Omahub
← All plugins
V

OpenCloud

by Victor

OpenCloud status, local storage usage, controls, and recent synced files.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
6ee0b29
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6ee0b29
Reviewed
1 month ago

The plugin is a read-only status widget for the OpenCloud Desktop client. It reads local config, socket, and log data with strict size limits, ignores credential sections, and only launches the client or xdg-open for user-visible actions. No malicious, destructive, or network behavior was found.

  • The helper reads OpenCloud config and sync logs, which may contain account hostnames and local file paths; this data is exposed via the plugin's IPC status output, so users should treat captured output as personal data.
  • The plugin can start/quit the OpenCloud client and open URLs/file paths via xdg-open; these actions are user-initiated and limited to HTTP(S) URLs and local paths, but a human may want to confirm the xdg-open usage is acceptable.
  • The deterministic scan found no issues; the low risk rating is based on the inherent sensitivity of reading local sync metadata, not on any identified vulnerability.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/victoralensai/omarchy-opencloud --enable
Widgets #bar #quickshell #system

OpenCloud for Omarchy

An Omarchy bar plugin for the official OpenCloud Desktop client. It monitors all configured accounts and sync spaces, so it is not tied to a particular OpenCloud server.

OpenCloud panel showing sync status, accounts, spaces, and recent activity

Features

  • Live per-space sync state from the OpenCloud Desktop local socket
  • Actual upload, download, move, delete, conflict, and error activity from the desktop client's local sync logs
  • Last completed sync run in the bar tooltip and panel
  • Local disk usage for every configured sync space
  • Honest whole-client start and quit control
  • Quick links to the OpenCloud client, account servers, local spaces, and synchronized files
  • A visible refresh animation and a brief confirmation after manual refresh
  • Mouse, keyboard, and Omarchy shell IPC controls
  • Multiple accounts and multiple spaces without server-specific configuration

The plugin deliberately does not report server quota: OpenCloud Desktop does not expose it through its local status interface. The displayed storage value is disk space used by synchronized files on this computer.

Requirements

  • Omarchy with shell plugin support

  • Python 3 (included with Omarchy)

  • The official OpenCloud Desktop client:

    omarchy pkg add opencloud-desktop
    

OpenCloud must have at least one account configured before account and space details can appear. Use any server URL supported by OpenCloud Desktop.

Install

From GitHub:

omarchy plugin add https://github.com/victoralensai/omarchy-opencloud.git --enable --yes

For local development, run this from the repository checkout:

omarchy plugin add "$PWD" --enable --yes

Open the official client to add or reconnect an account:

uwsm-app -- opencloud --showsettings

If the native OpenCloud tray icon duplicates this plugin, open Omarchy's Manage tray panel and hide the OpenCloud item. This is an optional personal tray preference; the plugin never changes it for you.

Controls

  • Left-click the bar icon to open or close the panel.
  • Right-click it to perform a detailed refresh.
  • Middle-click it to show OpenCloud Desktop.
  • In the panel, use arrows or j/k to move and Enter to activate.
  • Press R to refresh, O to show the desktop client, C to start or quit it, and Escape to close the panel.

The header switch starts or quits the complete OpenCloud Desktop client. It does not pretend to pause individual accounts or spaces because the desktop client does not provide a reliable supported command for that operation.

IPC examples:

omarchy shell victor.opencloud status
omarchy shell victor.opencloud refresh
omarchy shell victor.opencloud open
omarchy shell victor.opencloud statusJson

Updating and removal

omarchy plugin update victor.opencloud --yes
omarchy plugin remove victor.opencloud --yes

Removing the plugin removes only the Omarchy integration. It does not uninstall OpenCloud Desktop, remove accounts or credentials, delete synchronized files, or alter native tray preferences.

Privacy and security

The plugin performs no network requests. Its helper reads only the [Accounts] and [Folders] portions of OpenCloud Desktop's local configuration, queries the local status socket, and reads bounded tails of local sync logs. Credential sections are ignored. The status snapshot can contain account host names plus local file names and paths so the panel can open them; it stays on the machine unless you explicitly retrieve or share the IPC JSON output.

Server links are limited to HTTP(S), file paths are encoded before opening, log details are length-limited, and URLs found inside error details are removed. The helper rejects oversized configuration or socket input and caps every returned collection and string. The shell independently caps helper stdout, validates and normalizes the JSON schema, and renders helper-controlled labels as plain text.

Development

Run the complete test and validation suite:

./tests/run

The backend is standard-library-only. A sanitized fixture is available at demo/snapshot.json for documentation and UI previews.