Omahub
← All plugins
D

OnTheMinute

by Daniel Lobo

Customizable EMOM (Every Minute On the Minute) workout timer with per-minute and 5-second-warning cues, plus session history.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
2812536
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:37

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/DanielLob-o/OnTheMinute.git ~/.config/omarchy/plugins/lobo.on-the-minute

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2812536
Reviewed
1 month ago

OnTheMinute is a straightforward EMOM workout timer written in QML/JavaScript with no malicious behavior detected. The only deterministic finding (external host) refers to a `git clone` command in the README documentation, which is not executable code and poses no risk. The plugin's use of `execDetached` for playing audio cues and sending notifications is properly quoted and does not allow command injection.

  • The deterministic scan flagged an external host reference, but it is a `git clone` command in the README documentation only, not part of the executable code.
  • The plugin writes state files to `~/.local/state/omarchy/` and reads/writes history, which is expected behavior for a timer with session history and involves no sensitive data.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/DanielLob-o/OnTheMinute --enable
Widgets #quickshell #system

OnTheMinute

A customizable EMOM (Every Minute On the Minute) workout timer for Omarchy.

Write your exercises, set the minutes, hit start. Get cued every minute and on the last 5 seconds, with a history of past sessions.

OnTheMinute panel OnTheMinute big view OnTheMinute notification

Features

Type in whatever exercises you're doing and how many minutes you want to go. There's no fixed list, so it works for kettlebells, bodyweight circuits, or anything else you throw at it.

You get two ways to watch the clock: a small countdown in the bar with a dropdown for setup, or a fullscreen view if you want it visible from across the room while you work out.

Every minute, and again on the last 5 seconds, you get a sound plus a desktop notification, so you don't have to keep glancing at the screen.

Past workouts are saved automatically. Open the history list to see what you did and when, repeat a session with one click, or delete it if you don't want to keep it.

Install

omarchy plugin add https://github.com/DanielLob-o/OnTheMinute.git --enable --yes

Or by hand:

git clone https://github.com/DanielLob-o/OnTheMinute.git ~/.config/omarchy/plugins/lobo.on-the-minute
omarchy-shell shell rescanPlugins
omarchy plugin enable lobo.on-the-minute

Usage

  • Click the bar widget to configure exercises and minutes, then start.
  • Right-click the bar widget, or use the expand button, for the big view. Esc closes it.
  • Toggle sound from the dropdown.

Uninstall

omarchy plugin remove lobo.on-the-minute

Or by hand:

rm -rf ~/.config/omarchy/plugins/lobo.on-the-minute
omarchy-shell shell rescanPlugins

Session history lives separately at ~/.local/state/omarchy/on-the-minute-history.json and isn't removed by either method.

License

MIT, see LICENSE.