Omahub
← All plugins
W

Trace

by Waleed Barakat

A keyboard-first Sentry inbox with native triage, project scope, and default-agent handoff.

Security review

Potentially dangerous behavior detected · 4 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
2f4ec38
Scanned
1 month ago
  • high destructive_filesystem tests/test_model.js:74

    Destructive operation on the root filesystem or a block device.

    rm -rf /' }]
  • high destructive_filesystem tests/test_model.js:81

    Destructive operation on the root filesystem or a block device.

    rm -rf /'))
  • high destructive_filesystem scripts/trace-agent-handoff.sh:61

    Low-level disk manipulation or write command.

    dd of="$fifo" status=none
  • Augments a command with octal/hex escape sequences.

    \0Url":"https://sentry.example.test","organization":"acme"}\n' >"$CURL_CONFIG/trace/config.json"

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2f4ec38
Reviewed
1 month ago

The deterministic scan's high-risk findings are false positives: the `rm -rf /` strings appear only in test assertions (tests/test_model.js) and the `dd` in trace-agent-handoff.sh writes to a private FIFO for the agent handoff, not to a disk. The runtime code is carefully hardened: tokens are streamed via stdin to the keyring and curl, inputs are bounded and validated, and no destructive or obfuscated operations exist in the executable paths.

  • Agent handoff sends a bounded diagnostic packet to the configured Omarchy agent via a private FIFO; this is user-initiated and disclosed, but the agent provider could be untrusted.
  • The plugin relies on `secret-tool` and `curl`; a compromised keyring or network could expose the Sentry token, but this is standard for such integrations.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/wbarakat/omarchy-trace --enable
Developer Tools #bar #quickshell

Trace for Omarchy

Trace is a native Omarchy inbox for unresolved and regressed Sentry issues. It puts the frequent triage loop in a calm bar badge and tiled Quickshell window; Sentry remains the place for event exploration, releases, dashboards, and administration.

At a glance

Feature What Trace does
Calm bar inbox Polls Sentry in the background and only asks for attention when an issue is new, unreviewed, regressed, or disconnected.
Project and environment scope Loads selected Sentry projects and environments, then switches project scope instantly from the keyboard.
Triage ordering Puts regressions first, followed by unreviewed issues, explicit Sentry priority, and recency.
Native issue context Shows tags, affected users, breadcrumbs, and highlighted in-app stack frames without embedding a browser.
Explain with AI Hands a bounded diagnostic packet to the user’s configured Omarchy agent after an explicit privacy confirmation.
Sentry actions Reviews, resolves, assigns to the authenticated member, and timed-ignores issues without deleting data.
Regression notifications Sends one quiet desktop notification when an issue newly enters regression, with deduplication while it remains regressed.
Keyboard-first workflow Supports navigation, search, project switching, every triage action, agent handoff, refresh, and help without a mouse.
Offline demo Exercises the same service, model, detail, filter, and action paths with checked-in fictional data.

It does not delete Sentry data, edit alert rules, provide dashboards, or embed a browser. The initial provider is Sentry SaaS and self-hosted Sentry REST APIs.

Install

Install and enable Trace from GitHub:

omarchy plugin add https://github.com/wbarakat/omarchy-trace.git --enable

For a local checkout or development install:

omarchy plugin add "$PWD" --enable

Trace never edits Hyprland, Omarchy themes, or other user configuration.

Requirements

  • Omarchy Quattro with shell plugin support;
  • curl, jq, and python3 for the Sentry REST helper;
  • secret-tool from libsecret for live credentials;
  • wl-copy from wl-clipboard for the copy action;
  • notify-send from libnotify for optional regression notifications.
  • a configured Omarchy default agent for the optional Explain with AI handoff.

Demo mode is offline and only requires Omarchy plus jq.

First run

Open Trace from its bar icon. Setup asks for the Sentry base URL (default https://sentry.io), organization slug, optional comma-separated project slugs, comma-separated environments (default production; blank means all), and an API token. The token is accepted over stdin and stored only in GNOME Keyring by scripts/trace-api.sh; it is never written to settings, fixtures, logs, command arguments, or the process list. Non-secret settings are stored in ~/.config/trace/config.json with owner-only permissions, and caches are under ~/.cache/trace/ with the same intent.

The token needs the smallest practical Sentry permissions for the actions you use: issue read access, and issue write access for review, resolve, assignment, and timed ignore. Use a personal user token when you want per-user review state or assign-to-me; an organization token can be sufficient for read/resolve-only use where your Sentry policy permits it. Trace cannot prevent Sentry administrators from revoking a token; a disconnected state is shown instead of treating stale data as current.

Demo mode

Choose Demo mode from setup to inspect realistic checked-in issues without a Sentry account or network access. Demo data is deliberately handled by the same normalization, filtering, selection, and detail paths as live responses; actions report their demo result and do not contact Sentry. Leave demo mode from Settings to return to the configured organization.

Keyboard controls

Key Action
j / k, arrows Move through issues
Enter Open, choose, or confirm the current action
Esc Cancel, return from detail, then close the window
e Resolve selected issue
a Assign it to me
x Mark it reviewed
z, then j / k, Enter Choose a timed ignore duration; confirm with Enter
i Explain with the configured Omarchy agent after confirmation
o Open the Sentry permalink
y Copy the permalink
/, Ctrl+K Search
p, then j / k, Enter Choose the current project scope
g r / g u Regressions / unresolved
F5 Refresh
? Show shortcuts

Actions are only reflected after the helper reports success. A failed request leaves the issue intact and puts its safe, shortened error in the status line.

What the actions change

Action Result
Review Keeps the issue unresolved, but clears its unreviewed attention state for you.
Resolve Leaves the issue in Sentry as resolved and removes it from Trace’s unresolved inbox.
Assign Assigns the issue to your Sentry account and keeps it in the inbox.
Ignore Marks the issue ignored for the chosen duration; it leaves the inbox until Sentry reactivates it.
Explain Sends bounded issue context to the configured Omarchy agent; it does not change the issue in Sentry.
Open / copy Does not change the issue; it opens or copies the canonical Sentry URL.

In demo mode these changes are local and reset when the demo data reloads.

Security and limitations

Trace treats all API text as untrusted plain text: control characters are removed and fields are length-limited before they reach QML. URLs are accepted only with http or https schemes. The helper validates identifiers and URL components, uses request timeouts, rejects non-2xx responses, and redacts credential-shaped values from errors. Cached data is labelled by its fetch time; it is never presented as live when Sentry is unavailable.

Bearer headers are streamed directly from the keyring into curl's stdin and never written to a temporary curl config. Sentry responses are capped at 4 MiB, and the shell incrementally collects at most 1 MiB of helper output before it will refuse to parse it. Agent handoff sends the bounded diagnostic packet over a private, one-time FIFO in the user's runtime directory; only a generic instruction and opaque FIFO path appear in process arguments.

Provider issue arrays are sliced to the configured 10–100 issue window before field normalization. Every Sentry helper invocation has a 90-second process deadline, recurring refreshes are coalesced while work is active, and the remaining operation queue is capped rather than allowed to grow without bound.

Detail entries, frames, tags, and breadcrumbs are each sliced to 100 items before mapping. Trace accepts one JSON document per response, copies only known scalar metadata fields, and does not retain arbitrary frame variables or nested provider objects. Local configuration is capped at 64 KiB and project and environment arrays at 20 items before mapping; stale caches are capped at 1 MiB and normalized again before use. Setup and notification stdin are independently bounded as well.

Trace is a thin inbox, not a replacement for Sentry. One connection represents one Sentry organization; switching organizations deliberately means reconnecting. Search and the project picker operate on the current bounded fetch (10–100 issues), and pagination is not yet exposed. Large organizations may still encounter Sentry rate limits, and filters narrow the list rather than changing Sentry permissions. Stack traces and breadcrumbs can contain application-sensitive information; they remain local until you explicitly open the permalink, copy it, or confirm an agent handoff. Explain with AI may send the displayed issue metadata, tags, stack trace, breadcrumbs, and permalink to the configured agent provider. Trace labels the entire diagnostic block as untrusted data and asks the agent not to modify files without a separate request.

Removal

omarchy plugin disable wbarakat.trace
omarchy plugin remove wbarakat.trace

Removing the plugin does not silently destroy credentials or cached data. To remove those deliberately, use the keyring UI or the exact service entry shown by your installation, then remove the private Trace directories:

rm -rf ~/.config/trace ~/.cache/trace

Only run that command if you want to discard the saved organization settings and cache. Revoke the Sentry token in Sentry as well when the machine should no longer be trusted.

Using disconnect inside Trace removes its current token, configuration, and cached issue list. Removing the plugin files alone deliberately does not.

Development and validation

make validate

Validation runs the pure Node model tests, shell/source regressions, Omarchy plugin validation when available, git diff --check, and qmllint when it is installed. The project specification is in docs/SPEC.md.

Trace is independent software and is not affiliated with Sentry.