Omahub
← All plugins
J

OmarGram

by JoeJoeflyn

Native status bar Telegram client for Omarchy. Fast chat previews, instant messaging, unread notifications, and QR-code login.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
be19301
Scanned
2 days ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs package_manager README.md:34

    System-wide Python package installation (not --user).

    pip install telethon`) |
  • Docs package_manager README.md:35

    System-wide Python package installation (not --user).

    pip install qrcode[pil]`) |
  • Docs package_manager README.md:36

    System-wide Python package installation (not --user).

    pip install pillow`) |

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
be19301
Reviewed
2 days ago

OmarGram is a legitimate Telegram client that runs a background daemon with strict file/socket permissions and uses the official Telethon library. The deterministic scan flagged README lines about system-wide pip installs, but those are just package-name examples; the actual install command uses --user. No obfuscation, hidden persistence, or destructive behavior was found.

  • The daemon uses a broad pkill pattern (`python3.*omargram_daemon\.py`) which could theoretically match unrelated processes, though it is specific enough to be low risk.
  • The plugin stores Telegram session tokens locally; permissions are enforced (0700/0600), but a compromised user account could expose them.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/JoeJoeflyn/omargram --enable
Widgets #bar #quickshell

OmarGram 💬

Native, lightweight Telegram status bar client for the Omarchy Quattro Desktop.

OmarGram lets you read and reply to your Telegram chats directly from the Omarchy status bar on the same screen, without needing to open a new window for Telegram. It is designed to be lightweight, snappy, and consume minimal RAM.

Omargram Preview


✨ Features

  • 💬 Live Unread Badge: Real-time unread message counter directly in the Omarchy bar.
  • 📱 1-Click QR Code Login: Scan the QR code with your phone (Telegram Settings → Devices → Link Desktop Device) to log in in 3 seconds.
  • ⚡ Two-Column Fluid Layout: Sidebar with Direct Messages, Groups, and Channels + smooth-scrolling conversation stream.
  • 🚀 Instant Message Composer: Quick-reply input with Enter to send and Shift+Enter for multiline formatting.
  • ✏️ Edit & Pin Messages: Edit sent messages inline and pin/unpin important messages with a direct jump banner.
  • ↗️ Forward & Multi-Select: Batch select messages with custom checkboxes to forward, copy, or delete at once.
  • 🎨 Theme-Native Visuals: Matches your active Omarchy colorway, dynamic accent colors, and custom typography.
  • 🔒 Security-First Architecture:
    • Encrypted MTProto Transport: Official client-to-server MTProto 2.0 protocol directly to Telegram cloud servers.
    • Owner-Only Local Caching: Enforces strict 0700 directory modes and 0600 file permissions on ~/.config/omargram and ~/.cache/omargram to protect user metadata and session tokens from other local users.
    • Isolated IPC & PID Verification: Dedicated UNIX socket in $XDG_RUNTIME_DIR/omargram with 0600 socket permissions and PID starttime verification preventing process hijacking or PID-reuse termination.
    • Injection & SSRF Safe: All incoming message text and remote metadata strictly rendered as Text.PlainText.

📦 External Dependencies

OmarGram requires the following Python libraries for MTProto communication and QR code rendering:

Dependency Purpose Package
python-telethon Native Telegram MTProto API client python-telethon (or pip install telethon)
python-qrcode QR code generation for instant phone pairing python-qrcode (or pip install qrcode[pil])
python-pillow Image handling and profile avatar caching python-pillow (or pip install pillow)

Install Dependencies:

python3 -m pip install --user telethon qrcode[pil] pillow

📥 Installation

Install OmarGram using the Omarchy CLI:

omarchy plugin add https://github.com/JoeJoeflyn/omargram --enable
omarchy restart shell

Manual Bar Configuration

Add "omargram" to your desired status bar section in ~/.config/omarchy/shell.json:

{
  "bar": {
    "sections": {
      "right": [
        "omargram",
        "omarmail",
        "omaramp",
        "omarchy.audio"
      ]
    }
  }
}

⌨️ Shortcuts & Navigation

Key Action
Click Bar Icon Toggle OmarGram popout window
Enter (in composer) Send message immediately
Shift + Enter Insert newline in message
Click Chat Open chat & mark messages as read
Esc Close active chat or hide panel

🗑️ Removal & Uninstallation

To disable and remove OmarGram:

omarchy plugin disable omargram
omarchy plugin remove omargram
omarchy restart shell

To purge cached avatars and session data:

rm -rf ~/.config/omargram ~/.cache/omargram

📄 License

MIT © JoeJoeflyn