Omahub
← All plugins
R

Obsidian Panel

by rafaelmehdiyev

Search notes across Obsidian vaults from the menu bar

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
ce5c38c
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
ce5c38c
Reviewed
1 month ago

The plugin is a transparent Obsidian vault launcher/search widget: it reads the user's Obsidian config, runs `find` to locate markdown notes, opens notes via `obsidian://` URIs, and updates `obsidian.json` when creating a vault. No obfuscation, persistence, credential theft, or destructive behavior was found. The only concerns are shell-command string interpolation in VaultCreator.qml and unguarded `find` arguments, both of which require unusual local configuration to be exploitable.

  • VaultCreator.qml builds a `sh -c` command by concatenating `configPath`/`tmpPath` without shell quoting; paths containing spaces or shell metacharacters could break the write or, in extreme cases, execute unintended commands. The path originates from the user's own `obsidianConfigDir` setting, so this is a robustness issue rather than an external attack.
  • VaultSearch.qml passes vault paths directly to `find` without a `--` separator; a vault path beginning with `-` could be interpreted as a find option. Obsidian normally stores absolute paths, so practical risk is low.
  • The create-vault flow writes to and replaces `obsidian.json` via a temp file and `mv`; this is generally safe, but the rest of Panel.qml (create form/directory creation) should be checked for similar shell quoting if it invokes shell commands.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rafaelmehdiyev/omarchy-obsidian-panel --enable
Productivity #bar #quickshell

Obsidian Panel

An Omarchy bar plugin that lets you switch between Obsidian vaults and search notes across vaults from the menu bar.

Showcase

Features

  • Shows all your Obsidian vaults in a panel
  • Click any vault to open it instantly
  • Search your notes across every vault from one search bar
  • Create a new empty vault directly from the panel
  • Keyboard navigation (Up/Down to move, Enter to open, Escape to close)
  • Automatically reads vaults from Obsidian's config - NO MANUAL SETUP

Requirements

Install

omarchy plugin add https://github.com/rafaelmehdiyev/omarchy-obsidian-panel --enable

Preview

Preview