Omahub
← All plugins
Y

pubmedchy

by yamz8

Search the PubMed biomedical literature from the Omarchy bar

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
ebe42a5
Scanned
1 month ago
  • high destructive_filesystem tests/pubmed.test.mjs:182

    Destructive operation on the root filesystem or a block device.

    rm -rf /", "34968414"]

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
ebe42a5
Reviewed
1 month ago

The plugin is a safe PubMed search widget that makes network requests via curl with strict size limits and sanitizes all remote data. The deterministic scan flagged a literal 'rm -rf /' string in a test fixture, but it is only a test input to verify rejection and is never executed.

  • The test file contains a harmless string 'rm -rf /' used as a negative test case; it is not executed and poses no risk.
  • Network requests to NCBI are expected and bounded by --max-filesize and head -c.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/yamz8/pubmedchy --enable
Productivity #bar #quickshell

pubmedchy

pubmedchy is a native Omarchy bar plugin for searching PubMed, the U.S. National Library of Medicine's index of biomedical literature. Search by topic, author, journal, MeSH term, or PMID, then refine the live results by publication window and article type.

Each result shows its PMID, publication year, journal, authors, article type, and whether a free full text is available at PubMed Central. Opening a result hands it to Omarchy's configured browser.

The plugin uses the NCBI E-utilities API directly and needs no API key. A search runs two requests: esearch for the ranked PMID list and match count, then esummary for the citation details. Results keep PubMed's own ranking rather than being re-sorted locally.

It does not write a cache, history, or analytics data, and clears the query and results whenever the panel closes. Queries are still sent to NCBI, so do not enter patient names, record numbers, or other personal identifiers.

This is a literature discovery aid, not medical advice.

Omarchy integration

The widget uses Omarchy's native Panel, BarIconButton, KeyboardPanel, PanelHero, ButtonGroup, and theme tokens. Its open-book mark is a monochrome Nerd Font glyph, so it follows the active bar foreground color and font instead of falling back to a colored emoji.

Runtime dependencies are curl and network access to eutils.ncbi.nlm.nih.gov.

Install

omarchy plugin add https://github.com/yamz8/pubmedchy.git --enable

omarchy plugin add clones the repository, validates the manifest, and installs it as yamz8.pubmedchy. Update later with omarchy plugin update yamz8.pubmedchy.

Install from a local checkout

cp -R ./pubmedchy ~/.config/omarchy/plugins/yamz8.pubmedchy
omarchy plugin validate ~/.config/omarchy/plugins/yamz8.pubmedchy
omarchy plugin enable yamz8.pubmedchy

Plugin files hot reload. If the widget does not appear immediately, run:

omarchy-shell shell rescanPlugins

Remove

omarchy plugin disable yamz8.pubmedchy
omarchy plugin remove yamz8.pubmedchy

Removing the plugin takes the widget out of the bar and deletes ~/.config/omarchy/plugins/yamz8.pubmedchy. The plugin stores nothing outside that folder, so nothing else is left behind.

Use

  • Left-click the open-book icon to open the finder.
  • Right-click it to open PubMed.
  • Press Enter to search and then Enter again to open the selected citation.
  • Press Up/Down to choose a result, Esc to close, or Tab to switch bar panels.

The bar editor exposes default publication window, default article type, result order, and result-limit settings. For example:

omarchy bar set yamz8.pubmedchy defaultDate 5y
omarchy bar set yamz8.pubmedchy defaultType REVIEW
omarchy bar set yamz8.pubmedchy sortOrder pub_date
omarchy bar set yamz8.pubmedchy resultLimit 8

Validate

omarchy plugin validate .
node --test tests/pubmed.test.mjs
/usr/lib/qt6/bin/qmlformat Pubmedchy.qml >/dev/null

Data source

PubMed is a service of the U.S. National Library of Medicine. Please respect NCBI's usage policy; without an API key, E-utilities allows up to three requests per second.

License

MIT