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
80a5cc1
Reviewed
1 week ago

The plugin is a local bar companion with no network behavior, no install-time scripts, and no destructive commands. The deterministic 'obfuscation' finding is a false positive: tools/render-props.py is simply generating PNG files using zlib/struct. The only mild note is the optional cursor-position helper, which is local, parent-bound, and gated by a user preference.

  • The optional Curious cursor helper (bin/pebble-cursor) samples the global Hyprland cursor position; data stays local and is not exfiltrated, but this is slightly broader than the README's 'no global input monitoring' wording suggests.
  • The plugin runs unsandboxed in the Omarchy shell process, as documented in PRIVACY.md; this is inherent to the platform rather than a defect in this plugin.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/thecdrz/omarchy-pebble --enable
Widgets #bar #quickshell #workspaces

Pebble

A quiet penguin who lives in your Omarchy bar.

Curious, slightly clumsy, calm when ignored, and entirely local. He is the only companion this plugin ships.

Pebble on the Omarchy bar

Install

omarchy plugin add https://github.com/thecdrz/omarchy-pebble.git --enable

What Pebble does

  • Wanders the full horizontal bar, including behind the center clock.
  • Sleeps, stretches, preens, slips, belly-slides, and on Lively/playful outings may run and leap.
  • Finds leaves, pebbles, and stars, then keeps them by the nest.
  • Remembers bond milestones and collection progress between sessions.
  • Quiet, Normal, and Lively energy.
  • No network, analytics, global input monitoring, or cloud account.

Interaction

  • Hover him for a hand cursor and a small stir or look.
  • Left-click to wake him, then for hops and other small antics.
  • Right-click for the local PEBBLE panel.
  • Middle-click to send him walking home.
  • Snooze 1h pauses outings; left-click wakes him early.
  • The panel controls Energy, Reduced motion, and Curious cursor independently.

Defaults are Normal, Full motion, and Curious cursor on. Quiet rests at the nest; Lively may chase, run, leap, and show off. Circus stunts stay Lively. Reduced motion and cursor awareness can be changed without changing energy.

Care

PEBBLE panel

The first visit explains the click gestures. The panel then shows status, latest moment, bond milestones, collections, and energy controls in one card. State stays in ~/.local/state/omarchy/pebble/state.json and never leaves the machine.

See the animation

Studio reels from the same frames the plugin uses, enlarged for GitHub:

Waddle and return Tucked sleep
Pebble locomotion Pebble sleeping
Belly slide Slip and recover
Pebble belly slide Pebble slip and recover

Full frame sheet: docs/media/pebble-animation-sheet.png.

Compatibility

Horizontal top or bottom bars. Intentionally dormant on vertical bars. One Pebble on the focused monitor, with a brief handoff when focus moves between monitors. Logical layout is checked across 24–48 px bars, ultrawide displays, and fractional scales. See docs/COMPATIBILITY.md.

Remove

omarchy plugin remove io.github.thecdrz.pebble

Removal leaves the private journal in place so a later reinstall can resume. Delete ~/.local/state/omarchy/pebble/state.json only when you also want to reset him.

cp ~/.local/state/omarchy/pebble/state.json ~/pebble-state-backup.json
rm ~/.local/state/omarchy/pebble/state.json

Data contract: PRIVACY.md. Artwork: ASSET_LICENSES.md. Forward plan: docs/ROADMAP.md. Listing assets: docs/MARKETPLACE.md.

License

MIT