Omahub
← All plugins
R

Omasis

by ronnie

Browse, search, and one-click install community Omarchy plugins from omarchyplugins.com

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
7324068
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:26

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/Macs9319/Omasis.git ~/.config/omarchy/plugins/omasis

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
7324068
Reviewed
1 month ago

The plugin is a marketplace browser that fetches a public registry and installs plugins via the standard `omarchy plugin add` CLI. It includes defensive sanitization (repo URL allowlist, security outcome clamping, label sanitization) and performs no destructive or hidden actions. The deterministic finding about an external host refers to a documented git clone command in the README, which is illustrative and not part of the executable code.

  • The plugin fetches a community-editable registry over HTTPS; while the code sanitizes fields and restricts installs to plain GitHub URLs, the registry content is untrusted by design.
  • One-click installs rely on the external `omarchy plugin add` command; the plugin itself does not validate the target plugin's code beyond the URL allowlist.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Macs9319/Omasis --enable
Widgets #bar #launcher

Omasis

A community plugin marketplace browser for the Omarchy shell bar. Browse, search, and filter the plugin registry behind omarchyplugins.com and install anything in it with one click — all from the bar, no browser or terminal required.

<p align="center"> <img src="screenshots/bar-icon.png" alt="Bar icon" width="500"><br> <img src="screenshots/panel.png" alt="Omasis panel" width="360"> </p>

Install

Option 1 — omarchy plugin add (recommended):

omarchy plugin add https://github.com/Macs9319/Omasis.git --enable

You'll be prompted to pick a bar section (left/center/right) for the icon.

Option 2 — manual clone:

git clone https://github.com/Macs9319/Omasis.git ~/.config/omarchy/plugins/omasis
omarchy plugin enable omasis right

Either way, the shell picks up the plugin without a restart — edits under ~/.config/omarchy/plugins/ hot-reload automatically.

Usage

Click the 🧩 bar icon to open the browser. Type in the search box to filter by name, author, or tag; click a category chip to narrow the list further.

Each card shows an install button:

  • Get — installs the plugin directly via omarchy plugin add, the same CLI you'd run by hand. Clone, manifest validation, and enabling are all handled by that command.
  • View — opens the plugin's repo on GitHub instead. Used for plugin suites, entries the registry flags as needing manual setup, and repositories that bundle more than one plugin (which omarchy plugin add can't install a single one from yet).
  • ✓ Installed — already present on this system.

A ↻ refresh button in the header re-fetches the registry on demand; it also refreshes automatically once an hour.

Data source

The registry data comes from HANCORE-linux/omarchy-plugin-marketplace — the same feed that backs omarchyplugins.com. Most entries in that registry carry only an id, category, and tags (no name/description/author), so Omasis derives a display name from the plugin id and an author from the repo owner where the registry doesn't supply them directly.

Configuration

Settings live on the plugin's bar entry in ~/.config/omarchy/shell.json (hot-reloads on save). Defaults:

Setting Default Meaning
refreshHours 1 How often to re-fetch the registry (minimum 1)

Example entry:

{ "id": "omasis", "refreshHours": 6 }

Uninstall

omarchy plugin remove omasis

License

MIT — see LICENSE.