Omahub
← All plugins
Y

omaStream

by yada

Quickshell video & audio search and player plugin for Omarchy

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
bdf13a2
Scanned
1 month ago
  • medium package_manager …/workflows/ci.yml:16

    System package manager operation.

    apt-get install -y shellcheck
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y shellcheck

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bdf13a2
Reviewed
1 month ago

The plugin is a legitimate yt-dlp/Quickshell YouTube player with no installer-time commands, no obfuscated code, and no destructive actions, so the deterministic CI flags (sudo apt-get in GitHub Actions) are not a real user-facing risk. The medium rating comes instead from the helper scripts silently detecting the user's browser and automatically importing browser cookies into yt-dlp, plus an incompletely reviewed local HTTP relay path.

  • scripts/detect-browser.sh, omastream-download, omastream-resolve, omastream-formats, and omastream-upload-time automatically use --cookies-from-browser to read cookies from Chrome/Chromium/Firefox/Brave/etc. and pass them to yt-dlp; this is not disclosed in the README and grants the plugin access to sensitive browser session data.
  • scripts/omastream-relay spawns a local HTTP server and ffmpeg pipeline; the sampled file does not show the full bind address/port lifetime, so a human should confirm it is loopback-only and short-lived.
  • The deterministic findings reference only the CI workflow's `sudo apt-get install shellcheck`, which runs in GitHub Actions, not on a user's machine, and should not be treated as an install-time risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/yaredow/omastream --enable
Widgets #bar #quickshell #media

omaStream

YouTube search, playback, and download in Quickshell.

omaStream Preview

omaStream brings YouTube Discovery, an embedded player, and a fully-featured download manager directly into the Omarchy shell. Videos play locally through Qt Multimedia and yt-dlp, skipping the heavy browser client entirely.

Why you will love it

  • Lightweight by design. Playback is natively integrated into Quickshell, not an Electron YouTube client.
  • Discover. Bounded search with exact date hydration, filtering, and timestamp-aware sorting.
  • Player. Embedded Discover preview plus fullscreen video, audio-only mode with automatic stream fallback, playback rate, volume, and progressive quality selection.
  • Downloads Manager. Observable transfer queue, persistent history, real-time speed, ETA, and cancellation.
  • Custom Download Flow. Select container (MP4, MKV, WebM, MP3, M4A), audio-only extraction, or specific video resolutions merged via FFmpeg.
  • Persistent Service. Shared playback and download queue state between the overlay and bar widget.

Familiar from the first click

Shortcut What it does
Space Play or pause
Left / Right Seek backward or forward 10 seconds
Up / Down Change volume
M Mute or unmute
F Enter or leave fullscreen video
/ Focus search in Discover mode
C Toggle fullscreen controls
Escape Leave fullscreen, or close the overlay

Clearing search or starting a new search stops any active playback session so media cannot keep playing without a player surface.

Closing the overlay leaves playback running so the bar widget can still pause, stop, or change volume.

The bar widget uses middle click for play/pause, right click to stop, and the mouse wheel for volume.

Install

omarchy plugin add https://github.com/yaredow/omastream.git --enable

Requires Omarchy 4, Python 3, ffmpeg, jq, and yt-dlp:

omarchy pkg add ffmpeg yt-dlp python jq

From a local checkout:

omarchy plugin clone user.omastream --edit

Remove

To completely remove this plugin from your system:

omarchy plugin remove user.omastream

This will also delete your downloads history. To keep your downloaded media, ensure your configured downloads folder is outside of the plugin directory (the default is ~/Downloads).

Architecture

PlaybackService.qml         # Long-lived playback singleton & download service host
OmaStreamOverlay.qml        # Overlay shell, search, fullscreen player chrome
BarWidget.qml               # Compact bar transport controls
services/
  DownloadService.qml       # Transfer queue, event parser, and JSON history persistence
  MediaModel.js             # Metadata normalization, formatting, filtering, sorting
  DownloadModel.js          # Job normalization, status badges, byte/speed formatters
providers/
  YoutubeProvider.js        # Progressive format normalization & download catalog
views/
  DiscoverView.qml          # Search, list, embedded player, audio mode, errors
  DownloadsView.qml         # Queue & history lists, filter tabs, folder actions
components/
  QualityMenu.qml           # Stream quality selection menu
  DownloadPicker.qml        # Custom download options
  DownloadRow.qml           # Transfer progress bar, speed, ETA, and actions

scripts/
  omastream-search          # Fast two-stage relative time search adapter
  omastream-upload-time     # NDJSON streaming exact date hydration worker
  omastream-formats         # Machine-readable format extractor
  omastream-resolve         # yt-dlp URL resolver wrapper
  omastream-download        # NDJSON event-streaming download process with process-group cleanup