Omahub
← All plugins
P

Quick Notes

by Pilpup

A lightning-fast sticky note plugin built in c++.

Security review

Potentially dangerous behavior detected · 2 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
65d74b0
Scanned
2 weeks ago
  • high shell_profile src/quicknote.cpp:326

    Redirects content into a home directory shell profile.

    source ~/.bashrc 2>/dev/null; source \"$1\"; rm -f \"$1\"; exec bash";
  • Docs external_hosts README.md:62

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/Pilpup/quick-note

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
65d74b0
Reviewed
2 weeks ago

The plugin is a sticky-note widget with a user-initiated 'run in terminal' feature that executes selected text via a temporary script. The deterministic scan's high finding about shell profile redirection is a false positive: the code sources ~/.bashrc and a temp file, but does not write to any profile. The external host finding is documentation-only (git clone for building from source). No hidden persistence, credential theft, or destructive install-time behavior was found.

  • The 'Run in Terminal' feature executes arbitrary user-selected text in a shell; this is an intended feature but could be dangerous if the user runs untrusted content.
  • The 'Save to File' feature writes to user-specified paths, which is also user-initiated and not inherently malicious.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Pilpup/quick-note --enable
Productivity #quickshell
<div align="center">

QuickNote for Omarchy

A lightning-fast, sticky note plugin designed natively for the Omarchy shell.

</div>

Preview

QuickNote Preview

Features

  • Floating Sticky Notes: Right-click the icon to spawn notes directly on your desktop.
  • 7 Independent Tabs: Quickly switch between multiple notes (Ctrl+B).
  • Interactive Checkboxes: Click on [ ] or [x] in your text to instantly toggle them.
  • Run in Terminal: Highlight text and press Ctrl+T to run it in Bash.
  • Save to File: Press Ctrl+S to export notes to a specific file.
  • Drag & Drop: Easily drop text files or snippets straight into your notes.
  • Clickable Links: Click any URL to instantly open it in your browser.
  • Quick Typing Test: Press Ctrl+K to start a quick typing test on your note.

Keyboard Shortcuts

(Press Ctrl+H at any time while the panel is open to view this)

Shortcut Action
Ctrl+P Pin/Unpin the current tab to your desktop as a sticky note
Ctrl+B Cycle to the next buffer
Ctrl+T Run selected text (or entire buffer) in terminal
Ctrl+R Clear the entire buffer
Ctrl+S Open the "Save as:" prompt
Ctrl+H Show the shortcut help overlay
Ctrl+K Start typing test
Ctrl++ / Ctrl+- Increase / Decrease editor font size
Escape Close the panel or hide the active overlay

Installation

omarchy plugin add https://github.com/Pilpup/quick-note --enable

Update

omarchy plugin update my.quicknote

Uninstallation

omarchy plugin remove my.quicknote

Development & Building from Source

If you want to contribute to the code and build it manually from the main branch:

git clone https://github.com/Pilpup/quick-note
cd quick-note

# Compile the C++ binaries in-place
./build.sh