Omahub
← All plugins
R

Downloads

by Roy Melgar

Recent downloads at a glance: live folder watching, search, and quick actions from the bar.

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
8be9ac3
Scanned
1 month ago
  • medium external_hosts …/workflows/ci.yml:54

    Downloads or connects to an external HTTP(S) host.

    git clone --depth 1 --branch v1.11.0 https://github.com/bats-core/bats-core.git /tmp/bats-core
  • medium package_manager …/workflows/ci.yml:67

    System package manager operation.

    apt-get install -qy qt6-declarative-dev
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -qy qt6-declarative-dev
  • Docs external_hosts CONTRIBUTING.md:10

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/roymelgarv/omarchy-downloads

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
8be9ac3
Reviewed
1 month ago

The plugin is a local-only Downloads folder widget: it watches a folder, lists files, and offers open/reveal/copy/trash actions via small shell helpers. The deterministic scan's medium findings are all in CI workflow and contributing docs (git clone, apt-get with sudo), which are not part of the runtime plugin and pose no user risk. The runtime code is clean, uses standard tools, and shows deliberate security hardening (plain-text rendering, path encoding, bounded resource usage).

  • The plugin runs unsandboxed inside the Omarchy shell, but that is the normal plugin model and the code does not abuse it.
  • The CI workflow installs packages with sudo and clones external repos, but this only runs on the maintainer's CI, not on user machines.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/roymelgarv/omarchy-downloads --enable
Widgets #bar

Omarchy Downloads

Your Downloads folder, one click away. A bar widget for Omarchy that shows your most recent downloads with live tracking, instant search, and quick actions — without opening a file manager.

preview

Features

  • Recent downloads at a glance — the newest files in your Downloads folder, with size and type.
  • Live tracking — new files appear instantly; in-progress downloads (.part, .crdownload, .download) show as downloading while the bar icon pulses, and it gets a badge when one finishes while the panel is closed.
  • Stalled downloads surfaced — when a download dies partway through (browser crash, dropped connection), its row stops claiming to be in progress and is marked Stalled — download incomplete, so you can reveal or trash the leftover file instead of watching it spin forever.
  • Search everything — type to filter the entire folder, not just the recent list. Enter opens the top match.
  • Quick actions on any finished file: open (default app), reveal in file manager, copy to clipboard (paste into any file manager or chat), move to trash (with confirmation). Files still downloading stay non-actionable, so you can't open or copy a half-written one by accident.
  • Folder totals — total size and file count in the header, plus a button to open the folder.
  • 100% local — no network access, no sudo, no bundled binaries. Just QML and a few tiny shell helpers (wl-copy, gio, xdg-open, stat — all part of a standard Omarchy install).

Install

omarchy plugin add https://github.com/roymelgarv/omarchy-downloads --enable

Then place the widget where you want it:

omarchy bar move roymelgarv.omarchy-downloads --section right

Optional keybinding

Plugins can't ship keybindings, but one line in ~/.config/hypr/bindings.conf summons the panel from the keyboard:

bind = SUPER, D, exec, omarchy-shell downloads toggle

Keyboard

The panel opens with the search field already focused, so you can start typing straight away.

Key Action
↑ / ↓ Move the selection
Enter Open the selected file
Delete Trash the selected file — only while the search box is empty, so it still forward-deletes as you type
Shift+Delete Trash the selected file, even mid-search
Esc Clear the search first, then close the panel

Configure

Right-click the widget (or use the bar settings UI) to change:

Setting Default Description
Folder to watch ~/Downloads Any folder works — it's just a folder widget at heart.
Recent files shown 7 List length when not searching (3–15).
Badge on new downloads on Dot on the bar icon when a download finishes while the panel is closed.
Confirm before trashing on Skip the confirmation dialog if you like to live dangerously (trash is still recoverable).

Update

omarchy plugin update roymelgarv.omarchy-downloads

Remove

omarchy plugin remove roymelgarv.omarchy-downloads

Development

See CONTRIBUTING.md. Short version:

node --test tests/*.test.mjs   # unit tests
scripts/dev.sh                 # deploy to the live shell
scripts/dev.sh --restart       # deploy + restart the shell (required after Service.qml edits)

License

MIT