Omahub
← All plugins
V

Index Todos

by vinchinzu

Pebble Index 01 reminders and Notes to self in the Omarchy bar. Syncs from the Pebble app over Wi-Fi ADB.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
b30fcf6
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:30

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required.
  • Docs sudo SECURITY.md:8

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
b30fcf6
Reviewed
1 month ago

The sampled code is transparent and security-conscious: no sudo, no obfuscation, hardened state I/O, and no destructive install steps. The deterministic 'sudo' findings are false positives because the docs actually say 'No sudo or pkexec is required.' The main real risk is that the first USB sync may enable unauthenticated ADB over Wi-Fi (`adb tcpip 5555`), exposing the phone to any device on the same LAN; this is documented but still a significant exposure that warrants human review.

  • The deterministic scan's 'sudo' findings are false positives: README.md and SECURITY.md say 'No sudo or pkexec is required.'
  • First USB sync may run `adb tcpip 5555`, leaving unauthenticated ADB listening on the LAN; any local device could connect to the phone.
  • Saved ADB pairing is restricted to private/link-local addresses, but that does not mitigate attackers on the same LAN.
  • The agent-launch path should be confirmed to pass phone-derived prompt text as argv rather than through a shell, since reminder/note text is user-influenced.
  • No obfuscation, hidden persistence, credential theft, or destructive install commands were found in the sampled code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/vinchinzu/omarchy-pebble-index --enable
Productivity #bar #quickshell #ai

Index Todos

Pebble Index reminders and Notes to self in the Omarchy bar. The widget shows open and overdue counts, a checklist panel, and a one-key resync from the Pebble app over ADB (USB or Wi-Fi).

Right-click a row (or press A) to send it to your default coding agent — whatever you picked in Omarchy, not a hardcoded CLI.

Plugin id: v.pebble-index.

Privacy: what is not in this repo

Your Index list, voice notes, and phone pairing are personal data. They never live in the plugin checkout. The sync script writes them outside git:

Path What it is
~/.local/state/omarchy/pebble-index/index.json Last scraped reminders, notes, and timestamps
~/.local/state/omarchy/pebble-index/adb.json Saved Wi-Fi ADB host/port/serial (mode 600)

.gitignore also blocks index.json and adb.json at the plugin root, so a stray copy cannot be committed. Do not paste those files into this directory or into a gist when reporting bugs — redact titles and serials.

The widget does not upload Index data. Sending a row to the agent only launches omarchy agent prompt on this machine with that row's text.

No sudo or pkexec is required.

Security

This plugin runs unsandboxed in your Omarchy session. It can spawn python3, adb, and omarchy agent prompt, and it can drive a paired phone over ADB (wake the screen, dump the Pebble UI, tap and swipe).

Classic adb tcpip 5555 is unauthenticated. The first USB sync may enable it so later syncs work on the same LAN. Saved pairing is written only for private or link-local addresses, and reconnects to public IPs are refused. Prefer Android Wireless debugging pairing when you can. Unlock the phone yourself; the plugin does not dismiss a lock screen.

UI dumps are written under /data/local/tmp/ on the phone, streamed onto an exclusive local fd, then deleted on the phone and on this machine. State files are never opened through FileView or other symlink-following paths; bin/state.py pins an fd with no-follow, owner, regular-file, and size checks. Phone-derived titles and notes render as plain text. Local IPC (omarchy-shell v.pebble-index sync / send) is limited to your session.

See SECURITY.md. This is not a security audit, certification, warranty, or endorsement.

Default coding agent

The widget never names Pi, Grok, Claude, or anything else. It runs:

omarchy agent prompt "<the reminder or note>"

Omarchy reads the default agent from:

~/.config/omarchy/defaults/agent

That file is a single line (pi, grok, claude, codex, …). Change it from the menu (Setup → Defaults → Agent) or:

omarchy default agent          # print the current name
omarchy default agent grok     # pick one; installs via mise if needed

If the file is missing, Omarchy has no default and the launch fails until you pick one.

Requirements

  • Omarchy Quattro with shell plugins
  • python3 and adb (android-tools) on PATH
  • The Pebble app (coredevices.coreapp) on an Android phone
  • USB debugging (and wireless debugging after a reboot)

Install

omarchy plugin add https://github.com/vinchinzu/omarchy-pebble-index.git --enable

The widget defaults to the right side of the bar. Move it with omarchy bar move v.pebble-index. Confirm with omarchy plugin list | grep v.pebble-index.

omarchy plugin update v.pebble-index
omarchy plugin remove v.pebble-index

Removal deletes the plugin checkout. It does not delete ~/.local/state/omarchy/pebble-index/. Remove that directory yourself if you want the saved list and ADB pairing gone.

Phone setup (first sync)

  1. On the phone: Settings → Developer options → USB debugging.
  2. Plug USB once. Unlock the phone and tap Allow (check "always" if you want).
  3. Open the Pebble app, Index tab.
  4. In the widget, press R (or middle-click the bar icon).

The first USB sync also turns on ADB over Wi-Fi (port 5555) and writes adb.json, so later syncs work on the same network without a cable. After a phone reboot you may need USB once more, or Wireless debugging from developer options.

ANDROID_SERIAL overrides device choice if more than one phone is on ADB.

Controls

Input Action
Left click bar icon Open / close the panel
Middle click bar icon Resync from the phone
Right click bar icon Send Notes to self to the default agent
Click a reminder Toggle done (pushed to the phone on next sync)
Right click a row Send that row to the default agent
j / k or arrows Move the cursor
Space / Enter Check off a reminder, or send a note
n Jump to Notes to self
a / g Send the selected row (or all notes) to the agent
r / s Resync
Esc Close

IPC: omarchy-shell v.pebble-index <open|close|toggle|refresh|sync|notes|send>.

How it works

bin/sync is a UI scrape, not a Pebble API client. It launches the app over ADB, dumps the accessibility tree, and reads Reminders plus Notes to self. Done-checks you make in the bar are tapped back on the phone on the next sync. Geometry is taken from the dump so the swipes are not tied to one phone resolution.

That is also the limitation: Pebble UI changes, unusual screen sizes, or a locked phone will fail the scrape. The last good index.json is left alone if the new scrape looks empty or unrelated.

State I/O tests: ./test/run.

License

MIT. External tools used at runtime: Android adb, python3, and Omarchy's omarchy agent (your chosen coding agent).