Omahub
← All plugins
R

Update App Under Cursor

by Razaroth

Resolves the window under the cursor to the package that owns it and runs its update in a terminal (SUPER + right-click).

Security review

Potentially dangerous behavior detected · 8 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
48fed37
Scanned
1 month ago
  • Registers scheduled or boot-time system tasks.

    systemd-run | dbus-daemon | dbus-broker-launch | init) return 0 ;;
  • Snap package installation or removal.

    snap refresh '$app'"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo snap refresh '$app'"
  • Docs external_hosts README.md:55

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/Razaroth/omarchy-update-app-under-cursor
  • Docs package_manager README.md:21

    Snap package installation or removal.

    snap refresh <app>`                 |
  • Docs sudo README.md:21

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo snap refresh <app>`                 |
  • Docs sudo README.md:23

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -Sy <pkg>`, AUR packages via
  • Docs sudo README.md:40

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo can

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
48fed37
Reviewed
1 month ago

The plugin is a straightforward utility that resolves the window under the cursor to a package and runs its update via pacman/yay/flatpak/snap in a visible terminal. The deterministic scan's high rating is driven by documentation examples (git clone, sudo/snap in README) and a false-positive 'persistence' flag on a case statement that merely lists tool binaries to skip. The actual script is transparent, user-triggered, and only runs package-manager commands with sudo when the user initiates an update.

  • The installer modifies ~/.config/hypr/bindings.lua and reloads Hyprland, but this is documented, idempotent, and reversible via uninstall.sh.
  • The script runs sudo pacman/yay commands, but only when the user explicitly triggers the action (SUPER+right-click) and the terminal is visible for authentication.
  • Package names are derived from /proc/<pid>/cmdline, which could theoretically be spoofed by a malicious process, but the impact is limited to running a package-manager update on a user-chosen package.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Razaroth/omarchy-update-app-under-cursor --enable
System #system

omarchy-update-app-under-cursor

Hold SUPER + right-click on any window to update the app you're using — no need to know its package name.

Built for Omarchy (Arch + Hyprland), but works on any Hyprland setup with the same tooling.

What it does

Points at a window and figures out what "the app" really is, then runs the update in a terminal so you can authenticate and watch the result:

What's under the cursor What gets updated
Terminal running a CLI/TUI app The app running inside it (e.g. cliamp)
Idle terminal The terminal itself (e.g. foot)
Browser web app (e.g. Discord) A matching native package, installed or updated
Normal / Electron app The package owning its binary
Flatpak app flatpak update <app>
Snap app sudo snap refresh <app>

Update backends: repo packages via sudo pacman -Sy <pkg>, AUR packages via yay -S --cleanafter <pkg>, plus flatpak and snap. If nothing can be identified, you get a notification instead.

How it works

  1. Reads the cursor position with hyprctl cursorpos and finds the window underneath via hyprctl clients -j (topmost, most-recently-focused match).
  2. Identifies the app from /proc/<pid>/cmdline (not /proc/<pid>/exe, which YAMA's ptrace scope blocks for non-descendant processes):
    • Terminal windows (foot, kitty, alacritty, ghostty, …) are detected by class and walked down their process tree to the deepest package-owning binary, so a terminal running cliamp updates cliamp, not foot.
    • Chromium-family web apps (chrome-*, brave-*, …) are detected by class and resolved to a matching native package name.
    • Chromium folds its whole command line into argv[0], so the first word is used.
  3. Opens omarchy-launch-terminal running the update command, so sudo can prompt in the visible terminal.

Requirements

  • Omarchy (or a Hyprland setup with omarchy-launch-terminal and omarchy-notification-send)
  • hyprctl (Hyprland)
  • jq, pacman, pgrep
  • yay — required only for AUR packages
  • flatpak / snap — required only for those app types

Install

git clone https://github.com/Razaroth/omarchy-update-app-under-cursor
cd omarchy-update-app-under-cursor
./install.sh

Or install it as an Omarchy shell plugin — the repo carries a plugin manifest.json, so omarchy plugin add will clone, validate, and register it under ~/.config/omarchy/plugins/:

omarchy plugin add https://github.com/Razaroth/omarchy-update-app-under-cursor --enable

The plugin is a headless service (no UI); run install.sh as well so the SUPER + right-click binding and the omarchy-update-app-under-cursor command are available on your PATH.

The installer:

  • copies the script to ~/.local/bin/omarchy-update-app-under-cursor
  • appends a SUPER + mouse:273 binding block to ~/.config/hypr/bindings.lua (including an hl.unbind to replace the default resize window binding — idempotent, safe to re-run)
  • reloads Hyprland and checks hyprctl configerrors

Usage

Hold SUPER and right-click any window. A terminal opens running the update for the app under the cursor. If the window can't be identified, a desktop notification explains why.

Uninstall

./uninstall.sh

This removes the script and the binding block, restoring the default SUPER + right-click resize window behavior.

Troubleshooting

  • "Couldn't identify app" — the running command isn't owned by a package (e.g. a mise/language-manager shim). Nothing was changed.
  • Wrong app resolved — open an issue with the window title, the omarchy-update-app-under-cursor output, and ps -ef for that window's process tree.

License

MIT