Omahub
← All plugins
M

Omatulli

by marcuspelo

Current playing activity from Tautulli (Plex), stacked cards for movies, TV episodes and music.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
52d8c47
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
52d8c47
Reviewed
1 month ago

The plugin is a straightforward Tautulli activity widget that reads a user-provided API key from a local .env file and makes HTTP requests to the user's Tautulli instance. The code is transparent and follows reasonable security practices, such as sending the API key via stdin and setting file permissions. The deterministic scan found no issues, and the sampled code shows no malicious behavior.

  • The plugin reads an API key from ~/.config/omatulli/.env, which is a sensitive credential. While the README explains this and the code sets 0600 permissions, users must be aware that the key grants access to their Tautulli/Plex monitoring data.
  • The plugin makes network requests to a user-configured baseUrl; if a user misconfigures it to an untrusted server, the API key could be sent to that server. However, this is user-controlled and not a plugin vulnerability.
  • The full source was not reviewed; only a sample of files was provided. A complete review of all QML and any shell scripts would be prudent before final approval.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/MarcusPelo/omatulli --enable
Widgets #bar #quickshell #media

Omatulli

An Omarchy bar widget for Tautulli, the Plex Media Server monitoring tool. See what's currently playing across your Plex server — movies, TV episodes and music — as stacked cards with posters, stream details, progress and ETA.

Panel History

Features

  • Bar chip — play icon + active stream count, with a tooltip summary (direct play/transcode split, total bandwidth)
  • Stacked cards — one card per active session, adapted per media type:
    • Movies: title + year
    • TV episodes: show + episode title, S{season} · E{episode}
    • Music: track + artist, album
  • Poster / album art — fetched from Tautulli's pms_image_proxy API command and cached locally under ~/.cache/omatulli/
  • Full stream detail — product, player, stream decision (Direct Play/Direct Stream/Transcode), container, video, audio, subtitle and quality lines, mirroring Tautulli's own Activity view
  • Progress bar with elapsed/total time and ETA (wall-clock finish time)
  • User avatar + name per session
  • Location privacy — shows WAN/LAN only by default instead of the public IP (toggle in settings)
  • History — last 10 played items (title, poster, user, time), one click/keypress away from the activity view

Requirements

  • A running Tautulli instance monitoring your Plex server
  • A Tautulli API key (Settings → Web Interface → API in the Tautulli web UI)

Install

omarchy plugin add https://github.com/marcuspelo/omatulli.git

Setup

  1. Create ~/.config/omatulli/.env with your Tautulli API key:
    API_KEY=your-tautulli-api-key
    URL_BASE=http://your-tautulli-host:8181
    
    Keeping the key in this file (outside the plugin folder) instead of shell.json keeps it out of any config you might sync or share. URL_BASE is optional but recommended: omarchy plugin disable/enable drops the widget's bar-layout entry (including whatever baseUrl was set via the panel or omarchy bar set), so a value in .env is what keeps working across that reset.
  2. Enable the widget and point it at your Tautulli instance:
    omarchy plugin enable marcuspelo.omatulli
    omarchy bar set marcuspelo.omatulli baseUrl "http://your-tautulli-host:8181"
    
    This step is optional if URL_BASE is already set in .env.

Security

The Tautulli API key never appears in process arguments or request URLs:

  • The get_activity call is a curl POST with the key sent over the child process's stdin (--data @-), not as a -H/URL argument — so it's invisible to ps/process inspection and to any HTTP access logs that record URLs.
  • Poster and album art images go through the same stdin-authenticated curl request into a local cache (~/.cache/omatulli/), then Image.source points at the cached file. This avoids putting the key in a plain Image { source: url } binding, which QML has no way to attach auth headers to.
  • ~/.config/omatulli/.env is set to mode 0600 automatically every time the plugin reads it. You can also set this yourself: chmod 600 ~/.config/omatulli/.env.

Configuration

Available settings (shell.json, or omarchy bar set marcuspelo.omatulli <key> <value>):

Setting Type Default Description
baseUrl string http://localhost:8181 Base URL of your Tautulli instance (no trailing slash). Falls back to URL_BASE in ~/.config/omatulli/.env when unset.
refreshIntervalSec integer 10 Seconds between background refreshes (5–300)
maskLocation boolean true Show only WAN/LAN instead of the full public IP address

Keyboard shortcuts

Key Action
r Refresh
v Open history
esc Close the panel

Remove

omarchy plugin remove marcuspelo.omatulli

License

MIT