Omahub
← All plugins
T

Raindrop Bookmarks

by Trevor Ramey

Fuzzy-search Raindrop.io bookmarks with cached cover images.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
9708884
Scanned
1 week ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
9708884
Reviewed
1 week ago

The plugin is well-engineered with strong security measures: the Raindrop token is stored with private permissions, all network requests use strict curl options (HTTPS only, no proxies, no redirects), cover URLs are validated to prevent SSRF, and ImageMagick runs under a restrictive policy. No malicious, obfuscated, or destructive code was found in the sampled files; the deterministic scan also reported no issues.

  • The Raindrop token is stored in plaintext at ~/.config/raindrop/token, which is expected for this type of plugin but could be a risk if the user's home directory is compromised.
  • The plugin runs unsandboxed with the user's permissions, as documented, so any vulnerability in the QML or helper scripts could affect the user's account.
  • Cover images are downloaded from arbitrary HTTPS URLs and processed with ImageMagick; while the policy and resource limits are restrictive, image-processing libraries can still have undisclosed vulnerabilities.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/treramey/omarchy-raindrop-bookmarks --enable
Productivity #quickshell #launcher

Raindrop Bookmarks for Omarchy

A keyboard-first Omarchy Quattro overlay for searching your Raindrop.io bookmarks. It keeps the last successful bookmark download for offline search, caches small cover thumbnails, and uses a letter tile when a bookmark has no usable cover.

Raindrop Bookmarks overlay showing saved bookmarks

Requirements

  • Omarchy Quattro
  • curl, jq, file, python3, timeout, and ImageMagick's magick

Install the required packages:

omarchy pkg add jq imagemagick python

Install

omarchy plugin add https://github.com/treramey/omarchy-raindrop-bookmarks.git --enable

Open the overlay and paste your Raindrop test token when prompted. The plugin links to the Raindrop integrations menu, verifies the token, and stores it at ${XDG_CONFIG_HOME:-$HOME/.config}/raindrop/token with private permissions.

To open the overlay from a terminal:

omarchy-shell shell toggle io.github.treramey.raindrop-bookmarks '{}'

To store the token elsewhere, set RAINDROP_TOKEN_FILE before you start Omarchy Shell.

Keyboard shortcut

To use Super + Shift + R, add this binding to ~/.config/hypr/bindings.lua:

hl.unbind("SUPER + SHIFT + R")
o.bind(
  "SUPER + SHIFT + R",
  "Raindrop bookmarks",
  "omarchy-shell shell toggle io.github.treramey.raindrop-bookmarks '{}'"
)

This replaces any existing Super + Shift + R binding. Change the key combination if you already use it, then reload Hyprland:

hyprctl reload

Use

  • Type to fuzzy-search titles, domains, tags, and URLs.
  • Use Up, Down, Page Up, and Page Down to move through results.
  • Press Enter to open the selected bookmark.
  • Press Escape to clear the query, then press it again to close the overlay.
  • Click outside the card to close it.
  • Use Refresh to request a manual bookmark refresh.
  • Use Reconnect when the saved token is no longer valid.

Data and security

Omarchy plugins run unsandboxed with your user permissions. This plugin:

  • reads credentials only from the configured Raindrop token file;
  • sends that token only to https://api.raindrop.io;
  • stores the last complete bookmark response under ${XDG_DATA_HOME:-$HOME/.local/share}/omarchy-shell/raindrop-bookmarks;
  • binds saved bookmarks to a local SHA-256 fingerprint of the token without storing the token in the snapshot;
  • downloads only HTTPS cover URLs on port 443 whose DNS answers are all public;
  • pins each cover request to its validated address, disables redirects and proxies, and enforces strict connection, transfer-time, and 5 MiB limits;
  • accepts only PNG, JPEG, GIF, and WebP covers and processes them under a restrictive ImageMagick resource and codec policy;
  • stores generated thumbnails under ${XDG_CACHE_HOME:-$HOME/.cache}/omarchy-shell/raindrop-bookmarks/covers; and
  • opens selected links through xdg-open.

The plugin never copies the token into its directory or exposes it in a process argument. During cover sync, it attempts to refresh thumbnails at least seven days old and deletes thumbnail files with a modification age greater than 30 days. These checks do not run on a timer. It refreshes bookmark data in the background when you open the overlay and the last successful sync is at least five minutes old. A failed refresh keeps the last successful snapshot.

To clear the saved bookmark snapshot and cover cache without removing your token, run clear-bookmarks from the installed plugin directory:

Stop Omarchy Shell before clearing data. Closing the overlay does not stop background syncs. The command deletes files, but does not clear bookmarks from a running shell's memory or prevent an active sync from recreating the files. Start Omarchy Shell again when finished. Opening the plugin can download the bookmarks again while the token remains configured.

"${XDG_CONFIG_HOME:-$HOME/.config}/omarchy/plugins/io.github.treramey.raindrop-bookmarks/clear-bookmarks"

Remove

"${XDG_CONFIG_HOME:-$HOME/.config}/omarchy/plugins/io.github.treramey.raindrop-bookmarks/clear-bookmarks"
omarchy plugin remove io.github.treramey.raindrop-bookmarks

The clear command removes the saved snapshot and cover cache. The removal command leaves the configured token file in place because other Raindrop tools might use it. Remove that file yourself if you no longer need it.

Development

Test the onboarding flow from the current checkout. The script restores your installed plugin and token when you finish:

The script does not back up or restore bookmark snapshots or cover caches. Connecting during the test can replace those files with data for the test token.

scripts/test-onboarding.sh

Or run the checks directly:

omarchy plugin validate .
qmllint -I "$OMARCHY_PATH/shell" RaindropBookmarks.qml
for script in configure-token validate-token token-fingerprint load-bookmarks bookmark-sync clear-bookmarks cover-sync tests/*.sh; do
  bash -n "$script" || break
done
python3 -m py_compile validate-cover-url
tests/configure-token.sh
tests/validate-token.sh
tests/bookmark-sync.sh
tests/security.sh

Runtime changes require a Changesets entry (pnpm changeset). The release pull request updates package.json and manifest.json. Use Conventional Commit subjects.

Changesets tooling requires pnpm install. Its local node_modules tree contains symlinks, which Omarchy's plugin validator intentionally rejects. Remove it before validating the plugin folder:

rm -rf node_modules
omarchy plugin validate .

See the Omarchy marketplace guides for development and publishing.