Omahub
← All plugins
U

Omiru

by ussego

Icon picker for Omarchy: search and copy icons to the clipboard.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
b07745e
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
b07745e
Reviewed
1 month ago

The plugin is an icon picker that fetches catalogs and icons from well-known external services over HTTPS with restricted protocols and file size limits. It performs no arbitrary code execution from fetched data, and all file operations are confined to its own state/config directories. The code is transparent and follows safe practices.

  • Network access to third-party APIs and CDNs is inherent to the plugin's function, but the fetched content is only used for display and copying, not executed.
  • The embedded Python transform script is static and does not process untrusted input beyond JSON parsing, so no injection risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ussego/omiru --enable
Developer Tools #quickshell

Omiru

The icon picker for Omarchy: browse the Dashboard Icons and svgl.app logo libraries and copy icons to the clipboard.

omiru overlay

Install

omarchy plugin add https://github.com/ussego/omiru.git --enable

Usage

omarchy-shell shell summon ussego.omiru '{"query":"git"}'
  • Type to filter by name; both providers are searched together (Dashboard Icons first, then SVGL).
  • Enter opens the detail view, Ctrl+C copies the active action and closes (right-click copies directly).
  • Tab / Shift+Tab cycle top categories, Ctrl+K opens the full category list.
  • Ctrl+Tab / Ctrl+Shift+Tab cycle providers; Ctrl+T enables/disables providers (chip row: left-click filter, right-click disable); Delete toggles the active provider.
  • Detail view: Ctrl+F cycles the type (svg | png | webp), Tab cycles the copy action, 1-9 picks one, v cycles color variants, w opens the website, Esc goes back.
  • Ctrl+P opens a command palette (refresh catalogs, clear cache, …); Ctrl+R re-fetches catalogs; Esc clears the search or closes.

Summon payloads: query, category, and provider pre-select those on open.

Keybinding

Add to ~/.config/hypr/bindings.lua:

hl.unbind("SUPER + CTRL + G")
o.bind("SUPER + CTRL + G", "Icon picker", "omarchy-shell shell toggle ussego.omiru")

Providers & configuration

Provider enable/disable is persisted in ~/.config/omarchy/omiru.json and applied live. The chip row shows only enabled providers; manage all of them (including new ones) in the Ctrl+T dialog.

Omiru fetches the icon catalogs over HTTPS from api.svgl.app and dashboardicons.com, and downloads icon assets from their CDNs (cdn.jsdelivr.net, cdn.simpleicons.org, and the per-logo URLs published in those catalogs). Icon files are cached under ~/.local/state/omarchy/omiru. The full library uses roughly 230 MB on disk; icons are downloaded once and cached, so this is a one-time cost per catalog. rm -rf that directory at any time to force a re-download.

Removal

omarchy plugin remove ussego.omiru

To also delete all Omiru data (config, catalog cache, logo library):

rm -rf ~/.config/omarchy/omiru.json ~/.local/state/omarchy/omiru

Dependencies

curl, wl-copy (wl-clipboard), and rsvg-convert (librsvg) — all shipped with Omarchy. python3 is optional: when present, catalog downloads are compacted in a short-lived helper process so the shell keeps a much smaller memory footprint; without it Omiru falls back to internal parsing.