Omahub
← All plugins
S

Omwatch

by STUDIOSELFHQ

A TMDB watchlist for Omarchy: Kanban board, trending discovery, ratings, TV progress, and a details view.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
083f647
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
083f647
Reviewed
1 month ago

The plugin is a well-structured TMDB watchlist that stores its API key securely (0700/0600 permissions, passed to curl via a private config file rather than argv) and only makes network calls to TMDB endpoints. No obfuscation, destructive commands, or hidden persistence were found; the deterministic scan also reported no issues.

  • The plugin stores a TMDB API key in plaintext at ~/.local/state/omarchy/omwatch/library.json, but with restrictive permissions and clear disclosure in the README.
  • Network access is limited to api.themoviedb.org and image.tmdb.org; no other external endpoints are contacted.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/STUDIOSELFHQ/omwatch --enable
Widgets #bar #quickshell #media

Omwatch

A TMDB watchlist with a details panel for the Omarchy Quattro bar.

This product uses the TMDB API but is not endorsed or certified by TMDB.

Omwatch runs inside the long-running omarchy-shell process. It does not start a second Quickshell instance and does not install packages.

Install

omarchy plugin add https://github.com/STUDIOSELFHQ/omwatch.git --enable

Usage

Click the film icon to open or close the board. Press Escape to close nested views, then the panel.

Type in search to query TMDB, or click Trending for this week's popular titles. Cards can be dragged between Queue, Watching, Watched, and Dropped, or advanced with Start / Done / Rewatch. Click a card for details, ratings, TV progress, streaming providers, and similar titles.

omarchy-shell shell summon omwatch '{}'
omarchy-shell shell hide omwatch

Setup

A free TMDB API key is required. Request one at themoviedb.org/settings/api, then paste a v3 API key or v4 Read Access Token in the panel. The key is stored only in ~/.local/state/omarchy/omwatch/library.json (directory mode 700, file mode 600) and is sent to api.themoviedb.org over HTTPS. It is passed to curl through a private config file, not process arguments.

Configure

omarchy bar move omwatch --section right

The optional apiKey setting on the bar widget entry is an alternate place to store the TMDB key (in Omarchy widget settings, not library.json).

Remove

omarchy plugin remove omwatch

That command removes the plugin. It does not delete your watchlist or TMDB key. The credential-bearing state file is ~/.local/state/omarchy/omwatch/library.json. Remove it with:

rm -rf ~/.local/state/omarchy/omwatch

Requirements

  • Omarchy 4.x (Quattro) with omarchy-shell
  • curl and bash (already on Omarchy)
  • A TMDB API key

Network access is used only for TMDB search, details, trending, and poster images.

License

MIT