Omahub
← All plugins
L

Messaging

by lef

Web messaging hub for Slack, Discord, Telegram and WhatsApp. Bar widget shows how many apps are enabled; the panel toggles each one and opens its web client in the browser. No accounts or credentials are stored by this plugin.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
45769e8
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
45769e8
Reviewed
1 month ago

The plugin is well-structured with strict URL validation, bounded config file reads/writes, and safe process launching via command arrays. It does not store credentials and only launches web apps in isolated browser profiles. No obvious security issues were found.

  • The plugin launches external browsers with user-provided URLs, but the URLs are strictly validated to be http/https with no userinfo or special characters, and the launch uses execDetached with an argument array, preventing shell injection.
  • The config file is read/written with Perl scripts that enforce size limits, reject symlinks, and validate UTF-8, reducing the risk of file-based attacks.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Somnius/Messaging-for-Omarchy --enable
Productivity #bar #quickshell

Messaging for Omarchy

An Omarchy shell plugin that keeps web messaging one click away — Slack, Discord, Telegram and WhatsApp Web, each in its own dedicated app window. No Electron apps, no second IM client, no tab hunting.

A speech-bubble icon sits in the bar (default: right side):

  • Left-click — panel: toggle each app on/off and launch the enabled ones.
  • Badge — shows how many apps are currently enabled.
  • Hover — tooltip with "2 of 4 apps on".
<img width="428" height="659" alt="Messaging panel" src="preview.png" />

Features

  • Four web clients built in: Slack, Discord, Telegram, WhatsApp — each off until you enable it.
  • Dedicated app window per app: launches Chromium in --app mode (chromeless standalone window) with an isolated profile per app under ~/.local/share/omarchy/messaging/<app>-profile. Sign in once; sessions persist across opens and stay quarantined from your daily browser.
  • Falls back to xdg-open when no Chromium-family browser is found.
  • Zero credential handling: the plugin stores only enable flags and URLs.
  • Bounded configuration: config is read with a 64 KiB ceiling; each URL is limited to 2,048 characters and must be an absolute HTTP(S) URL without credentials, whitespace, control characters or backslashes. Invalid replacements leave the last accepted state intact.

Install

omarchy plugin add https://github.com/Somnius/Messaging-for-Omarchy.git --enable

Then place the widget in the bar:

omarchy bar put lef.messaging --section right

From a local checkout (development)

If you already have a copy of this repository on disk, link it into the plugins folder:

ln -s "$PWD" ~/.config/omarchy/plugins/lef.messaging
omarchy-shell shell rescanPlugins

Dev loop caveat: Quickshell's file watcher does not follow symlinks; after edits run omarchy restart shell.

Validate at any time with:

omarchy plugin validate "$PWD"

Configuration

~/.config/omarchy/messaging/config.json — hot-reloads:

{
  "apps": {
    "slack":    { "enabled": true,  "url": "https://app.slack.com/client" },
    "discord":  { "enabled": false, "url": "https://discord.com/channels/@me" },
    "telegram": { "enabled": true,  "url": "https://web.telegram.org/a/" },
    "whatsapp": { "enabled": false, "url": "https://web.whatsapp.com/" }
  }
}

Self-hosting alternatives or gateways? Point url at any valid absolute HTTP(S) URL; the Open button follows it.

IPC & keybindings

omarchy-shell lef.messaging status              # JSON state of every app
omarchy-shell lef.messaging enable slack true   # same path as the panel toggle
omarchy-shell lef.messaging launch telegram     # open its app window
omarchy-shell lef.messaging toggle              # open/close the panel

Hyprland binding example (~/.config/hypr/bindings.lua):

o.bind("SUPER + ALT + M", "Messaging panel", "omarchy-shell lef.messaging toggle")

External dependencies

  • Perl (provided by Omarchy) for bounded config reads and atomic writes.
  • A Chromium-family browser for app windows: chromium or brave (auto-detected), otherwise any browser via xdg-open.

Uninstall

omarchy plugin remove lef.messaging

(If installed via symlink, remove the symlink instead. App profiles remain under ~/.local/share/omarchy/messaging/; delete that folder to wipe all chat sessions.)

Privacy

The plugin never sees a password, token, cookie or message. It writes one config file containing booleans and URLs you typed. Chat sessions live only in the per-app browser profiles.

License

MIT