Omahub
← All plugins
J

Gospel of the Day

by Jonathan Montero

Daily Gospel readings from Evangelizo.org

Security review

Potentially dangerous behavior detected · 4 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
61020fd
Scanned
3 weeks ago
  • Registers scheduled or boot-time system tasks.

    systemd-run >/dev/null; then
  • Registers scheduled or boot-time system tasks.

    systemd-run is required" >&2
  • Registers scheduled or boot-time system tasks.

    systemd-run --user --quiet --pipe --wait --collect \
  • Docs persistence CLAUDE.md:52

    Registers scheduled or boot-time system tasks.

    systemd-run --user` with `NoNewPrivileges`, `ProtectHome=read-only`, `ProtectSystem=strict`, `PrivateTmp`, `ReadWritePaths=<cache dir>`, `MemoryMax=64M`, `TasksMax=32`, `RuntimeMaxSec=45`. Panel.qml a

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
61020fd
Reviewed
3 weeks ago

The plugin is a benign daily-gospel reader that fetches content from a single hardcoded HTTPS endpoint (feed.evangelizo.org) and displays it in a bar widget. The deterministic scan flagged systemd-run as persistence, but it is actually used to run the helper in a sandboxed transient unit (NoNewPrivileges, ProtectSystem, etc.), not to schedule anything. Input validation, allowlists, and cache hardening are thorough, and no malicious or destructive behavior was found.

  • The deterministic scan's 'persistence' findings are false positives: systemd-run is used to sandbox the helper process, not to register scheduled or boot-time tasks.
  • The plugin makes network requests to a third-party service (Evangelizo.org) when the user opens the panel, which is expected and disclosed in the README.
  • The helper writes cache files under ~/.cache/gospel-of-the-day; this is standard behavior and not a security concern.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/tuxmontero/omarchy-gospel-of-the-day --enable
Widgets #bar #quickshell #system

Gospel of the Day

A Catholic Omarchy bar plugin for the daily Mass readings: first reading, psalm, optional second reading, Gospel, and commentary.

It is meant for everyday use — a quiet place on the desktop to pray with the liturgy of the day.

Readings come from Evangelizo.org (Evangelio del día / Daily Gospel) through the official Reader Evangelizo feed. Scripture and commentary remain the property of their authors and of Evangelizo. This plugin does not bundle a Bible or commentary database.

Features

  • Latin cross on the Omarchy bar; the panel opens under the icon
  • Liturgical title plus the saint or celebration of the day
  • Readings, Gospel, and Commentary as separate tabs
  • Select and copy the readings, or copy the open tab
  • Several Catholic calendars: Roman Ordinary Form, Roman 1962 Missal (Extraordinary Form), Armenian, Byzantine, Coptic, Maronite, and Syriac
  • Roman Ordinary Calendar languages: Español, English (US), Français, Italiano, Deutsch, Português, العربية, Polski, Nederlands, Ελληνικά, Malagasy; the 1962 Missal in English, Español, Français, and Deutsch
  • Arabic and other right-to-left text is shown right-to-left
  • Previous / next day (up to 30 days) and a Today button
  • Rite and language chips always visible
  • Local cache for the current day; refresh when you ask for it
  • No network until a rite and language are chosen

Install

From this folder:

omarchy plugin validate .
omarchy-shell shell rescanPlugins
omarchy plugin enable jonathan.gospel-of-the-day --section right

Or add the git repository with omarchy plugin add <git-url> and enable it when you are ready.

Use

Click ✝ to open the panel. The first time, pick a rite, then a language (rites with a single language skip that step). Switching rite keeps your language when the new rite offers it. After that:

Input Action
Click ✝ Open or close
Rite chip Change rite
Language chip Change language
Today Jump to today
Refresh Fetch again, skip cache
Copy / c Copy the open tab
Middle-click ✝ Refresh
1 2 3 Readings, Gospel, Commentary
j k / ↑ ↓ Scroll, or move the cursor in a picker
l h / ← → Language list
r Rite (calendar) list
[ ] Previous or next day
t Today
u Refresh
Escape Close

Source line in the panel: Evangelizo.org.

Cache

Daily JSON is stored at:

~/.cache/gospel-of-the-day/<LANG>/<YYYY-MM-DD>.json

Opening the panel uses the cache when it exists. Refresh bypasses it. If the network fails, a saved copy is shown when available.

Develop

python3 tests/test_evangelizo.py
node tests/model-test.js
omarchy plugin validate .

The backend is scripts/evangelizo.py (Python standard library only). It talks only to https://feed.evangelizo.org.

License

Plugin code is MIT. See LICENSE.

Liturgical texts and commentaries are provided by Evangelizo.org and are not covered by that license. Do not redistribute those texts from the cache as if they were part of this project.