Omahub
← All plugins
S

bg-pasticcio

by ssimo

Rotates the desktop background on a timer from a remote JSON endpoint, with a bar panel to keep or discard what it shows you. Falls back to the images you kept when the endpoint is unreachable. Off until you switch it on, and it puts your original wallpaper back when you switch it off.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
3316a85
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:54

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/WinCisky/bg-pasticcio.git \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
3316a85
Reviewed
1 month ago

The plugin is a background rotator that fetches images from a configurable remote endpoint. It is off by default and requires explicit user consent. The code includes safety measures like URL validation, file type checks, size limits, and no shell injection. The only external host mentioned is the git repository URL in the README, which is not a runtime dependency.

  • Downloads and applies wallpapers from a remote endpoint, but only after user enables it and with validation of file type and size.
  • Endpoint is user-configurable, so a malicious endpoint could be set, but that is user choice.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/WinCisky/bg-pasticcio --enable
Appearance #bar #media

bg-pasticcio

demo image

An Omarchy 4 ("Quattro") shell plugin that changes your desktop background on a timer, pulling images from an HTTP JSON endpoint. An icon next to the clock opens a panel to switch it on, point it at a feed, and keep or discard the image on screen. Only the images you decide to keep are stored on disk, and they are what it rotates through when the endpoint cannot be reached.

It ships off, pointing at https://bg.ssimo.dev — a CC0 wallpaper feed. Nothing is downloaded and no wallpaper is touched until you turn on Change my background; turning it back off puts your original wallpaper back.

Requirements

Omarchy 4 with omarchy-shell. The worker uses curl, jq, file, sha256sum, find, flock and getent, all present in a default Omarchy install; it checks for them and says so in the log if one is missing. magick, fc-match and hyprctl are optional and only affect the "configure me" notice background.

Install

omarchy plugin add https://github.com/WinCisky/bg-pasticcio.git --enable --yes
omarchy bar put ssimo.bg-pasticcio --after omarchy.clock

Nothing has changed yet — that is deliberate. Click the icon by the clock and turn on Change my background; the wallpaper changes within a second or two. The same from a terminal:

omarchy-shell bgpasticcio enable

Left-click the icon for the panel, right-click for a fresh image, middle-click for the next one you kept. To use your own feed, paste its URL into the endpoint field and press Enter — any endpoint works that answers with JSON containing at least {"url": "https://.../image.jpg"}.

To stop: switch Change my background off (that restores your wallpaper), then omarchy plugin remove ssimo.bg-pasticcio.

Developing

Plain bash and QML — no build step and nothing to install. Clone it where the shell looks for plugins, and enable it from there:

git clone https://github.com/WinCisky/bg-pasticcio.git \
  ~/.config/omarchy/plugins/ssimo.bg-pasticcio
omarchy plugin validate ~/.config/omarchy/plugins/ssimo.bg-pasticcio
omarchy-shell shell rescanPlugins
omarchy plugin enable ssimo.bg-pasticcio
omarchy bar put ssimo.bg-pasticcio --after omarchy.clock

Edit in place, then:

omarchy-restart-shell                              # after any QML edit — the shell caches compiled QML
cd ~/.config/omarchy/plugins/ssimo.bg-pasticcio
bin/bg-pasticcio enable && bin/bg-pasticcio run    # the worker runs standalone
bin/bg-pasticcio status | jq .
tail -f ~/.local/state/bg-pasticcio/bg-pasticcio.log

CLAUDE.md has the rest: architecture, the worker's command surface, config keys, on-disk layout, the endpoint contract, and the invariants to preserve.

What leaves your machine

Nothing while the toggle is off. Once on, every BG_INTERVAL_MINUTES it makes two ordinary HTTPS requests — one to the endpoint, one to the image URL it returns — with whatever your system curl sends by default. No identifiers, no telemetry; keeps and discards are recorded locally and never reported. The default endpoint is run by this plugin's author and sees what any web server sees: your IP address and User-Agent. Point it elsewhere, or blank it to rotate only what is already on disk, and it is never contacted again.

License

MIT — see LICENSE. Copyright (c) 2026 Simone Simonella.

The plugin ships no images of its own. Wallpapers come from whatever endpoint you point it at, under that endpoint's terms; the default feed serves CC0 photography and sends the credit line the panel displays.