Omahub
← All plugins
M

Trackpad Gestures

by Mark Weaver

Configure Hyprland trackpad gestures and click mappings from the bar

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
3d2c1ce
Scanned
3 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
3d2c1ce
Reviewed
3 weeks ago

The plugin is a well-engineered bar widget that configures trackpad gestures by generating a Hyprland Lua config and editing shell.json. The installer is commit-pinned, verifies clean checkouts, backs up existing configs, and the apply script validates all inputs and uses secure temporary-file handling. No malicious, obfuscated, or destructive behavior was found; the code includes regression tests for injection and symlink attacks.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/mpweaver/omarchy-trackpad-gestures --enable
Productivity #quickshell

Omarchy Trackpad Gestures

A Quickshell bar widget for configuring Hyprland trackpad gestures on Omarchy.

Trackpad Gestures configuration panel

The popup configures 2-, 3-, and 4-finger swipes and pinches, toggles all gestures, changes click/tap mappings, and assigns a trackpad click to screenshots or screen recording. Changes persist in ~/.config/omarchy/shell.json and apply live through a generated ~/.config/hypr/gestures-generated.lua file.

Requirements

  • Omarchy 4 or newer
  • Hyprland 0.55 or newer with Lua configuration
  • git and jq

Install

Obtain the full 40-character commit SHA from the marketplace review for this plugin. A branch name, tag, or abbreviated SHA is not a review pin. Replace the placeholder below with that reviewed SHA before running the block. No repository code is executed until the fetched commit is checked.

(
  set -euo pipefail
  reviewed_commit=REPLACE_WITH_REVIEWED_40_CHARACTER_COMMIT
  [[ $reviewed_commit =~ ^[0-9a-f]{40}$ ]] || {
    echo "Set reviewed_commit to the full SHA from the marketplace review." >&2
    exit 1
  }
  checkout=$(mktemp -d)
  trap 'rm -rf -- "$checkout"' EXIT
  git -C "$checkout" init -q
  git -C "$checkout" remote add origin https://github.com/mpweaver/omarchy-trackpad-gestures.git
  git -C "$checkout" fetch --depth 1 origin "$reviewed_commit"
  git -C "$checkout" checkout --detach "$reviewed_commit"
  test "$(git -C "$checkout" rev-parse HEAD)" = "$reviewed_commit"
  bash "$checkout/install.sh" --commit "$reviewed_commit"
)

The installer verifies the clean source checkout and installs through omarchy plugin add using that local detached checkout, not remote HEAD. It verifies the installed checkout matches the same commit before backing up and modifying input.lua and shell.json. It then adds the widget and reloads Hyprland. Standalone installer downloads are not supported.

For an existing installation, the installed commit must already match the reviewed SHA and its working tree must be clean. A mismatch stops before configuration writes. Repeating installation at the same SHA does not duplicate the widget or loader. Do not substitute the latest upstream HEAD for a reviewed SHA simply to bypass this check.

Automatic plugin registration uses Omarchy's standard ~/.config location. For a custom XDG_CONFIG_HOME, clone the repository into $XDG_CONFIG_HOME/omarchy/plugins/user.trackpad-gestures, fetch and detach at the reviewed SHA, and run that checkout's installer with --commit and the same SHA. Configuration and helper paths honor that location.

First-run preset

  • All two-, three-, and four-finger swipe and pinch gestures: none
  • One-finger tap: left-click
  • Two-finger tap: right-click
  • Three-finger tap: screenshot capture
  • Screenshot editor: off

The Relative workspace action uses discrete numeric steps: swipe right advances +1 and swipe left goes back -1. It moves strictly in workspace-ID order, including empty workspaces, without the stuck state of Hyprland's continuous workspace action. A live motion threshold dispatches the step before finger release so workspace changes remain responsive.

Every value can be changed from the popup after installation.

Capture warning

Trackpads expose finger clicks as ordinary mouse buttons. Assigning two-finger click or the lower-right button area to capture replaces normal right-click. Assigning three-finger click replaces normal middle-click.

When the screenshot-editor toggle is enabled, the plugin uses omarchy-screenshot-edit if installed and otherwise opens Omarchy's standard smart screenshot flow.

Update

Obtain the newly reviewed full commit SHA. Preserve any local changes separately, then fetch and detach the installed checkout at that exact commit before running its installer. Do not execute an installer from mutable main.

(
  set -euo pipefail
  reviewed_commit=REPLACE_WITH_REVIEWED_40_CHARACTER_COMMIT
  [[ $reviewed_commit =~ ^[0-9a-f]{40}$ ]] || exit 1
  plugin_dir="${XDG_CONFIG_HOME:-$HOME/.config}/omarchy/plugins/user.trackpad-gestures"
  test -z "$(git -C "$plugin_dir" status --porcelain --untracked-files=all)"
  git -C "$plugin_dir" fetch https://github.com/mpweaver/omarchy-trackpad-gestures.git "$reviewed_commit"
  git -C "$plugin_dir" checkout --detach "$reviewed_commit"
  test "$(git -C "$plugin_dir" rev-parse HEAD)" = "$reviewed_commit"
  bash "$plugin_dir/install.sh" --commit "$reviewed_commit"
)

Uninstall

~/.config/omarchy/plugins/user.trackpad-gestures/uninstall.sh
omarchy plugin remove user.trackpad-gestures --yes

Run the cleanup script first so the generated Hyprland configuration is removed before Omarchy deletes the plugin directory.

Regression tests

Run python -m unittest discover -s tests -v with Python 3, Bash, jq, Lua, and luac installed. Tests use temporary configuration directories and stub Hyprland/shell commands; they do not modify your desktop configuration. They cover file permissions, temporary-file symlinks, failure cleanup, action validation, and screenshot-editor paths containing shell metacharacters.

License

MIT