Omahub
← All plugins
0

SSH LAN browser

by 0ncoming-Storm

Discover SSH servers in manually configured IPv4 ranges and open them in a terminal.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
9814a54
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
9814a54
Reviewed
1 month ago

The plugin performs network scanning and SSH connections as described, with input validation and no obvious malicious behavior. The main risk is that it runs unsandboxed and can initiate network scans and SSH connections, which could be misused if the user is tricked into configuring malicious ranges, but this requires explicit user action.

  • The plugin runs unsandboxed in the Omarchy shell process, so any vulnerability in the QML or shell scripts could affect the user's system.
  • The plugin automatically scans configured networks and can connect to discovered SSH hosts, which could be used for unauthorized network activity if the user is misled about the ranges.
  • The connect.sh script offers to install SSH keys via ssh-copy-id, which could be a vector for credential theft if a malicious host is configured, though it requires user confirmation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/0ncoming-Storm/omarchy-ssh-lan --enable
Developer Tools #bar #system

SSH LAN browser for Omarchy

A Quickshell panel and bar widget for Omarchy that finds SSH servers on your network and opens them in a terminal with one click. Scans are done with nmap against IPv4 CIDR ranges you configure; found hosts are remembered, so opening the panel afterwards only pings them instead of re-scanning the whole network.

Features

  • Remembered hosts, instant open — after the first scan, opening the panel just pings known hosts (8 at a time, 1 s each) to see which are still alive.
  • Full scans on demand — press Rescan (or r) to run a fresh nmap scan of your configured ranges at any time.
  • IPv4 CIDR ranges (/16–/32), entered in the gear menu.
  • Scans only TCP port 22.
  • Reverse-DNS names autofill as display names; editable per host.
  • Per-host settings — display name, username, and SSH port. The username defaults to your current Linux user and the port to 22.
  • Connect buttons open a new Omarchy terminal.
  • First-connection ssh-copy-id offer so later logins use your key.
  • In-panel log viewer — latest 200 lines, newest first, with a timestamped log on disk.

Requirements

  • OpenSSH (ssh), bash, nmap
  • ping (from iputils, part of a standard Arch install)

No passwords are stored anywhere: SSH prompts for them normally in the terminal, or you use a key once ssh-copy-id has run.

Install

omarchy plugin add https://github.com/0ncoming-Storm/omarchy-ssh-lan.git --enable

Manual install: clone the repository into ~/.config/omarchy/plugins/linuxinthebox.ssh-lan/, then run omarchy plugin validate and omarchy-shell shell rescanPlugins.

Quick start

  1. Click the SSH LAN icon in the bar.

  2. The first time, the button reads Scan — click it (or just open the panel; with no known hosts it scans automatically). You need at least one configured range first.

  3. Click the gear in the panel header and enter your ranges:

    192.168.1.0/24
    10.20.0.0/24
    100.92.146.107/32
    
  4. Back in the list, click Connect next to a host, or use its gear to set a display name, username, or non-default port.

Subsequent opens skip the scan and just ping the hosts you've discovered. Hosts that stop answering are hidden until they come back or you Rescan.

Hosts that block ICMP pings won't appear from the ping check — run a Rescan for those; the full scan probes TCP 22 directly.

Keyboard shortcuts

While the panel is open:

Key Action
↑ / ↓ / j / k Move the cursor
Enter Connect to the selected host
r Full rescan
p Edit the selected host's settings
Esc Close the panel

Right-clicking the bar icon also triggers a full rescan.

Logs and security

  • Scan and host-check activity is logged to ~/.cache/omarchy-ssh-lan/scan.log (700/600 permissions). The panel shows the latest 200 lines, newest first, via gear → View scan log.
  • Host settings are kept in ~/.config/omarchy/shell.json under the plugin's settings; nothing is written to command-line arguments or the log.
  • Scan only networks you own or are authorized to test. Plugins run unsandboxed inside the long-lived Omarchy shell process.

Removing

omarchy plugin remove linuxinthebox.ssh-lan

The command disables the plugin before removing it. Your settings in shell.json are not deleted automatically.