Omahub
← All plugins
M

Omarqui

by marcuspelo

Torrent speed and aggregate status via Qui (qBittorrent management).

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
4555464
Scanned
2 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4555464
Reviewed
2 weeks ago

The deterministic scan found no issues, and the sampled code shows no malicious behavior: it is a straightforward QML bar widget that talks to a user-configured Qui instance and handles the API key carefully via curl stdin. I rate it low rather than none only because it handles a sensitive API key and can issue destructive torrent commands, but all such behavior is user-configured and user-confirmed.

  • The Qui API key is sent to the configured baseUrl; if a user points the widget at a remote HTTP endpoint, the key would be transmitted in cleartext. The default is localhost, so this is a configuration caveat rather than a code defect.
  • The plugin can delete torrents and downloaded files; this is advertised functionality with a two-step confirmation, but it is inherently destructive if used carelessly.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/MarcusPelo/omarqui --enable
Widgets #bar #media #system

Omarqui

An Omarchy bar widget for Qui, the self-hosted qBittorrent management dashboard. See aggregate torrent speed and status at a glance, and manage torrents across all your qBittorrent instances without leaving the desktop.

Panel

In the bar

On the desktop

Features

  • Bar chip — aggregate download and/or upload speed across every qBittorrent instance Qui manages (configurable via the barMetric setting), with a tooltip summary
  • Status filters — click "active / downloading / seeding / paused / errored" to filter the list ("active" means torrents currently transferring data, i.e. non-zero download or upload speed)
  • Ratio at a glance — each torrent row shows its share ratio (e.g. 0.82) right next to its size
  • Instance filter — switch between "All" and individual qBittorrent instances
  • Search — filter by torrent name
  • Per-torrent actions — pause, resume, delete (with a two-step confirm to avoid mistakes, and an option to delete the downloaded files too)
  • Add torrent — paste a magnet link or a local .torrent file path, pick the instance and category, optionally start paused

Requirements

  • A running Qui instance
  • A Qui API key (Settings → API Keys in the Qui web UI)

Install

omarchy plugin add https://github.com/marcuspelo/omarqui.git

Setup

  1. Create ~/.config/omarqui/.env with your Qui API key:
    API_KEY=your-qui-api-key
    BASE_URL=http://your-qui-host:7476
    
    Keeping the key in this file (outside the plugin folder) instead of shell.json keeps it out of any config you might sync or share. BASE_URL is optional but recommended: omarchy plugin disable/enable drops the widget's bar-layout entry (including whatever baseUrl was set via the panel or omarchy bar set), so a value in .env is what keeps working across that reset.
  2. Enable the widget and point it at your Qui instance:
    omarchy plugin enable marcuspelo.omarqui
    omarchy bar set marcuspelo.omarqui baseUrl "http://your-qui-host:7476"
    
    This step is optional if BASE_URL is already set in .env.

Security

The Qui API key never appears in process arguments: every curl call sends it as an HTTP header supplied over the child process's stdin (curl -K - with a header = "X-API-Key: ..." config line), not as a -H argument — so it's invisible to ps/process inspection. ~/.config/omarqui/.env is also set to mode 0600 automatically every time the plugin reads it; you can do this yourself too: chmod 600 ~/.config/omarqui/.env.

Configuration

Available settings (shell.json, or omarchy bar set marcuspelo.omarqui <key> <value>):

Setting Type Default Description
baseUrl string http://localhost:7476 Base URL of your Qui instance (no trailing slash). Falls back to BASE_URL in ~/.config/omarqui/.env when unset.
refreshIntervalSec integer 10 Seconds between background refreshes (5–300)
barMetric enum Download What the bar chip shows: Download, Upload, or Both. Also editable from the in-panel Settings screen.

Keyboard shortcuts

Key Action
r Refresh
esc Close the panel

Remove

omarchy plugin remove marcuspelo.omarqui

License

MIT