Omahub
← All plugins
J

Notification Center

by Jankees van Woezik

Every notification you were sent, kept, and readable again

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
e90e1d7
Scanned
3 minutes ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4d5e483
Reviewed
15 hours ago

The plugin is a notification archiver: it copies Omarchy's on-disk notifications into a local JSONL archive with restrictive permissions, and deliberately refuses to execute stored notification actions. The deterministic scan found nothing, and I found no obfuscation, persistence, credential theft, or destructive install behavior. The only notable risk is inherent to the feature: a plaintext archive of all notifications, including potentially sensitive messages and 2FA codes, which is clearly documented and protected by file permissions.

  • The archive stores every notification in plaintext under ~/.local/state/omarchy-notification-center/, including chat messages and 2FA codes; permissions are set to 0700/0600, but any process running as the same user can read it. This is disclosed in the README and is the plugin's stated purpose.
  • Image copying is bounded to 5MB and normally validated with `file`, but if `file` is not installed the MIME check is skipped and only the image-extension allowlist and size cap apply. This is a minor hardening gap, not an exploitable code-execution path.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jankeesvw/omarchy-notification-center --enable
Desktop #bar #quickshell

Notification Center

An Omarchy bar widget that keeps the notifications you were sent. A bell on the right of the bar, a dot on it when something has come in, and a panel of everything you were told, still there tomorrow.

Omarchy shows a notification once. This answers the question that comes ten minutes later, in the middle of something else: what did that say?

<img src="preview.png" alt="The notification center open on the right of the screen, a column of cards under Today and Yesterday" width="720">

Install

omarchy plugin add https://github.com/jankeesvw/omarchy-notification-center.git --enable

Needs jq and inotifywait, both of which Omarchy already has. Leave the bell at the far right of the bar: the panel is pinned to the right edge of the screen, so a bell in the middle is a bell whose panel opens somewhere else.

What it does

Omarchy's notification service already writes every notification to disk, and then keeps only the last ten. This copies each one out of there as it lands, icon and all, and keeps it for 30 days.

  • One card per notification, newest first, under the day it arrived on.
  • A picture when there was one. Cameras and screenshot tools hand their file to the notification's action rather than setting an image on it, so the path is read out of there and a scaled copy is kept.
  • Clicking a card opens that picture, or focuses the app that sent the notification. It never runs the command the notification arrived with: that command is chosen by whoever sent the notification, so a stored one would be an attacker's command waiting for a click. Only an absolute path to an image is kept, and it is opened by argument rather than through a shell.
  • The × on a card, or a right-click, removes one. Clear draws a line under everything you have seen: the panel empties, and what was in it ages out through the ordinary retention limits instead of being deleted on the spot. Nothing is destroyed by a click, so nothing has to be confirmed.
  • The bell in the header is Do Not Disturb, the same switch as the bar's. Right-clicking the bell in the bar does it without opening anything.
  • The magnifier, or /, searches everything kept. Escape leaves the search, Escape again closes the panel.
  • No grouping, on purpose. Ten identical messages are ten cards, not one card with a ×10 on it. A stack hides when each one arrived, and the newest one on top hides whether an older one was urgent. If an app sends the same thing ten times, that is worth seeing as it is.

Settings

Setting Default
Mark what you have not read Dot Dot, Highlight, Count or None on the bell. Highlight colours the bell itself instead of adding anything to it.
Keep notifications for 30 days Older than this is deleted, icon and all.
Keep at most 1000 A ceiling regardless of age.
Clicking a notification Auto Opens the picture, or focuses the app. Or neither.
Show the message text on Off leaves the sender and subject only.
Show pictures on Off stops keeping copies as well.
Panel width 420 In the shell's spacing units.
List height 0 0 runs the list to the bottom of the screen.

Where things are kept

~/.local/state/omarchy-notification-center/, one line of JSON per notification plus a copy of every icon and picture. The directory is 0700 and the archive 0600, and only files that are actually images are copied into it.

Worth knowing for one reason: that is every notification you have been sent, chat messages and two-factor codes included. It never leaves the machine, but it is not something to sync or back up carelessly. Keep notifications for is the setting that limits the damage, and one day is a perfectly reasonable answer to it.

Removing the plugin leaves the archive alone, on purpose:

omarchy plugin remove jankeesvw.notification-center
rm -rf ~/.local/state/omarchy-notification-center

The command line

bin/notification-center is the storage side, and how you search further back than the panel loads:

list [LIMIT]       the archive as JSON, newest first
remove KEY         drop one, or clear for all of them
seed [N]           fill it with test traffic
backfill           give older entries the picture their action points at

watch, sync, seen, unread and prune are in there too; everything prints JSON.

# everything Slack sent you last week, as text
notification-center list 2000 | jq -r '.[] | select(.app == "Slack") | "\(.summary): \(.body)"'

The panel opens over IPC, which is how you bind it to a key:

omarchy-shell jankeesvw.notification-center toggle

Licence

MIT.