Omahub
← All plugins
U

Tempest

by unleashed-nick

Weather pill with the current temperature next to the condition icon

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
2ca27de
Scanned
1 month ago
  • medium external_hosts Panel.qml:336

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "10", "https://wttr.in/" + root.locationQuery + "?format=j1"]
  • medium external_hosts Panel.qml:459

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "4", "https://wttr.in/?format=%l"]

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2ca27de
Reviewed
1 month ago

The plugin is a weather widget that fetches data from wttr.in and Open-Meteo, which is expected functionality. The code is straightforward QML/JavaScript with no obfuscation, suspicious commands, or harmful operations. The deterministic scan flagged external hosts, but these are legitimate weather APIs and pose minimal risk.

  • Makes network requests to external weather services (wttr.in, api.open-meteo.com), which is inherent to its purpose.
  • Reads a local state file (weather.json) but does not appear to write or modify system files.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/unleashed-nick/omarchy-tempest --enable
Widgets #bar #quickshell #system

Tempest

Weather for the Omarchy bar, with the current temperature next to the condition icon.

Based on Omarchy's built-in weather widget. The forecast popup, location picker, and data sources are the same; the bar pill shows icon + temp instead of the icon alone.

Tempest on the Omarchy bar, showing the condition icon and current temperature

Install

omarchy plugin add https://github.com/unleashed-nick/omarchy-tempest.git --enable
omarchy plugin disable omarchy.weather

Disable stock weather or you will have two weather pills. The widget lands in the center of the bar. Move it if you want:

omarchy bar move unleashed-nick.tempest --section center --after omarchy.clock

Updating

omarchy plugin update unleashed-nick.tempest
omarchy restart shell

Removing it

omarchy plugin remove unleashed-nick.tempest
omarchy plugin enable omarchy.weather

That deletes Tempest and its bar entry. It leaves ~/.local/state/omarchy/settings/weather.json alone, since that file is owned by omarchy-weather-location and is shared with stock weather.

Requirements

Omarchy Quattro, and curl, which Omarchy already installs. The plugin calls omarchy-weather-location, omarchy-weather-status, and omarchy-notification-send — all ship with Omarchy. Nothing else is installed.

Usage

Left click open the forecast popup
Right click send a full weather notification
Middle click refresh
Click the location in the popup search and set a city

Temperature units follow locale and country (Fahrenheit in the US, Celsius elsewhere).

License

MIT. The forecast panel is derived from Omarchy's omarchy.weather plugin. See LICENSE.