Omahub
← All plugins
T

OmaMovie

by tenzin

Stream movies and TV shows directly from your Omarchy bar. Search content, select episodes, choose quality, and play instantly in mpv.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
504a21e
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
504a21e
Reviewed
1 month ago

The plugin is a media-streaming bar widget that installs a pure-Python bridge into the user's cache directory and fetches content from the MovieBox API. The deterministic 'obfuscation' finding is a false positive—it's just a PNG magic-number check in utils.py. The code is transparent, includes SSRF protections, and performs no destructive or hidden actions beyond a documented shell restart after install.

  • The setup script triggers an Omarchy shell restart after a fresh install (OMAMOVIE_RESTART_SHELL=1), which may be mildly disruptive but is documented.
  • The bridge hardcodes a MovieBox API secret and spoofs Android client headers/IPs to access the service; this is for API compatibility, not user harm.
  • Streaming content from third-party sources (MovieBox) is inherently untrusted, but the plugin sanitizes URLs and limits response sizes to mitigate risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/yesheytenzin/omamovie --enable
Widgets #bar #quickshell #media

Omarchy OmaMovie

Credit: MovieBox-TUI by mesamirh — ported to Python backend (bridge/python/).

OmaMovie preview

Quickshell panel for movies, shows & anime — search, pick season/episode and stream in mpv.

  • No Rust, no binary downloads — pure Python, ~1.8M clone (was ~231M before history purge)
  • Instant — dedicated streams process, E1 auto-selected, ≥2 chars for suggestions, recent-search chips, Esc to close/clear
  • Verified — py_compile + crypto unit tests on push/PR only (no release artifacts)

Install

omarchy plugin add https://github.com/yesheytenzin/omamovie.git --enable

Creates shim $XDG_CACHE_HOME/omamovie/omamovie-bridge → bridge/python/__main__.py and verifies {"cmd":"ping"}. Click in the bar to browse.

Update / Remove

omarchy plugin update tenzin.omamovie
omarchy plugin remove tenzin.omamovie

Backend

Pure Python — no Rust, no compilation, no binary downloads. Panel.qml unchanged — same CLI JSON contract.

File Role
bridge/python/crypto.py HMAC-MD5 signing (x-client-token, x-tr-signature), sorted query, x-client-info
bridge/python/client.py 7-host failover, requests or urllib fallback, token via x-user
bridge/python/cache.py ~/.cache/moviebox-tui/ — 24h search/details, 2h streams, 1h homepage
bridge/python/__main__.py ping/search/suggest/details/resources/captions/homepage + filtering/sorting

Rust bridge (moviebox-tui crates) fully replaced; removed from repo.

Panel

  • Esc closes from any view; clears search field when focused
  • Episodes auto-populate on openDetails; E1 selected, dedicated streamsProc for instant load
  • Suggestions gated at ≥2 chars (220ms debounce, history instant)
  • Recent searches Flow (max 10, deduped, click to re-search)
  • Streams placeholder: Loading streams for S1E1 … / No streams — tap again to retry (retry MouseArea)
  • Sub→dub fallback: auto-switched to <lang> — N streams when primary has no streams

License

MIT