Omahub
← All plugins
O

Go to Space

by Oscar Casado

A live countdown and flight manifest for upcoming rocket launches.

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
ab1dcb2
Scanned
1 month ago
  • high persistence reminder.sh:76

    Registers scheduled or boot-time system tasks.

    systemd-run --user --quiet --collect --on-calendar="@$target_epoch" \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
ab1dcb2
Reviewed
1 month ago

The deterministic finding flags a systemd-run call in reminder.sh, but that is the plugin's explicit, user-triggered reminder feature, not hidden persistence or an install-time action. The rest of the code is a straightforward HTTPS launch-data widget with sanitized output and strict validation around reminder units and paths, and no elevated privileges or destructive behavior were found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ocasadoc/gotospace --enable
Widgets #bar

Go to Space

A live rocket-launch countdown and flight manifest for the Omarchy Quattro bar.

Preview

Go to Space launch panel

Installation

omarchy plugin add https://github.com/ocasadoc/gotospace.git --enable

The plugin is installed as ocasadoc.gotospace and appears in the right section of the bar by default.

Usage

  • Click the bar countdown to open or close the launch manifest.
  • Click a launch to open its public detail page on Space Launch Now.
  • Select REMIND ME, enter the lead time in minutes, and press Enter or SET. The action changes to CANCEL REMINDER while that launch reminder is active.
  • Middle-click the bar widget, or press R in the panel, to refresh.
  • Use the arrow keys or mouse wheel to scroll. Press Escape to close.

Launches refresh every 20 minutes. Times are shown in the system's local time. Automatic requests are throttled to at most one every five minutes; an explicit refresh retries immediately with a short click-spam guard.

Dependencies

  • Omarchy Quattro with shell plugin support
  • curl for Launch Library 2 requests
  • A user systemd session for launch reminders
  • GNU coreutils, included in the Omarchy base system, for protected reminder files

Data and privacy

Launch data comes from the public Launch Library 2 API operated by The Space Devs. Unauthenticated access is free for up to 15 requests per hour. The panel always uses its bundled star field and does not load image URLs supplied by the API.

The plugin runs curl without elevated privileges and sends no local data beyond the IP address inherently visible to the API request. API responses are limited to 1 MiB, displayed text is normalized and length-limited, and launch links are restricted to HTTPS pages on spacelaunchnow.me. Successfully normalized launch data is retained in the runtime-created launch-cache.json inside the plugin directory.

Reminder message files are created only inside an owned, non-symlink XDG_RUNTIME_DIR; the helper refuses unsafe directories and existing message paths. Reminder cancellation and cleanup accept only units ending in ocasadoc.gotospace.

Removal

Clear reminders created by Go to Space before removing the plugin, because their systemd timers can outlive the plugin files:

bash "$HOME/.config/omarchy/plugins/ocasadoc.gotospace/reminder.sh" clear
omarchy plugin remove ocasadoc.gotospace

This removes the plugin and its launch cache. It does not clear reminders created by other applications.

License

The plugin code and bundled DefaultStars.svg artwork are available under the MIT License. The preview is a capture of the plugin using that bundled artwork and contains no third-party launch image.

Development

plugin_dir="$HOME/.config/omarchy/plugins/ocasadoc.gotospace"
omarchy plugin validate "$plugin_dir"
qmllint -I "$OMARCHY_PATH/shell" \
  "$plugin_dir/BarWidget.qml" \
  "$plugin_dir/Panel.qml" \
  "$plugin_dir/LaunchService.qml"