Omahub
← All plugins
V

slop-games

by Victor Campos

The whole catalog on the bar: every game one HTML file, opened as its own window

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
cf3daa3
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
cf3daa3
Reviewed
1 month ago

This is a straightforward bar widget that lists game metadata and launches each game via omarchy-launch-webapp, either from a local catalog directory or from the author's GitHub Pages site. No install scripts, no obfuscation, no credential access or persistence behavior were found, and the only shell invocation is a safely quoted read-only existence probe. The residual risk is limited to loading remotely hosted web games in the default browser, which is the plugin's stated, user-initiated purpose.

  • When no local catalog is present, the plugin opens games from https://victorlcampos.github.io/slop-games/; if that site were ever compromised it could serve malicious web content, though it would run in the browser sandbox and only after the user clicks a game.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/victorlcampos/omarchy-slop-games --enable
Widgets #quickshell #launcher #games

slop-games — the catalog on your Omarchy bar

Every game in the catalog, one HTML file each, behind a gamepad on the bar. Click one and it opens in its own window — no tabs, no address bar.

omarchy plugin add https://github.com/victorlcampos/omarchy-slop-games.git --enable

Using it

A gamepad icon appears on the bar. Click it and the whole catalog is there, each with its name and one line about it. ↑↓ or j/k walk the list, ⏎ plays, Esc closes, Tab moves to the next panel on the bar.

For a keybind instead of a click, the panel answers on IPC:

bind = SUPER, G, exec, omarchy-shell slop-games toggle

The footer has Open the catalog, which opens the index with every card, and EN / PT. The panel starts in the language your desktop asks for — a pt_* locale gets Portuguese, everything else English — and those two buttons override it.

Removing it

omarchy plugin update victorlcampos.slop-games   # fast-forward the checkout
omarchy plugin remove victorlcampos.slop-games   # disable and delete it

Removal takes the plugin's own folder and its entry in shell.json. If you also used the optional local copy of the games (below), delete ~/.local/share/slop-games yourself — it is outside the plugin and nothing else touches it.

What it needs, and what it writes

External dependencies: none beyond Omarchy itself. The panel runs omarchy-launch-webapp, which ships with Omarchy and opens your default browser with --app=, plus one bash -c line to detect whether you have a local copy of the games. It installs nothing, downloads nothing at runtime, starts no service of its own, asks for no elevated privileges, and makes no network calls.

Configuration: the only thing it ever writes is the EN/PT choice, into this widget's own entry in ~/.config/omarchy/shell.json, and only when you click one of those two buttons. It touches no other configuration and overwrites nothing.

Where the games come from

The plugin carries the names, not the games. It looks for them in order and takes the first that is really there:

Where Who puts it there
1 $SLOP_GAMES_DIR you, pointing at a build of your own
2 <plugin>/dist a dist/ copied into the installed plugin
3 ~/.local/share/slop-games npm run omarchy:install in the source repo
4 https://victorlcampos.github.io/slop-games/ the fallback, always there

The fallback is not a downgrade: the published catalog is a PWA whose service worker precaches every game on the first open, so after one game the whole catalog works with no connection. The footer tells you which one you are on — playing from disk or playing from the web.

To play from your own build instead, follow Running locally in the source repository and finish with its omarchy:install script, which writes the built catalog to ~/.local/share/slop-games — the third row above. The panel probes again every time it opens, so there is nothing to restart.

Build in your own checkout, never inside the installed plugin folder. A package manager run in there leaves a node_modules full of symlinks, and omarchy plugin validate — which omarchy plugin update runs before accepting a new revision — refuses a symlink anywhere inside a plugin folder.

Why it launches a browser

Quickshell has no web engine, and every game here is a canvas in an HTML file. omarchy-launch-webapp gives it a window with no tabs and no address bar, which is as close to "the game is an application" as a single HTML file gets, and closer than a browser tab.

This repository is generated

The source lives in victorlcampos/slop-games, under omarchy/, next to the games themselves. npm run omarchy:publish there assembles this repository; Catalog.js is generated from the games' own metadata, so the panel and the catalog can never disagree about what exists.

Open issues and pull requests against that repository.

MIT — see LICENSE.