Omahub
← All plugins
M

OmaProw

by marcuspelo

Search Prowlarr indexers and grab releases (individually or in bulk), with sortable results and history.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
d44f7d2
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d44f7d2
Reviewed
1 month ago

The plugin is a bar widget for searching and grabbing torrents via Prowlarr. It handles API keys securely (via stdin, not argv) and avoids using downloadUrl. No suspicious behavior found.

  • The plugin makes network requests to a user-configured Prowlarr instance and can trigger downloads, which is expected functionality but requires user trust in the configured base URL.
  • The API key is stored in a plaintext .env file, though the plugin attempts to secure it with 0600 permissions.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/MarcusPelo/omaprow --enable
Widgets #bar #quickshell #media

OmaProw

An Omarchy bar widget for Prowlarr, the indexer manager. Search across every indexer Prowlarr manages, sort and filter the results, and grab releases — individually or in bulk — without leaving the desktop.

Panel

Features

  • Search — query Prowlarr across all your indexers, filtered by category: All, Consoles, PC, Movies, TV, Books, Audio
  • Sortable results — Age, Title, Size, Grabs, Peers, Category or Indexer, ascending or descending
  • Grab — one click on a release, or select several with the checkbox and use "Grab Release(s)" for a bulk grab. Grabbing pushes the release straight to whatever download client(s) you already have configured in Prowlarr — exactly what Prowlarr's own "Grab Release(s)" button does
  • History — Prowlarr's own event history (searches, RSS, grabs) for this instance, paginated
  • In-panel settings — the ⚙ button lets you set the Prowlarr base URL directly from the panel, without editing shell.json
  • Keyboard-driven: / focuses search, g grabs the current selection, v switches between Search and History, r refreshes, esc returns focus from the search field or closes the panel

Requirements

  • A running Prowlarr instance
  • A Prowlarr API key (Settings → General → Security in the Prowlarr web UI)

Install

omarchy plugin add https://github.com/marcuspelo/omaprow.git

Setup

  1. Create ~/.config/omaprow/.env with your Prowlarr API key:
    API_KEY=your-prowlarr-api-key
    URL_BASE=http://your-prowlarr-host:9696
    
    Keeping the key in this file (outside the plugin folder) instead of shell.json keeps it out of any config you might sync or share. URL_BASE is optional but recommended: omarchy plugin disable/enable drops the widget's bar-layout entry (including whatever baseUrl was set via the panel or omarchy bar set), so a value in .env is what keeps working across that reset.
  2. Enable the widget:
    omarchy plugin enable marcuspelo.omaprow
    
    Setting the base URL is only needed if URL_BASE isn't set in .env — either via omarchy bar set marcuspelo.omaprow baseUrl "http://your-prowlarr-host:9696", or from the panel itself (⚙ → Prowlarr base URL → Save). Note that omarchy plugin disable/enable drops the widget's bar-layout entry, including any baseUrl set either way — a value in .env is what survives that reset.

Security

The API key never appears in process arguments: every curl call sends it as an X-Api-Key header supplied over the child process's stdin (curl -K - with a header = "X-Api-Key: ..." config line), not as a -H argument — so it's invisible to ps/process inspection. ~/.config/omaprow/.env is also set to mode 0600 automatically every time the plugin reads it; you can do this yourself too: chmod 600 ~/.config/omaprow/.env.

Note: Prowlarr's search results embed the API key directly in each release's downloadUrl field. This plugin never uses downloadUrl — grabbing goes through Prowlarr's own POST /api/v1/search grab endpoint instead, addressed by release + indexer id, so the key stays out of that path too.

Configuration

Available settings (shell.json, or omarchy bar set marcuspelo.omaprow <key> <value>):

Setting Type Default Description
baseUrl string (empty) Base URL of your Prowlarr instance (no trailing slash). Falls back to URL_BASE in ~/.config/omaprow/.env when unset.
pageSize integer 100 Maximum releases requested per search (10–500)
defaultCategoryId integer 0 Category pre-selected on open (0 All, 1000 Consoles, 2000 Movies, 3000 Audio, 4000 PC, 5000 TV, 7000 Books)

Keyboard shortcuts

Key Action
/ Focus the search field
enter (in search field) Run the search
g Grab every selected release
v Switch between Search and History
r Refresh (re-run the search, or reload history)
esc Drop focus from the search field back to shortcuts; closes the panel otherwise

Remove

omarchy plugin remove marcuspelo.omaprow

License

MIT