Omahub
← All plugins
T

Animechy

by tenzin

Search and stream anime from your Omarchy bar — pick season/episode (sub/dub) and play in mpv.

Security review

Review recommended · 5 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
d2a04f3
Scanned
1 month ago
  • medium package_manager animechy-setup.sh:44

    System-wide Python package installation (not --user).

    pip install --require-hashes -r
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S mpv)"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S python)"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S python-requests python-beautifulsoup4 python-lxml"
  • Docs package_manager README.md:90

    System-wide Python package installation (not --user).

    pip install curl-impersonate` (bridge tries `curl_firefox135` fallback)

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d2a04f3
Reviewed
1 month ago

The plugin is a bar widget that scrapes an anime site and plays streams via mpv. The setup script creates an isolated venv and installs pinned, hashed dependencies; the flagged sudo/pip commands are only in warning messages, not executed. No malicious or destructive behavior was found.

  • The setup script may restart the Omarchy shell once after a fresh install, which could be disruptive but is not harmful.
  • The README suggests a manual `pip install curl-impersonate` for troubleshooting, but this is not part of the automatic setup.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/yesheytenzin/animechy --enable
Widgets #bar #quickshell #media

Animechy — Omarchy Quattro Anime Bar Plugin

<p align="center"> <img src="animechy.png" alt="Animechy" width="800" /> </p>

Credit: ani-cli by pystardust (GPL-3.0) — scraping logic for anidb.app

Quickshell bar widget for anime — click ア → search → pick season/episode (sub/dub) → stream in mpv. No Rust/compile, pure Python bridge. No manual prerequisites — fresh Omarchy already includes mpv+python; requests/beautifulsoup4/lxml auto-install on first click via animechy-setup.sh (pipx/uv/pip --user).

Install

omarchy plugin add https://github.com/yesheytenzin/animechy.git --enable

The animechy-setup.sh auto-runs on first click (copies bridge to ~/.cache/animechy/, creates an isolated venv with pinned+hashed deps from bridge/requirements.txt — never touches user/system site-packages — verifies ping+search, then restarts the shell once). Click ア in the top bar to browse. Nothing is ever written inside the plugin dir, so the shell never blinks/restarts in a loop.

Update

omarchy plugin update tenzin.animechy

Remove

omarchy plugin remove tenzin.animechy

Usage

  1. Click ア in bar (center)
  2. Discover shows 24 shuffled trending titles — tap any
  3. Search: type + Enter, pick suggestion or genre chip (All, Action, Adventure… Supernatural)
  4. Details: pick Sub/Dub, Season (if multiple), Episode E1… (filler dimmed), Quality 1080p→360p, hit ▶ Play
  5. mpv --force-window=immediate --cache=yes opens; panel auto-closes. Back returns to Discover; ↻ Refresh reloads current view; Esc closes panel.
  6. Recent searches appear as chips below search bar (persisted to ~/.local/state/animechy/hists, max 10).

Features

  • Bar widget ア with BarWidget.qml + Panel.qml (KeyboardPanel)
  • Live suggestions (≥2 chars, 380 ms debounce) + genre cache (10 min)
  • Episode grid with light-grey outline card (Flickable+Flow), ScrollBar.AsNeeded
  • Streams via anidb.app → embed_url → master.m3u8 → qualities sorted 1080p,720p…
  • Parallel bridge IPC (queued bridgeProc + dedicated streamsProc for instant E1 streams)
  • Caching in ~/.cache/animechy/ — search 24h (86400), details 7d (604800), episodes 2h, streams 2h
  • Sub/Dub toggle with sub→dub fallback if first mode empty

Manual setup

cd ~/.config/omarchy/plugins/tenzin.animechy
bash animechy-setup.sh
python3 ~/.cache/animechy/animechy-bridge.py '{"cmd":"search","q":"one piece"}' | jq
python3 ~/.cache/animechy/animechy-bridge.py '{"cmd":"episodes","id":"one-piece-3880"}' | jq '.items | length'
python3 ~/.cache/animechy/animechy-bridge.py '{"cmd":"streams","id":"one-piece-3880","episode":"1","mode":"sub"}' | jq

Bridge API

python3 bridge/animechy-bridge.py '{"cmd":"…",…}' → {ok:true,…} or {ok:false,error}

cmd params returns
ping — {pong:true}
search {q, page} {items:[{id,title,cover,year,rating}]}
details {id} {value:{title,intro,description,year,genre,cover,coverUrl,seasons_list[],mal_id}}
episodes {id} {items:[{id,number,filler}]}
streams {id,episode,mode} {items:[{resolution,quality,url,resourceLink,bandwidth}]}
homepage {page,perPage} {items:[...]}
suggest {q} {suggestions:[{name,id,cover}]}

How it works

Panel.qml ──JSON──> animechy-bridge.py ──HTTP──> anidb.app
   │                     │                         ├── /browse?q=            → search (regex anime/([a-z0-9-]+-[0-9]+)".*alt="([^"]+)")
   │                     │                         ├── /anime/<id>           → details + Seasons (<h3>Seasons</h3>)
   │                     │                         ├── /api/frontend/anime/<num>/episodes → episodes
   │                     │                         └── /api/frontend/episode/<epId>/languages → embed_url (jpn/eng) → jwplayer file:'…master.m3u8' → #EXT-X-STREAM-INF:RESOLUTION
   └─ mpv ←──────────────┘

Troubleshooting

  • Bridge not ready → click again, animechy-setup.sh reruns; check python3 -c "import requests,bs4,lxml" and mpv --version
  • Blocked by cloudflare → pip install curl-impersonate (bridge tries curl_firefox135 fallback)
  • No streams → toggles Sub/Dub automatically; try different episode; check ~/.cache/animechy/ m3u8
  • Panel not showing → omarchy plugin list --json | jq '.[] | select(.id=="tenzin.animechy")' → enabled:true; omarchy-shell shell rescanPlugins; log out/in
  • Lint → qmllint BarWidget.qml Panel.qml → 0

Development

# Edit bridge, test without restarting shell
python3 ~/.config/omarchy/plugins/tenzin.animechy/bridge/animechy-bridge.py '{"cmd":"search","q":"naruto"}' | jq
# Edit Panel.qml, then
omarchy-shell shell rescanPlugins
# Check bar placement
cat ~/.config/omarchy/shell.json | jq '.bar.layout.center'

Credits & License

  • Source: pystardust/ani-cli (GPL-3.0)
  • UI: Forked from tenzin.omamovie bar-widget/Panel pattern
  • License: GPL-3.0

See LICENSE (http://www.gnu.org/licenses/).