Omahub
← All plugins
W

OmaPets

by Wei Zhu <yesmeck@gmail.com>

An animated Codex-compatible pet that reflects coding-agent activity in the Omarchy top bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
2d4fa03
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2d4fa03
Reviewed
1 month ago

The plugin is a well-engineered bar widget that downloads pet packages from a small allowlist of hosts and installs activity hooks into coding agents. All network access is HTTPS-only, redirects are validated, file sizes are capped, and config modifications are atomic with symlink protection and backups. No obfuscation, credential theft, or destructive behavior was found.

  • Downloads third-party pet packages (spritesheets, pet.json) from petdex.dev, codex-pets.net, and openpets.dev; while hosts are allowlisted and content is validated, the spritesheets are processed with ImageMagick, which could be a vector if a malicious image exploits a system vulnerability.
  • Installs hooks into coding-agent config files (Codex, Claude, etc.) which modifies user configuration; this is user-initiated via the panel and the installer is careful, but it does alter files outside the plugin directory.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/yesmeck/OmaPets --enable
Widgets #ai

OmaPets

OmaPets puts an animated coding companion in the Omarchy top bar. Your pet reacts while your coding agent works, waits for input, finishes, or encounters an error.

https://github.com/user-attachments/assets/be318ba0-94ea-4dd5-a315-9245acc02349

Install the plugin

Install and enable OmaPets:

omarchy plugin add https://github.com/yesmeck/OmaPets.git --enable --yes

Click the pet in the bar to open the OmaPets panel.

Bundled pet

OmaPets includes Glitchcat from Petdex as its default pet.

Install a pet

Open the OmaPets panel and select Install pet. Paste a pet URL from Petdex, Codex Pets, or OpenPets. When installation finishes, close the terminal and select your new pet from the panel.

Agent status

OmaPets detects agent activity automatically. For more accurate status changes, open the panel and select Agent hooks. Use Space to select your coding agents, then press Enter. Restart any open agent sessions after installation.

Usage

Left-click the pet to list installed pets and switch between them. The choice is saved in the bar configuration. Select Open folder to browse the installed pet files. Right-click cycles through pet statuses, and middle-click previews success. Hover for the current state and detail.