Omahub
← All plugins
G

Quattro Command

by Gavin Nugent

A vector missile-defence cabinet for omarchy-shell. Six cities, three launchers, warheads that split and bombs that dodge — drawn as glowing vectors on a curved phosphor screen in your live theme colours. Summon with: omarchy-shell shell toggle nosignal.quattro-command

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
25c0016
Scanned
1 month ago
  • medium sudo install.sh:59

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S qt6-multimedia"
  • Docs sudo README.md:124

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S qt6-multimedia`

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
25c0016
Reviewed
1 month ago

The plugin is a QML game that runs entirely within the user's shell session, writing only to its own state directory and appending an idempotent entry to the user's shell config. The flagged 'sudo' commands appear only in documentation and the installer script as a suggestion for installing an optional audio dependency, and are never executed by the plugin itself.

  • The plugin modifies ~/.config/omarchy/shell.json via jq on first open, but this is documented, idempotent, and only appends its own plugin entry.
  • The installer script runs `omarchy plugin add` and `omarchy bar move`, which are standard plugin manager commands and do not require elevated privileges.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/28allday/Quattro-Command --enable
Widgets #bar #quickshell #games

Quattro Command

Missile defence as a native Omarchy shell plugin. Six cities and three launchers under a night sky, drawn as glowing vectors on a curved phosphor screen — in your live theme, so it recolours the moment your desktop does.

Wave six

  • Warheads fall on your cities; you have thirty rounds a wave and eight interceptors in the air at once
  • From wave three they split into three on the way down, and from wave five some of them steer around your explosions
  • Bombers, satellites and killer satellites cross overhead from waves two, four and eight
  • Explosions carry no outline, so overlapping ones merge into one wall of fire — chaining them is where the scores are
  • Three cities can fall per wave, and every 10,000 points buys one back
  • The palette rotates every two waves, so wave nine never looks like wave one
  • High scores with three-letter initials, kept between sessions

Install

omarchy plugin add https://github.com/28allday/Quattro-Command --enable

Or with the installer, which does the same thing and places the bar icon:

./install.sh

Then click the in the bar, or bind a key to:

omarchy-shell shell toggle nosignal.quattro-command

install.sh takes two optional overrides: QCOMMAND_SECTION picks the bar section (left, center or right, default right), and QCOMMAND_REPO registers the plugin from a fork instead.

Removal

omarchy plugin remove nosignal.quattro-command

That unregisters the plugin and drops its bar icon. High scores are left behind; delete those too with:

rm -rf ~/.local/state/omarchy-quattro-command

Playing

Input Action
Mouse Aim
Left click Fire from whichever launcher is best placed
Right click Fire from Kilo specifically
A / S / D Fire from Bravo, Kilo or Sierra by name
1 / 2 / 3 The same three
Enter Start, and dismiss the end screens
F1 Curved-screen effect on or off
M Mute
Escape Close the cabinet

Kilo, in the centre, flies three times faster than the other two — it is the one you want when something is already low. Bravo and Sierra are slower but they sit out at the edges, and a warhead falling on the far right is not Kilo's problem to solve.

Watch what you spend. Unused rounds are worth points at the end of every wave, multiplied by the wave multiplier shown under the wave number, so a wave cleared with rounds to spare pays considerably better than one you sprayed.

A fireball holds full size for half a second. That is long enough for the next warhead to fly into it, which is the whole game: aim where something will be, not where it is.

The waves

Wave What arrives
1 Warheads
2 Bombers
3 MIRVs — one warhead that becomes three. They fly on twin exhausts until they split, which is your only warning
4 Satellites
5 Smart bombs — they steer away from your fireballs
8 Killer satellites

Warheads get faster and more numerous every wave, and stop getting worse at wave 19.

Scoring

Target Points
Warhead 25
Smart bomb 125
Bomber 100
Satellite 100
Killer satellite 150
Unused round, at the end of a wave 5
Surviving city, at the end of a wave 100

Everything is multiplied: ×1 for waves 1–2, ×2 for 3–4, and so on to ×6 from wave 11.

Title screen Wave two
Wave four Wave five
Bonus points

Dependencies

Omarchy 4 and its shell. Two optional extras:

  • qt6-multimedia for sound. Omarchy does not install it by default and the game plays perfectly well without it — it just plays silently. sudo pacman -S qt6-multimedia
  • jq, which Omarchy already installs, for one piece of plumbing described below.

Nothing is fetched or built at install time. The ten sounds ship as WAVs and the three shaders ship pre-compiled.

What it writes, and what it does not

  • ~/.local/state/omarchy-quattro-command/state.json — the high score table, the mute setting and whether the curved screen is on. Written when one of those changes.
  • ~/.config/omarchy/shell.json — on first open, the plugin appends its own {"id": "nosignal.quattro-command"} entry to plugins[] if one is not already there, using jq. This is a workaround: omarchy plugin enable writes only the bar-layout entry for a plugin that is both a panel and a bar widget, so without that entry the keybinding stops working the moment the bar icon is removed. The edit is idempotent, appends only, changes no other setting, and goes away once upstream PR #6510 lands. The code is near the top of Panel.qml if you would rather read it than take my word.

Nothing else on the system is touched. The plugin makes no network requests, needs no credentials, runs nothing privileged, and starts no process beyond the jq edit above and a mkdir -p for its own state directory.

Theme

Colours come from the shell, live. Switching desktop theme recolours the game mid-wave, and the game's own rotation moves the mapping on every second wave, so the cities, the sky and the trails all shift as you go. The screenshots above are one theme, across waves two, four, five and six.

The curved screen — barrel distortion, scanlines, an aperture-grille mask and a vignette — is on by default. F1 switches it off if you would rather have the flat, sharper picture.

Where things live

Path What
manifest.json Plugin manifest — panel + bar-widget, keepLoaded
Panel.qml The cabinet: window, focus, theme, high scores on disk
game/ The game itself, with no dependency on the shell
shaders/ Bloom and curved-screen shaders, source and compiled
audio/ Ten synthesised sounds, plus the script that renders them
~/.local/state/omarchy-quattro-command/state.json High scores and settings

Originality

This is a missile-defence game, and it is not the first one. What it owes to the genre are its rules — defend cities, three launchers, warheads that split, explosions that chain — and rules are not anyone's property.

Everything you can see or hear is this project's own. The city outlines and the launchers were drawn by hand in the game's own coordinate space, the sky and the starfield are generated at runtime, the ten sounds are synthesised by audio/make_sounds.py, and the three shaders were written for this. No code, art, audio or text has been taken from any commercial game, and there is no affiliation with, or endorsement by, any game publisher.

Licence

MIT.