Omahub
← All plugins
O

Tailscale

by OberdanSoldi

Tailscale status, on/off switching, login, exit nodes, machine browsing, copy actions, and Taildrop in the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
4a05e7c
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4a05e7c
Reviewed
1 month ago

This is a Tailscale status widget that interacts with the official `tailscale` CLI to show status, toggle the tunnel, switch accounts, and send files. The code is clean, well-structured, and uses only expected commands with no obfuscation or hidden behavior. The only security-relevant aspect is that it can run `pkexec` to grant operator access, but that is user-initiated and clearly documented.

  • The plugin can run `pkexec tailscale set --operator=<user>` to grant operator privileges, which is a sensitive operation, but it is user-initiated and clearly described in the README.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/OberdanSoldi/omarchy-tailscale --enable
Widgets #bar #quickshell #system

Tailscale for Omarchy

A status-bar plugin for Omarchy Quattro that puts your tailnet on the desktop instead of in a terminal.

Click the dot-grid mark to see whether you are connected, flip the tunnel on or off, pick an exit node, browse the machines on your tailnet, copy their addresses, and send files with Taildrop. Right-click the icon to toggle Tailscale without opening the panel. It talks to the official tailscale CLI, so the daemon you already trust is still what is running.

Tailscale panel on the Omarchy bar

Install

omarchy plugin add https://github.com/OberdanSoldi/omarchy-tailscale.git --enable

Requires the tailscale CLI on PATH (the panel tells you if it is missing).

From a local checkout (before or without publishing):

ln -s "$PWD" ~/.config/omarchy/plugins/nino.tailscale
omarchy-shell shell rescanPlugins
omarchy plugin enable nino.tailscale

Remove

omarchy plugin remove nino.tailscale

That disables the widget and deletes the plugin checkout. It does not uninstall Tailscale, stop tailscaled, log you out, or change other Omarchy config. If you used the one-click operator authorization, it also does not revoke that grant — see below.

Use

  • Left click: panel
  • Right click: toggle Tailscale up/down
  • Middle click: refresh status
  • Panel: power switch, connection switching, exit-node picker, machine list with copy menu and Taildrop send

Keys inside the panel: j/k or arrows move, Enter/Space activates, t toggle Tailscale, r refresh, c copy peer IP, n copy peer name, d copy peer DNS name, s send files, Esc closes.

Behavior notes

  • The bar icon is the Tailscale mark rendered natively as a 3x3 dot grid; it dims and gains a slash when the tunnel is down, and a ! badge when the device needs login or the daemon reports health warnings.
  • Toggling is optimistic: the icon and switch react the instant you click, and reality catches up on the next status poll.
  • If the tunnel drops without you asking, you get one critical desktop notification.
  • The CONNECTIONS section lists every logged-in profile (tailscale switch --list), so you can hop between accounts and tailnets with one click; it appears once more than one profile exists. If the daemon denies profile access, the section offers a one-click pkexec tailscale set --operator=<you> authorization. Tailscale has no read-only operator role: this grants the selected user full sudo-less control of the daemon (starting/stopping the tunnel, changing settings, switching profiles), and the grant lives in the daemon's state — it persists until revoked, including after removing the plugin. Revoke it with pkexec tailscale set --operator= (empty value).
  • The footer line (login, tailnet, own IP) is clickable and copies your Tailscale IP.
  • Taildrop send only appears when the tailnet allows file sharing and the peer accepts files; it hands off to omarchy-tailscale-send.

Requirements

  • Omarchy 4.0.0+ / omarchy-shell (bundles omarchy-tailscale-send, used for Taildrop)
  • tailscale on PATH
  • wl-copy for clipboard copy actions

Dev

node --test tests/*.test.js
omarchy plugin validate .
/usr/lib/qt6/bin/qmllint -I /usr/share/omarchy/shell -I /usr/lib/qt6/qml Panel.qml Service.qml TailscaleIcon.qml

The Model.js tests never touch the real CLI or change any state. The qmllint run reports the same import-resolution warnings as the stock Omarchy panels; the authoritative check is omarchy plugin validate plus loading the plugin in the shell.