Omahub
← All plugins
M

X Composer

by maiosx

Fullscreen X composer overlay. Serif on black, no outline. Browser handoff by default, optional paid API.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
d6c4141
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d6c4141
Reviewed
1 month ago

The plugin is a fullscreen X composer overlay with a Python backend that defaults to handing off posts to the X web intent in the browser, with paid API posting as an explicit opt-in. The code is well-structured, uses safe file handling (O_NOFOLLOW, permission checks, byte caps), and contains no obfuscation, destructive commands, or hidden persistence. The only notable risk is that the optional paid API mode stores OAuth credentials locally, but this is clearly documented and gated behind explicit user configuration.

  • The optional paid API mode stores OAuth 1.0a credentials in ~/.config/xtweet/config.toml; the backend enforces 0700/0600 permissions and refuses symlinks/foreign owners, but credential theft would be possible if the user's home directory is compromised.
  • The backend spawns a detached worker process and uses xdg-open to open a local redirect file containing the draft text; this is a deliberate design to avoid leaking the draft in argv, but a malicious local process could still read the redirect file before it is cleaned up.
  • The plugin is keepLoaded and runs a service that persists drafts and job state; this is expected behavior for the plugin's functionality, but it means the backend process is always resident while the shell is running.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/maiosx/X-Composer --enable
Other #bar

X Composer

X Composer preview

A fullscreen Omarchy overlay for composing X posts. Black field, no outline, centered serif composer. Click the X in the bar. Escape dismisses.

Built from the same overlay template as Soprano and Runway: WlrLayer.Overlay, exclusive keyboard focus, keepLoaded, bar-widget toggle.

Posting is a browser handoff by default (https://x.com/intent/tweet). Paid X API posting is an explicit opt-in.

Install

omarchy plugin add https://github.com/maiosx/X-Composer.git --enable --yes

Add a Hyprland binding to ~/.config/hypr/bindings.lua:

o.bind("SUPER + X", "X Composer", "omarchy-shell shell toggle x.composer")

Choose any unused chord if SUPER + X is already bound. For a local checkout:

plugin_dir="$HOME/.config/omarchy/plugins/x.composer"
mkdir -p "$(dirname "$plugin_dir")"
ln -s "$PWD" "$plugin_dir"
omarchy-shell shell rescanPlugins
omarchy plugin enable x.composer

Enable the X Composer bar widget from Setup → Bar if it does not appear on the right side.

Use

  • Click X in the bar to open or close the overlay.
  • Type in the centered serif field. There is no panel chrome and no outline.
  • Continue in X hands off to the web composer (or posts, in paid API mode) and hides the overlay. Escape also dismisses.
  • Drafts persist across open/close cycles.

IPC:

omarchy-shell shell toggle x.composer
omarchy-shell xcomposer toggle|open|close|status
omarchy-shell xcomposer compose "hello from IPC"

Configure

mkdir -m 700 -p ~/.config/xtweet
cp ~/.config/omarchy/plugins/x.composer/config.example.toml ~/.config/xtweet/config.toml
chmod 600 ~/.config/xtweet/config.toml

Leave paid_api = false (the default) to hand off to the X web composer. Set paid_api = true and fill all four OAuth 1.0a fields to post directly via POST /2/tweets. Partial credentials stay on the free Web Intent.

Pricing is pay-per-use and changes; the X Developer Console is authoritative.

Optional CLI

ln -sf ~/.config/omarchy/plugins/x.composer/bin/xtweet ~/.local/bin/xtweet
printf '%s' 'Your post text here' | xtweet post

Post text is always passed on stdin, never as a command-line argument.

Remove

omarchy plugin disable x.composer
omarchy plugin remove x.composer --yes
rm -f ~/.local/bin/xtweet
rm -rf ~/.config/xtweet

License

MIT — see LICENSE. Posting backend adapted from bitr0t.omarchytweet (Ryan Macy, MIT).