Omahub
← All plugins
H

Mihoro

by huacnlee

A Clash-style proxy client for Omarchy, running the Mihomo (Clash.Meta) core: connection status, live up/down speed, Rule, Global and Direct switching, proxy-node selection with delay tests, TUN toggling, and several Clash subscriptions to switch between, driven by the mihoro CLI.

Security review

Potentially dangerous behavior detected · 15 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
984689a
Scanned
4 days ago

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
984689a
Reviewed
3 days ago

The deterministic scan's high-risk findings are mostly documentation and test fixtures: the README's curl|sh and sudo snippets are upstream install instructions, not executed by the plugin, and the crontab references in tests are isolated test doubles. The only real persistence is scripts/timer_manager.py, which installs a user-level systemd timer to run subscription updates when auto_update_interval is set; this is a plausible feature but is not clearly documented in the README and deserves a human look. No obfuscation, root escalation, credential exfiltration, or destructive install behavior was found.

  • scripts/timer_manager.py installs and enables a user systemd timer and also removes existing crontab lines matching 'mihoro update'; this persistent behavior is not mentioned in the README or manifest, so a moderator should confirm it is only triggered with clear user consent.
  • The README's curl | sh and sudo setcap commands are documentation only and are not executed by the plugin, but they could be mistaken for plugin behavior.
  • Subscription URLs are bearer credentials; they are stored in ~/.config/mihoro/subscriptions.json with 0600 permissions and only sent to their own hosts, which is appropriate.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/huacnlee/omarchy-mihoro --enable
Widgets #bar #quickshell #security

Mihoro for Omarchy

An Omarchy bar panel for mihoro, the Mihomo CLI client for Linux.

<img width="400" alt="Mihoro for Omarchy" src="preview.png" />

Use it to monitor your proxy, switch between Rule, Global, and Direct modes, pick a proxy node per group with measured delays, toggle TUN, keep several subscriptions to switch between, and prepend per-subscription local routing rules without losing them on automatic updates.

Features

  • Connection status, live up/down speed, and a one-minute traffic history
  • Rule / Global / Direct switching against the running core
  • Per-group proxy-node switching (proxy-node style): each selector group's nodes with their last delay, a test button for fresh measurements, and fastest-first ordering — press n in the panel to jump there
  • TUN toggle (runtime only; a restart restores config.yaml)
  • Multiple subscription URLs with switching and updates
  • Per-subscription local routing rules, prepended on every update

Requirements

Getting Started

Open the panel and choose Install Mihoro.... The panel shows whether the CLI is installed, reports its detected version, and links to Mihoro's official installation guide. The guide remains available from the panel menu after installation.

You can also follow the upstream installation instructions from the panel menu or install it manually.

Install & initialize it and enter your subscription URL when prompted:

curl -fsSL https://raw.githubusercontent.com/spencerwooo/mihoro/main/install.sh | sh -s -- --mirror https://gh-proxy.org
MIHORO_GITHUB_MIRROR=https://gh-proxy.org mihoro init

For TUN mode, grant mihomo the required capabilities and restart it:

sudo setcap cap_net_admin,cap_net_raw,cap_net_bind_service=+ep ~/.local/bin/mihomo
getcap ~/.local/bin/mihomo
systemctl --user restart mihomo.service

Install the Omarchy plugin:

omarchy plugin add https://github.com/huacnlee/omarchy-mihoro.git --enable

Remove the Omarchy plugin:

omarchy plugin remove mihoro.omarchy

The panel looks for the mihomo binary where mihomo_binary_path in ~/.config/mihoro.toml says it is, and falls back to your PATH. If you installed mihomo somewhere else, point that key at it.

Subscriptions

mihoro holds one subscription at a time — remote_config_url in ~/.config/mihoro.toml — so the panel keeps the list and hands the selected one down. Open Subscriptions... from the panel menu (or press s) to add, name, edit, and remove them; clicking a row switches to it, which writes its URL into mihoro.toml and runs mihoro update --config to fetch it.

Whatever mihoro.toml already points at becomes the first entry the first time the panel runs, so nothing is lost on upgrade, and a URL you later set with mihoro init or by hand is picked up as an entry rather than overwritten. Removing the last subscription clears remote_config_url, returning the panel to its not-set-up state.

The list lives in ~/.config/mihoro/subscriptions.json, written 0600 — subscription URLs are bearer credentials, so they are kept out of shell.json and never rendered outside the editor.

From a script:

omarchy-shell mihoro.omarchy subscriptions     # names and ids, no URLs
omarchy-shell mihoro.omarchy select Backup     # switch by name or id

If mihomo does not start, inspect its recent logs:

journalctl --user -u mihomo.service -n 30 --no-pager

User agent

Subscription downloads identify with mihoro_user_agent in ~/.config/mihoro.toml — mihoro's own setting, mihoro by default. Both fetch paths use it: the CLI's mihoro update --config and the panel's enhanced update. If a provider hands out configs only to particular clients, set it there by hand. The value goes out as an HTTP header, so it has to be Latin-1 — a name written in Chinese falls back to mihoro, which is what mihoro's own fetch would send anyway:

mihoro_user_agent = "clash-verge/1.2"

Development

make test
make validate

License

MIT. mihoro and mihomo are distributed separately under their own licenses.

More Omarchy projects

  • Omamail — A mail plugin for Omarchy with Gmail, HEY, and IMAP support. Read and manage email right from the desktop.
  • Omasend — A native LocalSend client for Omarchy. Share files, folders, and text over your local network. Built with GPUI Kit for Linux, macOS, and Windows.
  • omarchy-which-key — Which Key for the desktop. Hold Super to see a shortcut guide drawn from your active Omarchy and Hyprland keybindings.