Omahub
← All plugins
N

Keyboard languages

by NOmarkOO

Switch and manage keyboard languages directly from the Omarchy bar. Customize labels, add layouts and variants, remove them safely, and change the shortcut in a theme-aware Quattro panel.

Security review

Review recommended · 6 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
4b1d5cc
Scanned
3 weeks ago
  • medium external_hosts …/workflows/ci.yml:25

    Downloads or connects to an external HTTP(S) host.

    git clone --depth 1 --branch quattro https://github.com/basecamp/omarchy.git /tmp/omarchy
  • Docs curl_pipe_sh README.md:27

    Command downloads content and pipes it directly into a shell interpreter.

    curl -fsSL https://raw.githubusercontent.com/NOmarkOO/omarchy-keyboard-languages/f1f163c4e26482006c0f735faa0c3b28af586535/install.sh |
  • Docs curl_pipe_sh README.md:88

    Command downloads content and pipes it directly into a shell interpreter.

    curl -fsSL https://raw.githubusercontent.com/NOmarkOO/omarchy-keyboard-languages/f1f163c4e26482006c0f735faa0c3b28af586535/install.sh |
  • Docs external_hosts README.md:27

    Downloads or connects to an external HTTP(S) host.

    curl -fsSL https://raw.githubusercontent.com/NOmarkOO/omarchy-keyboard-languages/f1f163c4e26482006c0f735faa0c3b28af586535/install.sh |
  • Docs external_hosts README.md:39

    Downloads or connects to an external HTTP(S) host.

    git clone --no-checkout https://github.com/NOmarkOO/omarchy-keyboard-languages.git
  • Docs external_hosts README.md:88

    Downloads or connects to an external HTTP(S) host.

    curl -fsSL https://raw.githubusercontent.com/NOmarkOO/omarchy-keyboard-languages/f1f163c4e26482006c0f735faa0c3b28af586535/install.sh |

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4b1d5cc
Reviewed
3 weeks ago

This is a commit-pinned installer plus a QML bar widget that manages XKB layouts through hyprctl/xkbcli and writes only user-owned Omarchy configuration and state. The code is defensive: it validates input, requires a full commit SHA, and includes rollback/backup behavior with no obfuscation, credential access, telemetry, or destructive runtime behavior. The deterministic medium findings are driven by the README's curl-pipe installer and CI/documentation references to external hosts, not by the runtime plugin itself.

  • The README instructs users to pipe install.sh from raw.githubusercontent.com into bash; this is a supply-chain pattern even though the installer is pinned to a specific commit SHA.
  • The README's pinned install SHA (f1f163c...) differs from the analyzed snapshot commit (4b1d5cca...); a moderator may want to confirm that SHA corresponds to the reviewed v1.1.0 release.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/NOmarkOO/omarchy-keyboard-languages --enable
System #bar
<p align="center"> <img src="icon.svg" width="104" height="104" alt="Keyboard Languages icon"> </p>

Keyboard Languages for Omarchy

Release Checks MIT License

A compact, customizable keyboard-language indicator and complete XKB layout manager for the Omarchy Quattro bar.

Keyboard Languages across four Omarchy Quattro themes

Left-click the bar label to switch language. Right-click it to manage layouts, customize their bar aliases, add variants, remove layouts safely, or change the switching shortcut.

[!NOTE] This is an independent community plugin. It is not an official Omarchy or Basecamp project and is not supported by them.

You can also take a look at this project here: Omarchy Plugin Marketplace

Install

Run this exact-SHA command from a terminal inside your Omarchy desktop session:

curl -fsSL https://raw.githubusercontent.com/NOmarkOO/omarchy-keyboard-languages/f1f163c4e26482006c0f735faa0c3b28af586535/install.sh |
  bash -s -- --commit f1f163c4e26482006c0f735faa0c3b28af586535

The downloaded installer and installed plugin are both pinned to the same immutable v1.1.0 commit.

The installer imports your current layouts, variants, group shortcut, and other XKB options. It replaces the stock keyboard indicator, places itself immediately before the tray, and restarts only omarchy-shell. It never reloads Hyprland.

Prefer to inspect scripts before running them?

commit=f1f163c4e26482006c0f735faa0c3b28af586535
git clone --no-checkout https://github.com/NOmarkOO/omarchy-keyboard-languages.git
cd omarchy-keyboard-languages
git checkout --detach "$commit"
less install.sh
./install.sh --commit "$commit"

The installer is idempotent. It also migrates the earlier copied nomarkoo.keyboard-layout installation to a normal Git-managed Omarchy plugin and keeps a recoverable backup.

What it does

  • Shows the active layout as a compact automatic label or a custom alias of up to six characters.
  • Switches to the next configured layout on left-click.
  • Opens a keyboard-first, screen-aware manager on right-click.
  • Discovers installed XKB layouts, variants, and valid group shortcuts.
  • Keeps a Latin layout first so Quattro's SUPER + letter bindings remain usable.
  • Prevents deletion of the last remaining layout.
  • Preserves Compose and other non-group XKB options.
  • Applies changes through targeted Hyprland IPC with rollback—no compositor reload and no session interruption.
  • Fits top, bottom, left, and right bars, including multi-monitor setups.
  • Inherits every active Quattro theme automatically.

Native by construction

This plugin is intentionally extremely close to first-party Quattro modules in both appearance and behavior. It directly composes the shell's shared WidgetButton, KeyboardPanel, PanelHero, PanelKeyCatcher, Button, BorderSurface, CursorSurface, and ConfirmDialog primitives. Spacing, typography, borders, focus, color, anchoring, and popup behavior come from qs.Ui and qs.Commons, not a parallel visual imitation.

It remains a third-party plugin because it is distributed outside the Omarchy repository. Quattro's public interfaces can evolve, so each release is tested against the current Quattro branch.

Across Quattro themes

Matte Black · manager Catppuccin · alias editor
Main language manager in Matte Black Bar-alias editor in Catppuccin
Flexoki Light · shortcut Gruvbox · remove confirmation
Shortcut picker in Flexoki Light Removal confirmation in Gruvbox

Requirements

  • Omarchy Quattro 4.0 or newer.
  • A live Hyprland session for first installation.
  • git, jq, xkbcli, and the standard Omarchy plugin commands.

These dependencies are present on a standard Quattro system. The first install deliberately stops without changing anything if it cannot read either existing plugin state or the live keyboard configuration.

Update

Use the exact-SHA command from the newest GitHub release. For v1.1.0, rerun:

curl -fsSL https://raw.githubusercontent.com/NOmarkOO/omarchy-keyboard-languages/f1f163c4e26482006c0f735faa0c3b28af586535/install.sh |
  bash -s -- --commit f1f163c4e26482006c0f735faa0c3b28af586535

It updates the existing checkout only after fetching and verifying that reviewed commit. Local edits inside the installed plugin are never overwritten.

Omarchy's native plugin updater follows mutable upstream HEAD; that is useful for testing current development but is not bound to the Marketplace-reviewed release snapshot.

Remove

From the installed plugin directory:

~/.config/omarchy/plugins/nomarkoo.keyboard-layout/uninstall.sh

This restores the stock keyboard indicator, backs up the plugin checkout, and preserves the current keyboard configuration. To remove the plugin-owned state too, log out of Hyprland first and run the backed-up script with --purge-state. Purging is refused inside a live session because removing an active keyboard override can trigger unsafe compositor reconfiguration.

Configuration and recovery

Mutable data stays outside the Git checkout:

~/.local/state/omarchy/settings/nomarkoo-keyboard-layout.json
~/.local/state/omarchy/toggles/hypr/nomarkoo-keyboard-layout.lua

The JSON document is the source of truth; the Lua file is generated for Omarchy's user-toggle loader. The installer creates timestamped shell.json backups and keeps its first-install snapshot under:

~/.local/state/omarchy/settings/nomarkoo-keyboard-layout-install-backup/

Custom bar aliases are stored with their layout or variant in the JSON state. Clearing an alias in the panel restores the automatic label; alias-only edits never reapply the XKB keymap.

If the panel cannot start, restore the newest ~/.config/omarchy/shell.json.bak.* and run omarchy restart shell. Open a bug report with your Omarchy and Hyprland versions if the problem continues.

Security

Omarchy plugins execute unsandboxed QML and processes inside the long-lived shell. Review code before enabling any plugin; the official Omarchy plugin manual gives the same warning.

This plugin performs no telemetry and makes no runtime network requests. The installer requires a full commit SHA, checks out that exact commit in detached mode before executing repository helpers, writes only user-owned Omarchy configuration/state paths, and invokes one omarchy restart shell. It requires no elevated privileges, edits no packaged Omarchy files, and never reloads Hyprland.

Development

./test.sh

The suite validates the manifest and QML, parses the live XKB catalog, exercises add/remove/shortcut rollback with a fake Hyprland endpoint, and tests clean install, copied-plugin migration, idempotency, origin conflicts, offline refusal, activation rollback, and uninstall recovery.

See CONTRIBUTING.md and docs/architecture.md for the release and runtime design.

License and attribution

Released under the MIT License. Omarchy is an independent MIT-licensed project by Basecamp; its name and project links are used only to identify compatibility. See the Omarchy repository.

Custom bar aliases were inspired by @msouza10, whose contribution highlighted the need for user-defined layout labels.