Omahub
← All plugins
M

Temparchy

by marc

Neon 3D tube-shooter arcade game with massive voxel explosions and a local high-score table

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
22ebc02
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
22ebc02
Reviewed
1 month ago

The plugin is a self-contained WebGL game that launches in an external browser window via the standard omarchy-launch-webapp mechanism. No network access at runtime, no system modifications, and the source code is available for review. The build script fetches Three.js only during development, not during installation or runtime.

  • The game is launched in an external browser window, which is expected behavior but may be unexpected for a bar widget.
  • The bundled game code is minified, though the unminified source is included for review.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/mrcgibb9876-hash/temparchy-omarchy-plugin --enable
Desktop #quickshell

Temparchy — Omarchy Quattro plugin

A neon 3D tube-shooter (Tempest-inspired) with massive voxel explosions, radiating neon shockwaves, and a local high-score table. Ships as a real Omarchy Quattro shell plugin: manifest.json + QML entry points, discovered and summoned by omarchy-shell like any other plugin.

How it works

The game itself is a self-contained WebGL/Three.js page (game/index.html plus game/vendor/, no server required to run). Rather than rendering WebGL inside the shell's QML compositor — which currently crashes Quickshell's WebEngineView (see quickshell-mirror/quickshell#298) — this plugin's job is just to launch the game in its own app-mode browser window via Omarchy's own omarchy-launch-webapp. That's a robust, already-supported mechanism (same one Omarchy webapps use), so the game runs full-speed as a normal browser-rendered window instead of fighting an unstable embed path. Since that launcher opens the game via a file:// URL, index.html loads three pre-built classic scripts (game/vendor/three-core.bundle.js, game/vendor/three-addons.bundle.js, game/vendor/game.bundle.js) rather than ES modules — Chromium refuses to resolve relative module imports when the document itself is file://, and the marketplace's static security scan hard-fails on any single file over 512 KB, which the vendored Three.js runtime doesn't fit in one file (see HANCORE-linux/omarchy-plugin-marketplace#1862). See game/vendor/three/PROVENANCE.md and "Developing" below for what's vendored and how the bundles are built.

Two entry points, per manifest.json:

  • bar-widget (BarWidget.qml) — a clickable "▲ TEMPARCHY" icon you can place in the bar. Click it to launch.
  • overlay (Overlay.qml) — a headless summon target for keybinds, the Omarchy menu, or IPC. Launches the game and immediately closes itself (there's nothing to render inside the shell).

Install

Manual install (local plugin, no git remote needed):

cp -r /path/to/temparchy-omarchy-plugin ~/.config/omarchy/plugins/marc.temparchy
omarchy-shell shell rescanPlugins
omarchy plugin enable marc.temparchy
omarchy bar put marc.temparchy   # place the bar icon (optional)

Or, once pushed to a git remote, the standard way:

omarchy plugin add <git-url-of-this-repo>
omarchy plugin enable marc.temparchy

Launch without the bar icon

omarchy-shell shell summon marc.temparchy '{}'

or bind a key to it in Hyprland, e.g. in ~/.config/hypr/bindings.conf:

bind = SUPER, T, exec, omarchy-shell shell summon marc.temparchy '{}'

Developing

The maintained source for the game logic is game/src/main.js (an ES module that imports Three.js via game/src/three-shim.js, which reads off the window.THREE_VENDOR global rather than importing game/vendor/three/ directly — see the comments in game/three-core-entry.js, game/three-addons-entry.js, and game/three-vendor-shim.js for why). It is not loaded directly — game/index.html loads three pre-built classic bundles instead, so the game keeps working when launched via file:// and no single file trips the marketplace's 512 KB static-scan limit. The one vendored file that's too large to commit at all (game/vendor/three/build/ three.module.js, ~1.24 MB) is fetched and checksum-verified at build time instead — see game/vendor/fetch-three.sh and game/vendor/three/PROVENANCE.md. After editing game/src/main.js or the vendored Three.js sources, rebuild:

./game/build.sh   # requires npx (Node.js) and curl; fetches+verifies
                   # three.module.js, then runs esbuild — fails if any
                   # output file exceeds 512 KB

Commit the regenerated game/vendor/three-core.bundle.js, game/vendor/three-addons.bundle.js, and game/vendor/game.bundle.js along with your source change.

Controls

Arrows / A-D / mouse to steer, Space / click to fire, Z for the superzapper. High scores are saved locally in the browser profile that omarchy-launch-webapp opens the game in.