Omahub
← All plugins
R

News Reader

by Ranjith Raj

Fullscreen overlay RSS news reader — bring your own RSS/Atom feeds, search, filter by source, and open stories in your browser. No hard-coded feeds or articles; configure via Settings or import OPML/JSON. Summon from the bar or with omarchy-shell shell summon.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
bcb495b
Scanned
3 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bcb495b
Reviewed
3 weeks ago

The deterministic scan found nothing, and I found no obfuscated code, destructive install steps, credential theft, or hidden persistence; the plugin is largely transparent and uses bounded, shell-quoted subprocess calls. My independent review is slightly less clean than 'none' because the overlay embeds a hard-coded defaultFeeds fallback despite the README claiming no hard-coded feeds, and article links taken from feed items are not visibly restricted to http(s), so a hostile/compromised feed could drive curl or xdg-open to local/private-network URLs. These are low-severity caveats for an unsandboxed shell plugin and warrant a human look before publishing.

  • Overlay.qml contains an embedded defaultFeeds array (HN, Lobsters, Phoronix, arXiv, etc.) used as a first-run/fallback seed, contradicting the README and manifest claim of 'no hard-coded feeds'; the first open can make network requests to those sites even before the user configures any feed.
  • Article links extracted from RSS/Atom entries are not checked to be http(s); a malicious or compromised feed could cause curl to fetch file:// or private-network URLs (local-file/SSRF exposure) or xdg-open to open such URLs. The fetch path in Overlay.qml should enforce an http(s) scheme and ideally block private/link-local addresses.
  • Runtime state reads and fetches shell out to bash/python3/curl, but python3 is omitted from the README's runtime dependency list; the unsandboxed subprocess use means any feed-parser or command-construction bug inherits the user's full privileges.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ranjithrajv/news-reader --enable
Productivity #Hyprland #bar #quickshell

News Reader — Omarchy Overlay

News Reader overlay — keyboard-driven RSS list with the full article rendered in-panel

Read the whole article without leaving the compositor. Fullscreen RSS overlay for Omarchy Quattro — press the bar button and a story opens, extracts and renders in the panel: no browser tab, no terminal split. Lives in one omarchy-shell process as an overlay + bar-widget plugin.

Press the bar button (📰) or summon via IPC to open a centered card:

  • Live RSS — no hard-coded feeds or articles; add your own RSS/Atom URLs in Settings (⚙) or import OPML/JSON — see suggested-feeds.json for examples
  • Search + feed chips — / focuses search, matches title/description/feed name plus the full cached body of any story you've opened; chips filter by source and are grouped into folders by feed category, j/k or ↑/↓ navigate, Enter opens, r refreshes, Ctrl+C copies link
  • Feed folders — feeds group under a category header (edit a feed's category inline in Settings) in both the chip bar and the Settings feed list
  • Scrim + keyboard layer — WlrLayershell.layer: Overlay, Exclusive focus, Esc dismisses, click outside dismisses
  • Read tracking — read ids persisted at ~/.local/state/omarchy/news-reader-read.json (800-entry cap), unread dot + “Mark read”
  • Auto refresh — configurable Hourly (default) / Daily / Weekly in Settings, persisted, + minute-granular “2h ago” labels
  • Language — English, Español, Deutsch, 中文, العربية, हिन्दी, Français, বাংলা, Русский, Português, اردو; auto-detected from the system locale, switchable in Settings → Preferences (Arabic/Urdu render right-aligned; layout stays LTR)

Install

omarchy plugin add https://github.com/ranjithrajv/news-reader --enable --yes
# then add to bar if not auto-placed:
omarchy bar move ranjithraj.news-reader --section right

Local dev (this repo is a plugin checkout already):

mkdir -p ~/.config/omarchy/plugins/ranjithraj.news-reader
cp manifest.json Overlay.qml BarWidget.qml NewsModel.js Config.js I18n.js suggested-feeds.json ~/.config/omarchy/plugins/ranjithraj.news-reader/
omarchy-shell shell rescanPlugins
omarchy plugin validate ~/.config/omarchy/plugins/ranjithraj.news-reader
qmllint -I /usr/share/omarchy/shell ~/.config/omarchy/plugins/ranjithraj.news-reader/Overlay.qml ~/.config/omarchy/plugins/ranjithraj.news-reader/BarWidget.qml

Remove

omarchy plugin remove ranjithraj.news-reader

State (feeds, read ids, unread count, font size) is left at ~/.local/state/omarchy/news-reader-*.json; delete those files to fully reset.

Dependencies

External commands invoked at runtime: curl (feed/article fetch), wl-copy (wl-clipboard, copy link/export), notify-send (libnotify, export/share notifications), xdg-open (open story in browser). No daemons, no build step, no sudo.

Summon / hide

omarchy-shell shell summon ranjithraj.news-reader '{}'
omarchy-shell shell hide ranjithraj.news-reader
omarchy-shell shell toggle ranjithraj.news-reader '{}'
# bar button also triggers summon

Files

  • manifest.json — kinds: ["overlay","bar-widget"], overlay: Overlay.qml, barWidget: BarWidget.qml, keepLoaded: true
  • Overlay.qml — PanelWindow overlay, fetches RSS via curl + Process, merges 150 newest, chips + search + split list/detail
  • BarWidget.qml — WidgetButton (\uF1EA) → shell summon
  • NewsModel.js — RSS/Atom parser (<item>/<entry>, CDATA, content:encoded, link href fallback), timeAgo, filterArticles (no hard-coded feeds)
  • Config.js — shared state-dir/path/sentinel config single source for Overlay + BarWidget
  • I18n.js — UI string tables + lookup (t()) for 11 locales (English, Spanish, German, Chinese, Arabic, Hindi, French, Bengali, Russian, Portuguese, Urdu); locale auto-detected from the system, overridable in Settings → Preferences → Language
  • suggested-feeds.json — example feeds to import (not auto-loaded); paste a filtered JSON array into Settings → Import

Theming

Uses shared tokens so themes style it automatically: Color.menu.* (background/text/border/scrim/selectedBackground/selectedText), Style.* (cornerRadius, space, spacing, font), Border.surfaceSpec. No hardcoded palette.

Security

Runs unsandboxed inside omarchy-shell as your user. Fetch is curl -sL --max-time 8 capped at 500 KB per feed, parsed as text in QML JS — no eval, no hooks, no sudo. Writable state files are read through bounded regular-file/no-follow readers (256 KiB ceiling) and all retained collections/field lengths are structurally capped before entering shell state. Review Overlay.qml:fetchNext + NewsModel.js:parseRss before enabling.

License

AGPL-3.0-or-later — see LICENSE.