Omahub
← All plugins
L

n8n

by legendik

n8n workflow monitor: execution status and workflow toggles in the Omarchy bar. Multi-instance support.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
e3c8107
Scanned
2 weeks ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S libsecret') and ensure a" >&2
  • Docs external_hosts CHANGELOG.md:21

    Downloads or connects to an external HTTP(S) host.

    curl response sizes to prevent disk/memory exhaustion ([a3e8aed](https://github.com/legendik/omarchy-n8n/commit/a3e8aedb57012281c8b9975be797a7bbe1bdaa5e))
  • Docs external_hosts CHANGELOG.md:23

    Downloads or connects to an external HTTP(S) host.

    curl argv, honor keyring-first fallback ([b1e5150](https://github.com/legendik/omarchy-n8n/commit/b1e5150b4b462433ae2c6b41376264c7b1ac122f))

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e3c8107
Reviewed
2 weeks ago

The deterministic medium findings are false positives: the external host URLs are CHANGELOG documentation, and the `sudo pacman -S libsecret` string in the setup script is only a printed installation hint, not an executed command. The plugin itself is a straightforward n8n monitor that contacts only user-configured n8n instances, stores API keys in the system keyring, and uses bounded, validated subprocess calls. No obfuscation, persistence, credential exfiltration, or destructive behavior was found.

  • The setup script prints an advice line containing `sudo pacman -S libsecret`, but it is inside an echo string and is never executed by the script.
  • The CHANGELOG entries contain `https://github.com/...` links, which are release documentation, not runtime network activity.
  • The plugin handles n8n API keys and makes authenticated HTTP requests to user-configured n8n hosts; this is expected functionality and does not appear to leak credentials elsewhere.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/legendik/omarchy-n8n --enable
Developer Tools #bar #quickshell

omarchy-n8n

n8n workflow monitoring in the Omarchy bar — no Electron, no browser tab.

Monitor executions and toggle workflows from a native Quickshell panel. Multi-instance support: track prod and local side by side.

n8n plugin preview

Features

  • Bar pill — workflow icon with a live count badge. Red on failure, blue when running, quiet when all green.
  • Executions tab — last N executions across all workflows with status, workflow name, mode, and relative time. Click → opens in browser.
  • Workflows tab — full list with active/inactive indicator. Toggle active state inline without leaving the desktop.
  • Multi-instance — configure prod, staging, local; switch between them inside the panel.
  • Failure notifications — desktop alert on new failures (compares against last known state, per-instance). Click the notification to open the failed execution in your browser.
  • Vim motions — j/k move the selection, h/l (or [/]) switch tabs, gg/G jump to top/bottom, Enter/Space opens the selected item, r refreshes, Esc closes.

Requirements

  • Omarchy Quattro shell (Quickshell)
  • secret-tool (libsecret) with a running keyring service (gnome-keyring, kwallet, ...) — required for storing API keys
  • dd (coreutils) — used by the widget itself for bounded, symlink-safe reads of its own config/state files
  • bash, curl, jq — only needed for the omarchy-n8n-setup CLI wizard, not for the running widget
  • An n8n instance with API enabled (n8n ≥ 0.188 for REST API; Settings → API → Enable)

Install

omarchy plugin add https://github.com/legendik/omarchy-n8n.git --enable
omarchy bar put legendik.n8n --after omarchy.weather

Uninstall

omarchy plugin remove legendik.n8n
rm -rf ~/.config/omarchy-n8n   # optional: also delete stored instances (keyring entries need: omarchy-n8n-setup remove <id> beforehand, or secret-tool clear service omarchy-n8n)

First-time setup

Run the setup wizard to add your first instance:

omarchy-n8n-setup

You'll be prompted for:

  1. Instance name (e.g. prod, local)
  2. n8n URL (e.g. http://localhost:5678 or https://n8n.yourcompany.com)
  3. API key (n8n → Settings → n8n API → Create an API key)

If your n8n instance supports scoped API keys, the plugin only needs: workflow:list, workflow:activate, workflow:deactivate, execution:list. No credential, user, or write-access-to-workflow-content scopes are required.

Multiple instances

omarchy-n8n-setup add          # add another instance
omarchy-n8n-setup list         # show all configured instances
omarchy-n8n-setup remove prod  # remove by instance id

Optional hotkey

Add to your Hyprland bindings.lua:

o.bind("SUPER + SHIFT + N", "n8n", "omarchy-shell shell toggle legendik.n8n")

Hyprland float rule

windowrulev2 = float, title:^(n8n)$
windowrulev2 = size 460 640, title:^(n8n)$
windowrulev2 = center, title:^(n8n)$

Configuration

In the Omarchy shell settings panel:

Key Default Description
refreshIntervalSec 30 How often to poll n8n (seconds)
maxExecutions 20 Max executions to fetch per instance
notifyOnFailure true Desktop notification on new failures

How it works

The panel's Service.qml polls each configured instance directly via XMLHttpRequest — GET /api/v1/workflows and GET /api/v1/executions — in-process, in QML/JS. No curl/jq subprocess is spawned for the recurring poll or the workflow toggle action. Results are aggregated in memory and the failed-execution IDs are written to ~/.config/omarchy-n8n/.last-state.json via Quickshell's FileView (atomic write: private temp file + rename) for failure diffing between refreshes. Toggling a workflow issues a direct POST /api/v1/workflows/:id/activate or deactivate request the same way.

instances.json and .last-state.json live at predictable, user-writable paths, so reading their contents never goes through FileView (Quickshell's reader follows symlinks and can block on a FIFO). Instead the widget spawns dd iflag=nofollow,nonblock with a byte cap to read them, refusing anything that isn't a plain, bounded, readable regular file — FileView is used only to watch for changes on disk.

API keys are looked up from the system keyring via secret-tool for each request; they are never written to disk. omarchy-n8n-setup remains a small bash/curl/jq CLI wizard for interactively adding, listing, and removing instances — it's the only place those tools are still used.

Releasing

Releases are automated by release-please from Conventional Commits on master (fix:, feat:, feat!:/BREAKING CHANGE:, etc.). It opens/updates a release PR with the version bump and changelog; merging it tags the release, publishes it on GitHub, and updates version in manifest.json.

License

MIT