Omahub
← All plugins
R

Expose

by ronnie

macOS-style window overview: hot corner, type-to-search, Space for Quick Look

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
a2772d7
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a2772d7
Reviewed
1 month ago

The plugin is a straightforward window-overview overlay that queries hyprctl for window data and focuses windows via validated addresses. The code is transparent, includes explicit input sanitization (app-id path/URI rejection, plain-text rendering, address regex, length caps), and uses static argv arrays with no shell involvement. No malicious, destructive, or hidden behavior was found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Macs9319/OmaExpose --enable
Desktop #Hyprland #quickshell #workspaces

Expose

A macOS-style window overview for Omarchy / Hyprland.

Expose overview

Trigger it with the top-left hot corner or SUPER + E. Type to filter windows by title or app id, hit Enter to focus one (switching workspace if needed), or hit Space on the highlighted card for a Quick Look inspector (large icon, full title, app id, workspace, size, and floating/fullscreen/XWayland/pid).

Install

omarchy plugin add <this-repo-url> --enable

Then bind a key (optional — the hot corner works without one):

-- ~/.config/hypr/bindings.lua
o.bind("SUPER + E", "Expose", "omarchy-shell shell toggle ronnie.expose")

Remove

omarchy plugin remove ronnie.expose

If you added the optional keybinding above, remove that line from ~/.config/hypr/bindings.lua too.

License and dependencies

MIT — see LICENSE. No dependencies beyond hyprctl, which ships with Hyprland/Omarchy itself; nothing else is installed or required.

How it works

  • Expose.qml — the overlay itself. Window data is a fresh hyprctl clients -j query on every open, not Quickshell's HyprlandToplevel.lastIpcObject (which only reflects a window's state at creation time and never refreshes — using it produces stale sizes/flags).
  • HotCorner.qml — a headless service that polls hyprctl cursorpos and summons the overlay after a short dwell in the top-left corner. Edit the corner/zonePx/dwellMs properties in the file to change which corner or how long the dwell is.
  • Focusing the selected window shells out to hyprctl dispatch with hl.dsp.focus({ window = "address:..." }) — this Hyprland build's IPC socket only accepts its own Lua dispatch syntax, so Quickshell's built-in Hyprland.dispatch() (which sends the classic dispatch string) gets rejected.

Security notes

Window titles and app ids are supplied by whatever application owns the window, not by the user, so they're treated as untrusted:

  • App-id strings are rejected before they reach icon lookup if they look like a path or URI (shell.appLibrary.iconSource() treats a leading /, file://, or image:// as a direct image source to load).
  • All displayed text sets textFormat: Text.PlainText — Qt's default auto-detects and renders HTML-like markup in a string.
  • Window addresses are regex-validated (^0x[0-9a-fA-F]+$) before being placed in a dispatch string.
  • Title/app-id/workspace strings are length-capped.

Both hyprctl calls (clients -j, cursorpos) run as static argv arrays with no shell involved, and JSON.parse output is validated before use.