Omahub
← All plugins
W

Copilot Usage Panel

by wellatleastitried

Display Copilot usage and quota in the agents panel widget.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
a8078fa
Scanned
5 days ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a8078fa
Reviewed
5 days ago

The deterministic scan found no issues, and I agree there is no obviously dangerous behavior: the plugin is readable, uses no shell injection, has no install hooks, and only runs a Python collector on a timer. I rate it low rather than none because it reads Copilot OAuth tokens from editor configs and the gh CLI and makes an authenticated network request to GitHub, but this is transparent, matches the stated purpose, and the sampled code sends the token only to api.github.com.

  • The collector reads OAuth tokens from ~/.config/github-copilot (apps.json, hosts.json, oauth.json) and via `gh auth token`; this is sensitive, though the sampled code uses them only for the GitHub quota API and does not appear to persist or exfiltrate them.
  • The plugin runs a Python process every 5 minutes and keeps itself loaded, but the operations are limited to reading local Copilot data, fetching quota, and writing a usage record under the user's state directory.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/wellatleastitried/omarchy-copilot-panel-usage --enable

Copilot Panel Usage Plugin

Displays Copilot usage and quota in the Omarchy agents panel.

Copilot usage inside of Omarchy with Agents Panel

Install

omarchy plugin add https://github.com/wellatleastitried/omarchy-copilot-panel-usage.git --enable

Uninstall

omarchy plugin remove wellatleastitried.copilot-panel-usage

Requirements

  • Python 3.10+
  • Copilot CLI installed with session history at ~/.copilot/session-store.db
  • Optional: An authenticated gh session OR editor OAuth tokens for quota display (VS Code, JetBrains, or copilot.vim plugin)

Overview

Note: This plugin was built from my PR that is open in Omarchy. If this PR is merged, this plugin will no longer be supported.

Shows token usage by model, active days, and current quota limits. Reads from Copilot CLI's local session store and fetches quota from GitHub's API (requires editor OAuth tokens or an authenticated gh session).

Data updates every 5 minutes or when you refresh the agents panel.

License

MIT