Omahub
← All plugins
Y

Keybind Manager

by younesdahdouh

Rebind any Hyprland or Herdr key by pressing it — with conflict warnings and layout switching

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
a4b9495
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:64

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/younesdahdouh/keybind-manager.git ~/.config/omarchy/plugins/keybind-manager

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a4b9495
Reviewed
1 month ago

This is a legitimate keybinding-management panel that edits the user's own Hyprland/Herdr config files, with explicit conflict warnings before overwriting existing bindings. No obfuscated code, credential theft, hidden persistence, or destructive install-time behavior was found. The deterministic scan's external-host finding refers to the README's manual git clone install snippet, which is documentation only and not executed by the plugin.

  • Rebinding and creating bindings appends Lua lines to ~/.config/hypr/bindings.lua and reloads Hyprland; a malformed write could leave Hyprland config errors until manually corrected.
  • Key capture temporarily switches Hyprland into a near-empty submap; if the plugin is killed mid-capture, global keybindings remain suspended until the panic chord or the grab script's off command is used.
  • Layout changes rewrite the kb_layou setting in ~/.config/hypr/input.lua inside a plugin-owned marker block, which relies on last-write-wins behavior relative to other config.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/younesdahdouh/Hyprland-Keybind-manager --enable
Appearance #Hyprland

Keybind Manager

Rebind Hyprland and Herdr keys by pressing them. No config editing, no collisions.

Rebinding a key in Hyprland means opening a config file, remembering the syntax, reloading, and finding out afterwards whether you just clobbered something else. This is a panel that does it by pressing the key.

<p align="center"> <img width="520" alt="Rebinding a keybinding — the panel waits for the new chord" src="docs/capture.png" /> </p>

Click the pencil on any binding, press the combo you want. If it's taken, you're told what by, before anything changes — and whatever you bump reappears at the top of the list flagged needs a key, so nothing goes quietly missing. Hyprland and Herdr bindings, one searchable list, plus a keyboard-layout switcher in the header.

<p align="center"> <img width="520" alt="Conflict warning naming the binding that currently holds the combo" src="docs/conflict.png" /> </p>

What it does

  • One searchable list of everything. Hyprland and Herdr bindings together, in the exact same priority order as the native menus — it calls those menus' underlying logic directly, so the ordering never drifts.
  • Rebinding never writes silently. The conflict warning names what currently holds the combo and waits for an explicit confirm before touching your config.
  • Nothing you bump disappears. A displaced binding returns to the top of its section flagged needs a key until you give it one.
<p align="center"> <img width="520" alt="A displaced binding flagged 'needs a key' at the top of the list" src="docs/needs-a-key.png" /> </p>
  • + New creates a brand-new Hyprland binding — a command, or an app launched via uwsm. It writes straight to your own ~/.config/hypr/bindings.lua, the same file omarchy menu keybindings reads, so it shows up there immediately, no restart required.
  • Add and remove keyboard layouts without editing config. Omarchy's own bar widget shows and switches your layouts, but only once you've got more than one — and getting there means hand-editing kb_layout in ~/.config/hypr/input.lua with an xkb code you had to go look up. The EN indicator in this panel's header opens a searchable catalogue of every xkb layout (100+ languages); click one to add it, trash icon to remove it (it refuses to drop your last remaining layout). Applied immediately, written into a clearly-marked block this plugin owns so nothing else in that file moves.
<p align="center"> <img width="420" alt="Keyboard layout menu with searchable xkb catalogue" src="docs/layouts.png" /> </p>
  • Fully theme-aware. It only ever draws from the shell's live Color/Style tokens, the same ones every built-in panel uses, so it re-themes instantly with omarchy theme set — no plugin-side theme code at all.

Install

git clone https://github.com/younesdahdouh/keybind-manager.git ~/.config/omarchy/plugins/keybind-manager
omarchy-shell shell rescanPlugins
omarchy plugin enable keybind-manager

A small keyboard icon appears in the bar — click it to open the panel. It also registers as IPC target keybind-manager, so if you'd rather summon it with a hotkey:

-- ~/.config/hypr/bindings.lua
o.bind("SUPER + SHIFT + K", "Keybind manager", "omarchy-shell keybind-manager toggle")

Uninstall

omarchy plugin remove keybind-manager

Then remove the hotkey binding above from ~/.config/hypr/bindings.lua if you added one. Bindings and layouts you created through the panel stay in your own config (~/.config/hypr/bindings.lua, ~/.config/herdr/config.toml, ~/.config/hypr/input.lua) — removing the plugin doesn't undo them, same as any keybinding you'd set by hand.

What it deliberately doesn't do

  • Rebinding is exec-only for Hyprland. Anything created with o.bind(key, description, "command") — the vast majority of user-facing binds, launching apps and running scripts — is fully rebindable. Hyprland's own native dispatchers (window/workspace management, etc.) show up in the list with a locked edit button, because hyprctl binds reports them by their classic dispatcher name and there's no verified, general mapping from that to Hyprland's newer hl.dsp.* Lua namespace. Guessing one risked writing a syntactically-valid but functionally-wrong bind into your config. You can still free up a native binding's key from this panel by rebinding something else onto it; it just can't reconstruct the original for you afterwards, and says so before you confirm.
  • No "new binding" flow for Herdr. Unlike Hyprland, Herdr's actions are a fixed, built-in catalogue — you can't invent a new one, only assign or reassign a key to an existing action. Every currently-unbound Herdr action already appears in the main list flagged needs a key, and its own edit button is "create a new Herdr binding" — no separate picker needed.
  • Herdr rebinds are single-combo, not prefix-sequence. Herdr's own "prefix" leader-key combos (press ctrl+space, release, then press the next key) are a sequence, not a chord you can hold down — this plugin can only capture and assign simultaneous chords (ctrl+alt+x, etc). That's still a fully valid alternate binding for any action; it just can't reproduce a prefix-style one through key capture.
  • If herdr isn't installed, the Herdr section says so and stays empty — everything else works the same.

How it works

  • bin/keybinds-list merges Hyprland (hyprctl binds plus a Lua-bind scan for binds Hyprland reports via its opaque __lua dispatcher) and Herdr (herdr --default-config diffed against your ~/.config/herdr/config.toml) into one JSON array, using the exact same priority table as omarchy-menu-keybindings.
  • Writes are append-only and land in the files you already own: ~/.config/hypr/bindings.lua (hl.unbind(...) / o.bind(...) lines), ~/.config/herdr/config.toml (the [keys] table), and ~/.config/hypr/input.lua (a single kb_layout line, kept under its own marker comment so it can be found and replaced next time rather than duplicated) — never anything under /usr/share/omarchy/ or Herdr's own defaults.
  • bin/keyboard-layout mirrors omarchy.keyboard-layout's own mechanism (hyprctl -j devices for state, hyprctl switchxkblayout to switch) and its language names and codes come from xkbcli list --load-exotic.
  • Hyprland has no notion of a "known but unbound" binding — unbinding a key just makes it vanish from hyprctl binds. So when a rebind bumps one out of the way, this plugin remembers it (in ~/.local/state/omarchy/keybind-manager/pending-hypr.json) until it's reassigned a key, which is what makes it reappear at the top of the list.
  • bin/keybinds-grab suspends Hyprland's own keybindings for the duration of a key capture. Hyprland consumes a bound chord in the compositor and never forwards it to the focused surface, so without this, capturing a combo that's already taken would just fire that binding instead of reaching the capture dialog. It switches Hyprland into a submap containing (almost) no binds — every global bind goes inactive while normal key input still reaches the panel — then resets the submap when the capture ends. The submap is registered once per Hyprland session via hyprctl eval, and holds a single panic bind, CTRL+ALT+SHIFT+ESCAPE, that resets it directly in case the plugin ever dies mid-capture. One exception: binds declared with Hyprland's submap_universal flag stay active inside every submap, so those particular chords can't be captured. Herdr needs none of this — its actions fire within Herdr's own surface, not as compositor-level grabs.

Author

younesdahdouh

License

MIT