Omahub
← All plugins
S

Portboard

by SVIGHNESH

Summonable panel of listening localhost ports with owning process and cwd. Enter opens the URL, Ctrl+K kills.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
0244db0
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
0244db0
Reviewed
1 month ago

This plugin lists listening localhost ports and lets the user kill owning processes via Ctrl+K. The code is straightforward and transparent: it invokes `ss -tlnp`, filters to loopback/wildcard addresses, and renders a list. The kill action is triggered only by explicit user keypress and uses the PID parsed from `ss` output. Risk is inherent to the feature (killing a process), not to the plugin itself.

  • Ctrl+K sends `kill` (SIGTERM) to the selected process — destructive by design, but requires explicit user action in the UI and is clearly announced in the README and in-app help.
  • PID is parsed from the output of `ss -Htlnp`; a malicious or compromised process on loopback that can set its own socket metadata could potentially confuse the parser, but that requires a user to manually select and kill the fake entry.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/SVIGHNESH/omarchy-portboard --enable
Developer Tools #quickshell #system

Portboard

A summonable Omarchy shell overlay showing every listening localhost TCP port, with the owning process, PID, and working directory. Answers "which dev server is on 5173?" without leaving the keyboard.

kind: overlay

Portboard overlay

Keys

Key Action
type Filter the list (e.g. 3000, node, or a directory name)
enter / click Open http://localhost:<port> in the browser
ctrl+k Kill the owning process and refresh the list
ctrl+r Refresh the list
arrows / ctrl+n / ctrl+p Move selection
esc Clear the filter, then close

Install

omarchy plugin add https://github.com/SVIGHNESH/omarchy-portboard --enable

Then bind a key in ~/.config/hypr/bindings.lua:

o.bind("SUPER + ALT + P", "Portboard", "omarchy-shell shell summon svighnesh.portboard '{}'")

How it works

The overlay runs list-ports.sh (a small ss -tlnp wrapper) each time it opens or refreshes, and renders the result with the active Omarchy theme. Only sockets bound to loopback or wildcard addresses are shown; IPv4/IPv6 duplicates are collapsed to one row per port.

Ports owned by other users (for example root services like CUPS) show ? for process and PID, since ss can't read their process info without root. ctrl+k does nothing for those.

Fallback CLI

bin/portboard is a standalone fzf version of the same panel for use outside the shell (SSH sessions, plain terminals). Run it directly, or bin/portboard --list for a raw table.

Uninstall

omarchy plugin remove svighnesh.portboard

License

MIT