{"schemaVersion":1,"plugins":[{"package":"@ericvrp/omarchy-bar-autohide","repository":"ericvrp/omarchy-bar-autohide","repositoryId":1312622234,"path":"","commit":"514d6fc353f5b88b7c159edc7d3cab74d60506ce","tree":"ea7256eece8d8f06cd129a1cca3b6d693bb85d64","manifestSha256":"920b19cb7ab8c7cab721753ee1d954e07d3cf557e274379021e23ef3aad419b7","id":"ericvrp.bar-autohide","name":"Bar Autohide","description":"Event-driven auto-hide for the Omarchy bar","author":"Eric van Riet Paap","license":"MIT","version":"1.3.0","kinds":["service"],"publisher":"","publishedAt":"2026-09-09T14:45:27.451018+00:00","repositoryCreatedAt":"2026-07-26T08:19:15Z","stars":2,"forks":2,"warnings":["Service.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"ericvrp.bar-autohide","name":"Bar Autohide","version":"1.3.0","author":"Eric van Riet Paap","description":"Event-driven auto-hide for the Omarchy bar","license":"MIT","kinds":["service"],"entryPoints":{"service":"Service.qml"}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[{"file":"Service.qml","line":15,"evidence":"property var shell: null"},{"file":"Service.qml","line":93,"evidence":"command: [\"bash\", \"-c\", \"[[ -f \" + Util.shellQuote(root.barOffFile)"},{"file":"scripts/dev-install.sh","line":1,"evidence":"#!/bin/bash"},{"file":"scripts/dev-uninstall.sh","line":1,"evidence":"#!/bin/bash"}],"process":[{"file":"Service.qml","line":89,"evidence":"Process {"}],"filesystemRead":[],"filesystemWrite":[{"file":"Service.qml","line":85,"evidence":"Util.execDetached(\"rm -f \" + Util.shellQuote(barOffFile))"},{"file":"Service.qml","line":103,"evidence":"Util.execDetached(\"mkdir -p \" + Util.shellQuote(root.toggleDir)"},{"file":"Service.qml","line":188,"evidence":"Util.execDetached(\"mkdir -p \" + Util.shellQuote(toggleDir)"},{"file":"Service.qml","line":191,"evidence":"Util.execDetached(\"rm -f \" + Util.shellQuote(barOffFile))"},{"file":"scripts/dev-install.sh","line":24,"evidence":"mkdir -p \"$plugin_dir\" \"$(dirname -- \"$shell_config\")\""},{"file":"scripts/dev-install.sh","line":30,"evidence":"rm -f \"$plugin_dir/cursor_poll.py\""},{"file":"scripts/dev-install.sh","line":31,"evidence":"rm -rf \"$legacy_plugin_dir\""},{"file":"scripts/dev-install.sh","line":78,"evidence":"os.unlink(temporary)"},{"file":"scripts/dev-uninstall.sh","line":58,"evidence":"os.unlink(temporary)"},{"file":"scripts/dev-uninstall.sh","line":66,"evidence":"rm -rf \"$plugin_dir\""},{"file":"scripts/dev-uninstall.sh","line":67,"evidence":"rm -rf \"$legacy_plugin_dir\""}],"environment":[{"file":"Service.qml","line":13,"evidence":"property string toggleDir: Quickshell.env(\"HOME\") + \"/.local/state/omarchy/toggles\""},{"file":"scripts/dev-install.sh","line":16,"evidence":"repo_dir=$(cd -- \"$(dirname -- \"${BASH_SOURCE[0]}\")/..\" && pwd)"},{"file":"scripts/dev-install.sh","line":17,"evidence":"config_home=${XDG_CONFIG_HOME:-$HOME/.config}"},{"file":"scripts/dev-install.sh","line":19,"evidence":"plugin_dir=\"$config_home/omarchy/plugins/$plugin_id\""},{"file":"scripts/dev-install.sh","line":20,"evidence":"legacy_plugin_dir=\"$config_home/omarchy/plugins/autohide\""},{"file":"scripts/dev-install.sh","line":21,"evidence":"shell_config=\"$config_home/omarchy/shell.json\""},{"file":"scripts/dev-install.sh","line":22,"evidence":"defaults=\"${OMARCHY_PATH:-/usr/share/omarchy}/config/omarchy/shell.json\""},{"file":"scripts/dev-install.sh","line":24,"evidence":"mkdir -p \"$plugin_dir\" \"$(dirname -- \"$shell_config\")\""},{"file":"scripts/dev-install.sh","line":26,"evidence":"if [[ $repo_dir != \"$plugin_dir\" ]]; then"},{"file":"scripts/dev-install.sh","line":27,"evidence":"install -m 0644 \"$repo_dir/manifest.json\" \"$plugin_dir/manifest.json\""},{"file":"scripts/dev-install.sh","line":28,"evidence":"install -m 0644 \"$repo_dir/Service.qml\" \"$plugin_dir/Service.qml\""},{"file":"scripts/dev-install.sh","line":30,"evidence":"rm -f \"$plugin_dir/cursor_poll.py\""}],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[]},"counts":{"network":0,"shell":4,"process":1,"filesystemRead":0,"filesystemWrite":11,"environment":29,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":0},"qml":[{"file":"Service.qml","warnings":134,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800492","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"99ed90cfbd9c21edc5f20033d811615eb39b7e9430bc01c10fae8fb12023a57c","slug":"55416616d4f656724286"},{"package":"@nuu-maan/coffer-omarchy-plugin","repository":"Nuu-maan/coffer-omarchy-plugin","repositoryId":1352745516,"path":"","commit":"d7dee38657af991fac7490c1ab8a1cd4780e9289","tree":"b4ddeba0d005cc21123afe928d019e13ff0e6c67","manifestSha256":"981bb870284796aa8dc2b9f341f3907a5d66f9fc771ce0dab05eac7e01a0d6a5","id":"io.github.nuu-maan.coffer","name":"Coffer","description":"Coffer's capture queue in the Omarchy bar. See what is still open, stash a selection or clip a region without leaving what you are doing.","author":"nuu-maan","license":"MIT","version":"0.1.0","kinds":["service","bar-widget"],"publisher":"Nuu-maan","publishedAt":"2026-09-09T19:46:34.852933+00:00","repositoryCreatedAt":"2026-08-31T18:39:17Z","stars":0,"forks":0,"warnings":["Service.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/20","manifest":{"schemaVersion":1,"id":"io.github.nuu-maan.coffer","name":"Coffer","version":"0.1.0","author":"nuu-maan","license":"MIT","description":"Coffer's capture queue in the Omarchy bar. See what is still open, stash a selection or clip a region without leaving what you are doing.","kinds":["service","bar-widget"],"keepLoaded":true,"entryPoints":{"service":"Service.qml","barWidget":"Panel.qml"},"barWidget":{"displayName":"Coffer","description":"Open items in the Coffer capture queue","category":"Utility","allowMultiple":false,"defaultSection":"right","defaults":{"hideWhenEmpty":false,"maxItems":20},"schema":[{"key":"hideWhenEmpty","type":"boolean","label":"Hide the icon when the queue is empty","description":"Keep the bar icon out of the way until something is stashed. Left off, the icon stays put and dims instead.","defaultValue":false},{"key":"maxItems","type":"integer","label":"Items shown in the panel","description":"How many open items the panel lists before it stops and says how many more there are. The bar count is always the full number.","min":5,"max":100,"step":5,"defaultValue":20}]}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[{"file":"Service.qml","line":10,"evidence":"property var shell: null"},{"file":"Service.qml","line":98,"evidence":"Quickshell.execDetached([\"bash\", \"-c\", \"wl-copy --type image/png < \\\"$1\\\"\", \"wl-copy\", path])"},{"file":"bin/omarchy-coffer","line":1,"evidence":"#!/usr/bin/env bash"},{"file":"dev-install.sh","line":1,"evidence":"#!/usr/bin/env bash"}],"process":[{"file":"Service.qml","line":107,"evidence":"Process {"},{"file":"bin/omarchy-coffer","line":10,"evidence":"line=$(sed -n 's/^Exec=//p' \"$file\" | head -n1) || true"},{"file":"bin/omarchy-coffer","line":60,"evidence":"stash) exec \"$BIN\" --stash ;;"},{"file":"bin/omarchy-coffer","line":61,"evidence":"clip) exec \"$BIN\" --clip ;;"},{"file":"bin/omarchy-coffer","line":64,"evidence":"exec \"$BIN\" \"--done=$1\""},{"file":"tests/manifest.test.js","line":12,"evidence":"process.exitCode = 1"},{"file":"tests/manifest.test.js","line":89,"evidence":"if (!process.exitCode) console.log(passed + \" manifest tests passed\")"},{"file":"tests/model.test.js","line":8,"evidence":"process.exitCode = 1"},{"file":"tests/model.test.js","line":184,"evidence":"if (!process.exitCode) console.log(passed + \" model tests passed\")"}],"filesystemRead":[{"file":"Service.qml","line":52,"evidence":"FileView {"}],"filesystemWrite":[{"file":"dev-install.sh","line":8,"evidence":"mkdir -p \"$DEST\""}],"environment":[{"file":"Service.qml","line":9,"evidence":"property string omarchyPath: Quickshell.env(\"OMARCHY_PATH\")"},{"file":"Service.qml","line":16,"evidence":"readonly property string home: Quickshell.env(\"HOME\")"},{"file":"Service.qml","line":24,"evidence":"readonly property string configDir: (Quickshell.env(\"XDG_CONFIG_HOME\") || (home + \"/.config\")) + \"/coffer\""},{"file":"bin/omarchy-coffer","line":6,"evidence":"IFS=: read -ra dirs <<<\"${XDG_DATA_HOME:-$HOME/.local/share}:${XDG_DATA_DIRS:-/usr/local/share:/usr/share}\""},{"file":"bin/omarchy-coffer","line":7,"evidence":"for dir in \"${dirs[@]}\"; do"},{"file":"bin/omarchy-coffer","line":8,"evidence":"for file in \"$dir/applications/coffer.desktop\" \"$dir/applications/com.coffer.app.desktop\"; do"},{"file":"bin/omarchy-coffer","line":9,"evidence":"[[ -r \"$file\" ]] || continue"},{"file":"bin/omarchy-coffer","line":10,"evidence":"line=$(sed -n 's/^Exec=//p' \"$file\" | head -n1) || true"},{"file":"bin/omarchy-coffer","line":11,"evidence":"[[ -n \"$line\" ]] || continue"},{"file":"bin/omarchy-coffer","line":12,"evidence":"line=${line%% %*}"},{"file":"bin/omarchy-coffer","line":13,"evidence":"line=${line#\\\"}"},{"file":"bin/omarchy-coffer","line":14,"evidence":"line=${line%\\\"}"}],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[{"file":"tests/model.test.js","line":142,"evidence":"var image = { id: \"i\", kind: \"image\", file: \"../../.ssh/id_rsa\" }"}]},"counts":{"network":0,"shell":4,"process":9,"filesystemRead":1,"filesystemWrite":1,"environment":33,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":1},"qml":[{"file":"Panel.qml","warnings":645,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Service.qml","warnings":79,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/20#issuecomment-5607760139","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"fb75fd22e0572fd5c4fd65724f4d4cbf4f42d5f393b8f38633da851a8f456aaf","slug":"abc97256971695cb95bf"},{"package":"@elynch303/fan-monitor","repository":"elynch303/fan-monitor","repositoryId":1316395286,"path":"","commit":"0c0b45716517f50f668e4df51e725130ebde628e","id":"io.github.elynch303.fan-monitor","name":"Fan Monitor","description":"Fan-speed and temperature badge for Omarchy bars. Polls lm_sensors every 30s; click for per-fan RPM and per-chip temps (CPU, board, NVMe). Badge turns amber when elevated, red when hot.","author":"elynch303","version":"1.0.0","kinds":["bar-widget"],"license":"Not declared","stars":0,"forks":2,"repositoryCreatedAt":"2026-07-29T17:22:18Z","status":"review-required","publishedAt":null,"importedAt":"2026-09-09T08:40:44.277303+00:00","publisher":null,"warnings":[],"reviews":[],"reports":[],"verification":null,"submissionStatus":"REVIEW REQUIRED","capabilityChanges":[],"trustEvents":[{"type":"upstream","package":"@elynch303/fan-monitor","commit":"0c0b45716517f50f668e4df51e725130ebde628e","state":{"releases":[],"repository":"elynch303/fan-monitor","archived":false,"disabled":false},"requestId":"13e21e8cd26e9954a244a6a096f20442533a33609cf2c40ab601db3e55d86d1a","timestamp":"2026-09-09T14:45:29.199157+00:00","notes":"Invalid manifest license","receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800689"}],"scanDigest":"44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a","slug":"e0062ad63fd2f6edaf95"},{"package":"@glafeara/omarchy-wireguard","repository":"glafeara/omarchy-wireguard","repositoryId":1317471978,"path":"","commit":"acffeb96cb40c207b0cc6698215c04cfb1b56231","tree":"56ffa52573be464dae630fa11c296fce532127b7","manifestSha256":"04dd9211b3980d79931f5c0f3de5ae82883001d1522275e6c8c56bbba0e5a297","id":"glafeara.wireguard","name":"Omawire","description":"Tunnel status, transactional switching, import, rename, QR export, live traffic and drop notifications in the Omarchy bar. Unofficial third-party widget for WireGuard tunnels; not affiliated with the WireGuard project.","author":"glafeara","license":"MIT","version":"2.5.1","kinds":["bar-widget"],"publisher":"","publishedAt":"2026-09-09T14:45:31.415821+00:00","repositoryCreatedAt":"2026-07-30T16:28:58Z","stars":13,"forks":3,"warnings":[],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"glafeara.wireguard","name":"Omawire","version":"2.5.1","author":"glafeara","license":"MIT","description":"Tunnel status, transactional switching, import, rename, QR export, live traffic and drop notifications in the Omarchy bar. Unofficial third-party widget for WireGuard tunnels; not affiliated with the WireGuard project.","kinds":["bar-widget"],"entryPoints":{"barWidget":"Panel.qml"},"barWidget":{"displayName":"Omawire","description":"Toggle, switch and rename NetworkManager WireGuard tunnels, import .conf files, show QR codes, watch traffic, get a toast when a tunnel drops. No sudo required.","category":"Network","allowMultiple":false,"defaultSection":"right","defaults":{"refreshIntervalSec":10,"pingHost":"1.1.1.1"},"schema":[{"key":"refreshIntervalSec","type":"integer","label":"Refresh interval (seconds)","min":2,"max":3600,"step":1,"defaultValue":10},{"key":"pingHost","type":"string","label":"Ping host (empty disables the latency probe)","defaultValue":"1.1.1.1"}]}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[{"file":"Panel.qml","line":269,"evidence":"Quickshell.execDetached([\"bash\", \"-c\", \"printf %s \" + Util.shellQuote(text) + \" | wl-copy\"])"},{"file":"Service.qml","line":7,"evidence":"// deactivates them through backend.sh (nmcli over D-Bus, authorized by"},{"file":"Service.qml","line":8,"evidence":"// polkit \u2014 no sudo, no root shell, config hooks never run)."},{"file":"Service.qml","line":16,"evidence":"readonly property string backendPath: String(Qt.resolvedUrl(\"backend.sh\")).replace(/^file:\\/\\//, \"\")"},{"file":"Service.qml","line":93,"evidence":"// Connection facts from `backend.sh details` \u2014 ip, ip6, endpoint, allowed,"},{"file":"Service.qml","line":209,"evidence":"trafficProcess.command = [\"bash\", \"-c\", trafficScript, \"wireguard\"].concat(activeDevices)"},{"file":"Service.qml","line":216,"evidence":"detailsProcess.command = [\"bash\", backendPath, \"details\", primaryUuid, primaryDevice]"},{"file":"Service.qml","line":241,"evidence":"pingProcess.command = [\"bash\", \"-c\", pingScript, \"wireguard\","},{"file":"Service.qml","line":542,"evidence":"saveProcess.command = [\"bash\", \"-c\","},{"file":"Service.qml","line":670,"evidence":"editProcess.command = [\"bash\", backendPath, \"edit\", _editUuid, _editName]"},{"file":"Service.qml","line":698,"evidence":"exportProcess.command = [\"bash\", backendPath, \"export-file\", profile.uuid, dest]"},{"file":"Service.qml","line":723,"evidence":"qrProcess.command = [\"bash\", backendPath, \"qr-png\", profile.uuid]"}],"process":[{"file":"Service.qml","line":508,"evidence":"// Queued, not fired directly: the process may be busy, and a lost"},{"file":"Service.qml","line":707,"evidence":"// closeQr retracts a render but lets it finish, so the process can be"},{"file":"Service.qml","line":731,"evidence":"// process handler deletes an unwanted result instead of keeping it."},{"file":"Service.qml","line":732,"evidence":"// The process itself is left to finish: killing qrencode mid-write would"},{"file":"Service.qml","line":742,"evidence":"// Each path gets its own detached remover. A shared Process can have its"},{"file":"Service.qml","line":777,"evidence":"// Deferred through a timer because the editor process that produced the"},{"file":"Service.qml","line":869,"evidence":"// is world-readable through /proc/<pid>/cmdline for as long as the process"},{"file":"Service.qml","line":894,"evidence":"\"  exec zenity --file-selection --title='Import WireGuard config' \\\\\\n\" +"},{"file":"Service.qml","line":897,"evidence":"\"  exec kdialog --getopenfilename \\\"$HOME\\\" '*.conf|WireGuard config'\\n\" +"},{"file":"Service.qml","line":899,"evidence":"\"  exec yad --file --title='Import WireGuard config'\\n\" +"},{"file":"Service.qml","line":1050,"evidence":"Process {"},{"file":"Service.qml","line":1080,"evidence":"Process {"}],"filesystemRead":[{"file":"Service.qml","line":908,"evidence":"\"  printf '%s %s %s\\\\n' \\\"$d\\\" \\\"$(cat \\\"$s/rx_bytes\\\")\\\" \\\"$(cat \\\"$s/tx_bytes\\\")\\\"\\n\" +"},{"file":"Service.qml","line":990,"evidence":"FileView {"},{"file":"backend.sh","line":183,"evidence":"t=\"$(cat \"$f\" 2>/dev/null)\" || t=0"},{"file":"backend.sh","line":270,"evidence":"live=\"$(cat \"/sys/class/net/$ifname/mtu\" 2>/dev/null)\" && [ -n \"$live\" ] && mtu=\"$live\""},{"file":"backend.sh","line":586,"evidence":"uuid=\"$(cat /proc/sys/kernel/random/uuid 2>/dev/null)\" ||"},{"file":"backend.sh","line":929,"evidence":"seed=\"$(cat)\""},{"file":"backend.sh","line":947,"evidence":"cat -- \"$tmp\""},{"file":"tests/fake/mktemp","line":8,"evidence":"[ -f \"$count_file\" ] && count=\"$(cat \"$count_file\")\""},{"file":"tests/fake/nmcli","line":22,"evidence":"cat \"$FAKE_DIR/list\" 2>/dev/null"},{"file":"tests/fake/nmcli","line":31,"evidence":"cat \"$FAKE_DIR/partial-export.$u\""},{"file":"tests/fake/nmcli","line":35,"evidence":"cat \"$FAKE_DIR/export.$u\""},{"file":"tests/fake/nmcli","line":48,"evidence":"cat \"$FAKE_DIR/names\" 2>/dev/null"}],"filesystemWrite":[{"file":"Service.qml","line":543,"evidence":"\"mkdir -p \\\"$1\\\" && printf '%s' \\\"$2\\\" > \\\"$1/wireguard-last\\\"\","},{"file":"Service.qml","line":748,"evidence":"if (knownPath !== \"\") Quickshell.execDetached([\"rm\", \"-f\", \"--\", knownPath])"},{"file":"Service.qml","line":752,"evidence":"// current PNG is known to this instance, so remove only that path; do not"},{"file":"backend.sh","line":51,"evidence":"#   cleanup-runtime             remove QR/editor files owned by a dead shell"},{"file":"backend.sh","line":594,"evidence":"printf '%s\\n' \"Could not remove incomplete replacement $uuid; state is unknown \u2014 check connections manually\" >&2"},{"file":"backend.sh","line":845,"evidence":"# and Service destruction remove it; a hard crash is reaped on the next"},{"file":"backend.sh","line":860,"evidence":"trap 'rm -f \"$tmp\"; exit 1' HUP INT TERM"},{"file":"backend.sh","line":861,"evidence":"trap 'rm -f \"$tmp\"' EXIT"},{"file":"backend.sh","line":884,"evidence":"trap 'rm -f -- \"$png\"; exit 1' HUP INT TERM"},{"file":"backend.sh","line":885,"evidence":"trap 'rm -f -- \"$png\"' EXIT"},{"file":"backend.sh","line":892,"evidence":"# Remove only known-safe stale secret-bearing runtime files. New-format names"},{"file":"backend.sh","line":909,"evidence":"rm -f -- \"$png\""}],"environment":[{"file":"Service.qml","line":14,"evidence":"readonly property string stateDir: Quickshell.env(\"HOME\") + \"/.local/state/omarchy\""},{"file":"Service.qml","line":897,"evidence":"\"  exec kdialog --getopenfilename \\\"$HOME\\\" '*.conf|WireGuard config'\\n\" +"},{"file":"Service.qml","line":906,"evidence":"\"  s=\\\"/sys/class/net/$d/statistics\\\"\\n\" +"},{"file":"Service.qml","line":907,"evidence":"\"  [ -r \\\"$s/rx_bytes\\\" ] && [ -r \\\"$s/tx_bytes\\\" ] || continue\\n\" +"},{"file":"Service.qml","line":908,"evidence":"\"  printf '%s %s %s\\\\n' \\\"$d\\\" \\\"$(cat \\\"$s/rx_bytes\\\")\\\" \\\"$(cat \\\"$s/tx_bytes\\\")\\\"\\n\" +"},{"file":"Service.qml","line":921,"evidence":"\"out=\\\"$(ping -n -q -c 1 -W 2 -I \\\"$dev\\\" -- \\\"$host\\\" 2>/dev/null)\\\" || rc=$?\\n\" +"},{"file":"Service.qml","line":922,"evidence":"\"if [ \\\"$rc\\\" != 0 ] && [ \\\"$rc\\\" != 1 ] && [ -n \\\"$src\\\" ]; then\\n\" +"},{"file":"Service.qml","line":924,"evidence":"\"  out=\\\"$(ping -n -q -c 1 -W 2 -I \\\"$src\\\" -- \\\"$host\\\" 2>/dev/null)\\\" || rc=$?\\n\" +"},{"file":"Service.qml","line":926,"evidence":"\"[ \\\"$rc\\\" = 0 ] || exit \\\"$rc\\\"\\n\" +"},{"file":"Service.qml","line":927,"evidence":"\"printf '%s\\\\n' \\\"$out\\\" | awk -F/ '/^rtt|^round-trip/ {print $5; exit}'\\n\""},{"file":"Service.qml","line":973,"evidence":"\"for pair in \\\"$@\\\"; do bash \\\"$be\\\" mark-active \\\"${pair%%:*}\\\" \\\"${pair#*:}\\\" || rc=1; done\\n\" +"},{"file":"Service.qml","line":974,"evidence":"\"exit $rc\\n\""}],"downloads":[],"downloadExecution":[{"file":"backend.sh","line":8,"evidence":"# here ever eval()s config content, so a config file is data, not code."}],"obfuscation":[],"credentials":[{"file":"backend.sh","line":6,"evidence":"# has network-control and settings.modify.system without a password on"},{"file":"backend.sh","line":243,"evidence":"# nmcli runs *without* -s, so no secret is ever read, let alone printed \u2014"},{"file":"backend.sh","line":275,"evidence":"local chunk token count=0 endpoint=\"\" allowed=\"\""},{"file":"backend.sh","line":283,"evidence":"for token in $chunk; do"},{"file":"backend.sh","line":284,"evidence":"case \"${token%%=*}\" in"},{"file":"backend.sh","line":285,"evidence":"endpoint) endpoint=\"${token#*=}\" ;;"},{"file":"backend.sh","line":286,"evidence":"allowed-ips) allowed=\"${token#*=}\"; allowed=\"${allowed//;/, }\" ;;"},{"file":"backend.sh","line":813,"evidence":"local chunk token first"},{"file":"backend.sh","line":820,"evidence":"for token in $chunk; do"},{"file":"backend.sh","line":822,"evidence":"echo \"PublicKey = $token\""},{"file":"backend.sh","line":826,"evidence":"key=\"${token%%=*}\""},{"file":"backend.sh","line":827,"evidence":"value=\"${token#*=}\""}]},"counts":{"network":0,"shell":98,"process":30,"filesystemRead":23,"filesystemWrite":32,"environment":664,"downloads":0,"downloadExecution":1,"obfuscation":0,"credentials":18},"qml":[{"file":"NamePrompt.qml","warnings":216,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Panel.qml","warnings":1284,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"QrWindow.qml","warnings":289,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"RenameWindow.qml","warnings":92,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Service.qml","warnings":306,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800945","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"1969858b14dbbe7b244906b67182723d039d6a39df3a6a0e63a8c2082356ff69","slug":"9f84abf0851a448255b2"},{"package":"@ayushkr2003/omarchy-overview","repository":"AyushKr2003/omarchy-overview","repositoryId":1314845013,"path":"","commit":"b09c227ba43182bebf101e5882147029fdddf7f1","id":"omarchy-overview","name":"Overview","description":"Hyprland workspace overview with live window previews.","author":"AyushKr2003","version":"1.0.0","kinds":["overlay"],"license":"Not declared","stars":8,"forks":2,"repositoryCreatedAt":"2026-07-28T10:28:58Z","status":"review-required","publishedAt":null,"importedAt":"2026-09-09T08:40:36.911508+00:00","publisher":null,"warnings":[],"reviews":[],"reports":[],"verification":null,"submissionStatus":"REVIEW REQUIRED","capabilityChanges":[],"trustEvents":[{"type":"upstream","package":"@ayushkr2003/omarchy-overview","commit":"b09c227ba43182bebf101e5882147029fdddf7f1","state":{"releases":[],"repository":"AyushKr2003/omarchy-overview","archived":false,"disabled":false},"requestId":"d1406516464080d206ace0feb31b382f7fe41b3a41cdfd635e30776915b89a50","timestamp":"2026-09-09T14:45:19.700612+00:00","notes":"Invalid manifest license","receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603799765"}],"scanDigest":"44136fa355b3678a1146ad16f7e8649e94fb4fc21fe77e8310c060f61caaff8a","slug":"6be2c5c1934248ebe92e"},{"package":"@jjdizz1l/dizziee.power-profiles","repository":"JJDizz1L/dizziee.power-profiles","repositoryId":1315368371,"path":"","commit":"b607a941a2e23ef4b5f7855eaafa426d5b949009","tree":"8c2b4b0241d0cbf60bdfe57d94394550e8acbae7","manifestSha256":"34f9de19c42bf962a8a1a966897482ed478a4c0438db35895e3635dfbf000a86","id":"dizziee.power-profiles","name":"Power Profiles","description":"Power profile switcher for desktop systems.","author":"Dizziee","license":"MIT","version":"1.0.0","kinds":["bar-widget"],"publisher":"","publishedAt":"2026-09-10T04:25:57.387259+00:00","repositoryCreatedAt":"2026-07-28T19:36:06Z","stars":0,"forks":0,"warnings":["Panel.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"dizziee.power-profiles","name":"Power Profiles","version":"1.0.0","author":"Dizziee","license":"MIT","description":"Power profile switcher for desktop systems.","kinds":["bar-widget"],"entryPoints":{"barWidget":"Panel.qml"},"barWidget":{"displayName":"Power Profiles","description":"Switch between power-saver, balanced, and performance profiles.","category":"System","allowMultiple":false}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[],"process":[{"file":"Panel.qml","line":66,"evidence":"Process {"},{"file":"Panel.qml","line":75,"evidence":"Process {"}],"filesystemRead":[],"filesystemWrite":[],"environment":[],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[]},"counts":{"network":0,"shell":0,"process":2,"filesystemRead":0,"filesystemWrite":0,"environment":0,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":0},"qml":[{"file":"Panel.qml","warnings":215,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"changedFiles":["README.md"],"compareUrl":"https://github.com/JJDizz1L/dizziee.power-profiles/compare/e790fd60a019903a1f2314d97fede36cd04d0a03...b607a941a2e23ef4b5f7855eaafa426d5b949009","receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5613076721","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"6b03579ff13660f45ab27a6a2536a4f229326905cb02a8cbb2fe362d40e79817","slug":"1cea4c7c7c380f801dfc"},{"package":"@jjdizz1l/dizziee.system-stats","repository":"JJDizz1L/dizziee.system-stats","repositoryId":1315368415,"path":"","commit":"5500990ce9da1d732e58876886c52181d68923cf","tree":"894755dfe74e00024a7f0225d306531bf7d7eafb","manifestSha256":"595ec91e6e3316d5b8b592511eb342ae41d508e0a041206d7b8e785257d966bb","id":"dizziee.system-stats","name":"System Stats","description":"CPU, GPU, Memory, and Storage monitor with per-compartment toggles.","author":"Dizziee","license":"MIT","version":"1.0.2","kinds":["bar-widget"],"publisher":"","publishedAt":"2026-09-09T14:45:24.678605+00:00","repositoryCreatedAt":"2026-07-28T19:36:08Z","stars":3,"forks":2,"warnings":["Panel.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"dizziee.system-stats","name":"System Stats","version":"1.0.2","author":"Dizziee","license":"MIT","description":"CPU, GPU, Memory, and Storage monitor with per-compartment toggles.","kinds":["bar-widget"],"entryPoints":{"barWidget":"Panel.qml"},"barWidget":{"displayName":"System Stats","description":"Hardware monitoring for CPU, GPU, memory, and storage.","category":"System","allowMultiple":false,"defaults":{"compartments":{"cpu":{"enabled":true,"showInBar":false,"barDisplay":"usage","pollIntervalSec":30},"gpu":{"enabled":false,"showInBar":false,"barDisplay":"usage","pollIntervalSec":30},"memory":{"enabled":true,"showInBar":false,"pollIntervalSec":30},"storage":{"enabled":true,"showInBar":false,"pollIntervalSec":30}}},"schema":[{"key":"compartments","type":"object","label":"Compartments","description":"Per-compartment settings","options":[{"key":"cpu","label":"CPU","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":true},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"barDisplay","type":"enum","label":"Bar display","options":["usage","temp","both"],"defaultValue":"usage"},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]},{"key":"gpu","label":"GPU","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":false},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"barDisplay","type":"enum","label":"Bar display","options":["usage","temp","both"],"defaultValue":"usage"},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]},{"key":"memory","label":"Memory","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":true},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]},{"key":"storage","label":"Storage","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":true},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]}]}]}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[],"process":[{"file":"Panel.qml","line":314,"evidence":"Process {"},{"file":"Panel.qml","line":323,"evidence":"Process {"},{"file":"Panel.qml","line":332,"evidence":"Process {"},{"file":"scripts/system_stats_scanner.py","line":11,"evidence":"import subprocess"},{"file":"scripts/system_stats_scanner.py","line":117,"evidence":"result = subprocess.run("},{"file":"scripts/system_stats_scanner.py","line":226,"evidence":"result = subprocess.run([\"lspci\"], capture_output=True, text=True, timeout=3)"},{"file":"scripts/system_stats_scanner.py","line":244,"evidence":"result = subprocess.run("}],"filesystemRead":[{"file":"Panel.qml","line":302,"evidence":"FileView {"},{"file":"Panel.qml","line":308,"evidence":"FileView {"}],"filesystemWrite":[],"environment":[],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[]},"counts":{"network":0,"shell":0,"process":7,"filesystemRead":2,"filesystemWrite":0,"environment":0,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":0},"qml":[{"file":"Panel.qml","warnings":1446,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800261","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"2881ab946fc305aa0ac1cd9d50a8425990d041b17fc05703e052b8355f11345b","slug":"9c8e33969b0ab09191aa"},{"package":"@nuu-maan/omarchy-widgets","repository":"Nuu-maan/omarchy-widgets","repositoryId":1359152458,"path":"","commit":"9265e49ed7bd52b87a86840044dda6462cb6002d","tree":"1da32d2e4d5f834839e8462dc550bad31734f431","manifestSha256":"6a85364322bf3b6c557249edb7959c48d56a5c2b2f2e14ce6b50f6c77d08292e","id":"anishfn.widgets","name":"Widgets","description":"Desktop widgets that sit on your wallpaper and take their colors from your Omarchy theme. Choose which ones are on screen from the bar.","author":"anishfn","license":"MIT","version":"0.2.0","kinds":["panel","bar-widget","service"],"publisher":"Nuu-maan","publishedAt":"2026-09-09T14:45:07.233925+00:00","repositoryCreatedAt":"2026-09-06T13:09:38Z","stars":0,"forks":0,"warnings":["Service.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"anishfn.widgets","name":"Widgets","version":"0.2.0","author":"anishfn","license":"MIT","description":"Desktop widgets that sit on your wallpaper and take their colors from your Omarchy theme. Choose which ones are on screen from the bar.","repository":"https://github.com/anishfn/omarchy-widgets","keywords":["widgets","desktop","clock","wallpaper","quickshell"],"kinds":["panel","bar-widget","service"],"keepLoaded":true,"entryPoints":{"panel":"Surface.qml","barWidget":"BarWidget.qml","service":"Service.qml"},"barWidget":{"displayName":"Widgets","description":"Choose which desktop widgets are on screen.","category":"Desktop","allowMultiple":false,"defaultSection":"right","defaults":{"showCount":false},"schema":[{"key":"showCount","type":"boolean","label":"Show how many widgets are on","defaultValue":false}]}},"scan":{"validation":"passed","capabilities":{"network":[{"file":"Model.js","line":1774,"evidence":"if (isSafeRepo(candidates[i])) return \"https://github.com/\" + candidates[i]"},{"file":"Service.qml","line":387,"evidence":"\"https://wttr.in/\" + query + \"?format=j1\"]"},{"file":"Service.qml","line":470,"evidence":"\"https://github.com/users/\" + login + \"/contributions\"]"},{"file":"Service.qml","line":562,"evidence":"\"https://api.github.com/repos/\" + name]"},{"file":"Service.qml","line":604,"evidence":"\"https://api.github.com/search/issues?per_page=1&q=repo:\""},{"file":"install","line":31,"evidence":"#   curl -fsSL https://raw.githubusercontent.com/anishfn/omarchy-widgets/main/install | bash -s -- --yes"},{"file":"install","line":39,"evidence":"URL=\"https://github.com/anishfn/omarchy-widgets.git\""},{"file":"install","line":48,"evidence":"\"palccod.omate|https://github.com/Palccod/Omate.git|the Omate card|the desktop pet's switch, its skins, and its dials\""},{"file":"manifest.json","line":9,"evidence":"\"repository\": \"https://github.com/anishfn/omarchy-widgets\","},{"file":"tests/model.test.js","line":1523,"evidence":"\"https://github.com/Nuu-maan/Filly-Discord-Token-Filler\")"},{"file":"tests/model.test.js","line":1526,"evidence":"assert.equal(Model.repoUrl(null, \"cli/cli\"), \"https://github.com/cli/cli\")"},{"file":"tests/model.test.js","line":1547,"evidence":"\"https://github.com/cli/cli\")"}],"shell":[{"file":"Editor.qml","line":24,"evidence":"property var shell: null"},{"file":"Editor.qml","line":364,"evidence":"shell: root.shell"},{"file":"Editor.qml","line":845,"evidence":"shell: root.shell"},{"file":"Service.qml","line":16,"evidence":"property var shell: null"},{"file":"Service.qml","line":236,"evidence":"// and it is cheap: one short-lived bash for every zone in the config,"},{"file":"Service.qml","line":261,"evidence":"zoneProc.command = [\"/usr/bin/timeout\", \"-k\", \"2\", \"5\", \"/usr/bin/bash\", \"-c\", service.zoneScript, \"--\"].concat(zones)"},{"file":"Surface.qml","line":25,"evidence":"property var shell: null"},{"file":"Surface.qml","line":171,"evidence":"shell: root.shell"},{"file":"Surface.qml","line":188,"evidence":"item.shell = root.shell"},{"file":"WidgetInstance.qml","line":20,"evidence":"property var shell: null"},{"file":"WidgetInstance.qml","line":53,"evidence":"if (\"shell\" in item) item.shell = root.shell"},{"file":"dev/preview","line":1,"evidence":"#!/bin/bash"}],"process":[{"file":"Model.js","line":1980,"evidence":"while ((match = pattern.exec(html)) !== null) {"},{"file":"Model.js","line":2225,"evidence":"// should not have to wait for a subprocess to answer."},{"file":"Model.js","line":2403,"evidence":"var m = /^([+-])(\\d{2})(\\d{2})(\\d{2})?$/.exec(String(value || \"\").replace(/^\\s+|\\s+$/g, \"\"))"},{"file":"Model.js","line":2417,"evidence":"var m = /^(\\d{4})(\\d{2})(\\d{2})(?:T(\\d{2})(\\d{2})(\\d{2})(Z)?)?$/.exec(s)"},{"file":"Model.js","line":2456,"evidence":"var weeks = /^P(\\d+)W$/.exec(s)"},{"file":"Model.js","line":2458,"evidence":"var m = /^P(?:(\\d+)D)?(?:T(?:(\\d+)H)?(?:(\\d+)M)?(?:(\\d+)S)?)?$/.exec(s)"},{"file":"Model.js","line":2514,"evidence":"var m = /^([+-]?\\d{1,2})?(SU|MO|TU|WE|TH|FR|SA)$/.exec(days[d])"},{"file":"Model.js","line":2691,"evidence":"// zoneinfo lookup the shell would have to run a subprocess for."},{"file":"Model.js","line":2857,"evidence":"// from the network being turned into objects inside the process that draws"},{"file":"Model.js","line":3167,"evidence":"var todoTxt = /^x\\s+(?:\\d{4}-\\d{2}-\\d{2}\\s+)?(.*)$/.exec(rest)"},{"file":"Model.js","line":3172,"evidence":"var box = /^\\[([ xX\\u00d7~-])\\]\\s*(.*)$/.exec(rest)"},{"file":"Model.js","line":3180,"evidence":"var bang = /^!+\\s*(.*)$/.exec(rest)"}],"filesystemRead":[{"file":"Service.qml","line":217,"evidence":"FileView {"},{"file":"Service.qml","line":224,"evidence":"// Absent on first run. FileView reports that as a failure rather than as"},{"file":"Service.qml","line":356,"evidence":"FileView {"},{"file":"Service.qml","line":825,"evidence":"delegate: FileView {"},{"file":"dev/preview","line":45,"evidence":"cat > \"$ROOT/shell.qml\" <<EOF"},{"file":"install","line":242,"evidence":"cat <<'NEXT'"}],"filesystemWrite":[{"file":"Inspector.qml","line":9,"evidence":"// then Duplicate and Remove, then whatever its schema asked for, all reading"},{"file":"Inspector.qml","line":97,"evidence":"// Duplicate and Remove sit up here with the name rather than under the"},{"file":"Inspector.qml","line":99,"evidence":"// be told, and a Remove at the bottom of a list of fields is a Remove"},{"file":"Inspector.qml","line":180,"evidence":"text: \"Remove\""},{"file":"Service.qml","line":208,"evidence":"configFile.setText(text)"},{"file":"Service.qml","line":804,"evidence":"view.setText(next)"},{"file":"Service.qml","line":1100,"evidence":"function remove(id: string): string {"},{"file":"dev/preview","line":40,"evidence":"rm -rf \"$ROOT\""},{"file":"dev/preview","line":41,"evidence":"mkdir -p \"$ROOT\""},{"file":"dev/preview","line":85,"evidence":"trap 'rm -rf \"$ROOT\"' EXIT"},{"file":"tests/model.test.js","line":410,"evidence":"for (const bad of [\"../../etc/passwd\", \"Asia/Kolkata; rm -rf ~\", \"$(id)\", \"/etc/localtime\"]) {"},{"file":"tests/model.test.js","line":2104,"evidence":"for (const bad of [\"\", \"/etc/passwd\", \"../../etc/passwd\", \"Asia/../..\", \"Asia/Kolkata; rm -rf ~\","}],"environment":[{"file":"Service.qml","line":18,"evidence":"property string omarchyPath: Quickshell.env(\"OMARCHY_PATH\")"},{"file":"Service.qml","line":20,"evidence":"readonly property string home: Quickshell.env(\"HOME\")"},{"file":"Service.qml","line":246,"evidence":"'  if [ -f \"/usr/share/zoneinfo/$z\" ]; then\\n' +"},{"file":"Service.qml","line":247,"evidence":"'    printf \\'%s\\\\t%s\\\\n\\' \"$z\" \"$(TZ=\":/usr/share/zoneinfo/$z\" date +%z)\"\\n' +"},{"file":"Service.qml","line":249,"evidence":"'    printf \\'%s\\\\t\\\\n\\' \"$z\"\\n' +"},{"file":"dev/preview","line":29,"evidence":"ROOT=${XDG_RUNTIME_DIR:-/tmp}/omarchy-widgets-preview"},{"file":"dev/preview","line":32,"evidence":"[ -d \"$SHELL_DIR/Commons\" ] || { echo \"Omarchy shell not found at $SHELL_DIR\" >&2; exit 1; }"},{"file":"dev/preview","line":40,"evidence":"rm -rf \"$ROOT\""},{"file":"dev/preview","line":41,"evidence":"mkdir -p \"$ROOT\""},{"file":"dev/preview","line":42,"evidence":"ln -s \"$SHELL_DIR/Commons\" \"$ROOT/Commons\""},{"file":"dev/preview","line":43,"evidence":"ln -s \"$SHELL_DIR/Ui\" \"$ROOT/Ui\""},{"file":"dev/preview","line":45,"evidence":"cat > \"$ROOT/shell.qml\" <<EOF"}],"downloads":[{"file":"Model.js","line":2313,"evidence":"// curl, so it is matched against a pattern rather than escaped -- an"},{"file":"Service.qml","line":383,"evidence":"// and the whole thing is passed as one argv entry to curl."},{"file":"Service.qml","line":386,"evidence":"\"/usr/bin/curl\", \"-fsS\", \"--max-time\", \"15\","},{"file":"Service.qml","line":469,"evidence":"\"/usr/bin/curl\", \"-fsS\", \"--max-time\", \"20\","},{"file":"Service.qml","line":560,"evidence":"\"/usr/bin/curl\", \"-fsSL\", \"--max-time\", \"15\","},{"file":"Service.qml","line":602,"evidence":"\"/usr/bin/curl\", \"-fsSL\", \"--max-time\", \"20\","},{"file":"Service.qml","line":697,"evidence":"// about to be handed to curl as a URL."},{"file":"Service.qml","line":703,"evidence":"\"/usr/bin/curl\", \"-fsSL\", \"--max-time\", \"30\","},{"file":"install","line":21,"evidence":"#     Missing curl is not an install failure; it is four cards that never"},{"file":"install","line":31,"evidence":"#   curl -fsSL https://raw.githubusercontent.com/anishfn/omarchy-widgets/main/install | bash -s -- --yes"},{"file":"install","line":124,"evidence":"\"/usr/bin/curl|weather, the contribution graph, repo pulse and the calendar fetch with it\" \\"},{"file":"tests/model.test.js","line":1982,"evidence":"test(\"a report also parses from the raw string curl hands back\", () => {"}],"downloadExecution":[{"file":"install","line":31,"evidence":"#   curl -fsSL https://raw.githubusercontent.com/anishfn/omarchy-widgets/main/install | bash -s -- --yes"}],"obfuscation":[],"credentials":[{"file":"Model.js","line":249,"evidence":"description: \"What is next, from your Google Calendar's secret iCal address.\","},{"file":"Model.js","line":256,"evidence":"// decoration holding an OAuth token. One GET to Google's own host, no"},{"file":"Model.js","line":265,"evidence":"label: \"Secret iCal address\","},{"file":"Model.js","line":830,"evidence":"// non-empty text setting\" -- would put a calendar's secret address in the"},{"file":"Model.js","line":1934,"evidence":"// /users/<login>/contributions and needs no token. That is the whole source:"},{"file":"Model.js","line":2240,"evidence":"function parseOffsetToken(token) {"},{"file":"Model.js","line":2241,"evidence":"var m = String(token || \"\").match(/^([+-])(\\d{2})(\\d{2})$/)"},{"file":"Model.js","line":2291,"evidence":"// Google Calendar publishes every calendar as an iCalendar file at a secret"},{"file":"Model.js","line":2292,"evidence":"// address: Settings -> Integrate calendar -> \"Secret address in iCal format\"."},{"file":"Model.js","line":2294,"evidence":"// refresh token for a wallpaper decoration to hold, and no third party in the"},{"file":"Model.js","line":2312,"evidence":"// The secret address, to Google's own shape. This becomes a URL handed to"},{"file":"Service.qml","line":422,"evidence":"// /users/<login>/contributions and needs no token. So this goes to"}]},"counts":{"network":26,"shell":19,"process":35,"filesystemRead":6,"filesystemWrite":12,"environment":162,"downloads":12,"downloadExecution":1,"obfuscation":0,"credentials":19},"qml":[{"file":"BarWidget.qml","warnings":412,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Editor.qml","warnings":1019,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Field.qml","warnings":70,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Inspector.qml","warnings":425,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"PickerField.qml","warnings":391,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Service.qml","warnings":376,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"SettingField.qml","warnings":304,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Surface.qml","warnings":123,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetCard.qml","warnings":43,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetInstance.qml","warnings":45,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetRow.qml","warnings":170,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetsMark.qml","warnings":72,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Calendar.qml","warnings":477,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Clock.qml","warnings":187,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Github.qml","warnings":287,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Music.qml","warnings":760,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/MusicButton.qml","warnings":96,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Omate.qml","warnings":935,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Photo.qml","warnings":272,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/RepoPulse.qml","warnings":278,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/TickRing.qml","warnings":55,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Todos.qml","warnings":557,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Weather.qml","warnings":276,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603799330","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"0852aed72f53a0c18fa794dac551550e487048120329d5ea2d3473b498cdf428","slug":"355109434baeed25d3a0"}],"releases":[{"package":"@jjdizz1l/dizziee.power-profiles","repository":"JJDizz1L/dizziee.power-profiles","repositoryId":1315368371,"path":"","commit":"b607a941a2e23ef4b5f7855eaafa426d5b949009","tree":"8c2b4b0241d0cbf60bdfe57d94394550e8acbae7","manifestSha256":"34f9de19c42bf962a8a1a966897482ed478a4c0438db35895e3635dfbf000a86","id":"dizziee.power-profiles","name":"Power Profiles","description":"Power profile switcher for desktop systems.","author":"Dizziee","license":"MIT","version":"1.0.0","kinds":["bar-widget"],"publisher":"","publishedAt":"2026-09-10T04:25:57.387259+00:00","repositoryCreatedAt":"2026-07-28T19:36:06Z","stars":0,"forks":0,"warnings":["Panel.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"dizziee.power-profiles","name":"Power Profiles","version":"1.0.0","author":"Dizziee","license":"MIT","description":"Power profile switcher for desktop systems.","kinds":["bar-widget"],"entryPoints":{"barWidget":"Panel.qml"},"barWidget":{"displayName":"Power Profiles","description":"Switch between power-saver, balanced, and performance profiles.","category":"System","allowMultiple":false}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[],"process":[{"file":"Panel.qml","line":66,"evidence":"Process {"},{"file":"Panel.qml","line":75,"evidence":"Process {"}],"filesystemRead":[],"filesystemWrite":[],"environment":[],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[]},"counts":{"network":0,"shell":0,"process":2,"filesystemRead":0,"filesystemWrite":0,"environment":0,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":0},"qml":[{"file":"Panel.qml","warnings":215,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"changedFiles":["README.md"],"compareUrl":"https://github.com/JJDizz1L/dizziee.power-profiles/compare/e790fd60a019903a1f2314d97fede36cd04d0a03...b607a941a2e23ef4b5f7855eaafa426d5b949009","receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5613076721","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"6b03579ff13660f45ab27a6a2536a4f229326905cb02a8cbb2fe362d40e79817","slug":"1cea4c7c7c380f801dfc"},{"package":"@nuu-maan/coffer-omarchy-plugin","repository":"Nuu-maan/coffer-omarchy-plugin","repositoryId":1352745516,"path":"","commit":"d7dee38657af991fac7490c1ab8a1cd4780e9289","tree":"b4ddeba0d005cc21123afe928d019e13ff0e6c67","manifestSha256":"981bb870284796aa8dc2b9f341f3907a5d66f9fc771ce0dab05eac7e01a0d6a5","id":"io.github.nuu-maan.coffer","name":"Coffer","description":"Coffer's capture queue in the Omarchy bar. See what is still open, stash a selection or clip a region without leaving what you are doing.","author":"nuu-maan","license":"MIT","version":"0.1.0","kinds":["service","bar-widget"],"publisher":"Nuu-maan","publishedAt":"2026-09-09T19:46:34.852933+00:00","repositoryCreatedAt":"2026-08-31T18:39:17Z","stars":0,"forks":0,"warnings":["Service.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/20","manifest":{"schemaVersion":1,"id":"io.github.nuu-maan.coffer","name":"Coffer","version":"0.1.0","author":"nuu-maan","license":"MIT","description":"Coffer's capture queue in the Omarchy bar. See what is still open, stash a selection or clip a region without leaving what you are doing.","kinds":["service","bar-widget"],"keepLoaded":true,"entryPoints":{"service":"Service.qml","barWidget":"Panel.qml"},"barWidget":{"displayName":"Coffer","description":"Open items in the Coffer capture queue","category":"Utility","allowMultiple":false,"defaultSection":"right","defaults":{"hideWhenEmpty":false,"maxItems":20},"schema":[{"key":"hideWhenEmpty","type":"boolean","label":"Hide the icon when the queue is empty","description":"Keep the bar icon out of the way until something is stashed. Left off, the icon stays put and dims instead.","defaultValue":false},{"key":"maxItems","type":"integer","label":"Items shown in the panel","description":"How many open items the panel lists before it stops and says how many more there are. The bar count is always the full number.","min":5,"max":100,"step":5,"defaultValue":20}]}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[{"file":"Service.qml","line":10,"evidence":"property var shell: null"},{"file":"Service.qml","line":98,"evidence":"Quickshell.execDetached([\"bash\", \"-c\", \"wl-copy --type image/png < \\\"$1\\\"\", \"wl-copy\", path])"},{"file":"bin/omarchy-coffer","line":1,"evidence":"#!/usr/bin/env bash"},{"file":"dev-install.sh","line":1,"evidence":"#!/usr/bin/env bash"}],"process":[{"file":"Service.qml","line":107,"evidence":"Process {"},{"file":"bin/omarchy-coffer","line":10,"evidence":"line=$(sed -n 's/^Exec=//p' \"$file\" | head -n1) || true"},{"file":"bin/omarchy-coffer","line":60,"evidence":"stash) exec \"$BIN\" --stash ;;"},{"file":"bin/omarchy-coffer","line":61,"evidence":"clip) exec \"$BIN\" --clip ;;"},{"file":"bin/omarchy-coffer","line":64,"evidence":"exec \"$BIN\" \"--done=$1\""},{"file":"tests/manifest.test.js","line":12,"evidence":"process.exitCode = 1"},{"file":"tests/manifest.test.js","line":89,"evidence":"if (!process.exitCode) console.log(passed + \" manifest tests passed\")"},{"file":"tests/model.test.js","line":8,"evidence":"process.exitCode = 1"},{"file":"tests/model.test.js","line":184,"evidence":"if (!process.exitCode) console.log(passed + \" model tests passed\")"}],"filesystemRead":[{"file":"Service.qml","line":52,"evidence":"FileView {"}],"filesystemWrite":[{"file":"dev-install.sh","line":8,"evidence":"mkdir -p \"$DEST\""}],"environment":[{"file":"Service.qml","line":9,"evidence":"property string omarchyPath: Quickshell.env(\"OMARCHY_PATH\")"},{"file":"Service.qml","line":16,"evidence":"readonly property string home: Quickshell.env(\"HOME\")"},{"file":"Service.qml","line":24,"evidence":"readonly property string configDir: (Quickshell.env(\"XDG_CONFIG_HOME\") || (home + \"/.config\")) + \"/coffer\""},{"file":"bin/omarchy-coffer","line":6,"evidence":"IFS=: read -ra dirs <<<\"${XDG_DATA_HOME:-$HOME/.local/share}:${XDG_DATA_DIRS:-/usr/local/share:/usr/share}\""},{"file":"bin/omarchy-coffer","line":7,"evidence":"for dir in \"${dirs[@]}\"; do"},{"file":"bin/omarchy-coffer","line":8,"evidence":"for file in \"$dir/applications/coffer.desktop\" \"$dir/applications/com.coffer.app.desktop\"; do"},{"file":"bin/omarchy-coffer","line":9,"evidence":"[[ -r \"$file\" ]] || continue"},{"file":"bin/omarchy-coffer","line":10,"evidence":"line=$(sed -n 's/^Exec=//p' \"$file\" | head -n1) || true"},{"file":"bin/omarchy-coffer","line":11,"evidence":"[[ -n \"$line\" ]] || continue"},{"file":"bin/omarchy-coffer","line":12,"evidence":"line=${line%% %*}"},{"file":"bin/omarchy-coffer","line":13,"evidence":"line=${line#\\\"}"},{"file":"bin/omarchy-coffer","line":14,"evidence":"line=${line%\\\"}"}],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[{"file":"tests/model.test.js","line":142,"evidence":"var image = { id: \"i\", kind: \"image\", file: \"../../.ssh/id_rsa\" }"}]},"counts":{"network":0,"shell":4,"process":9,"filesystemRead":1,"filesystemWrite":1,"environment":33,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":1},"qml":[{"file":"Panel.qml","warnings":645,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Service.qml","warnings":79,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/20#issuecomment-5607760139","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"fb75fd22e0572fd5c4fd65724f4d4cbf4f42d5f393b8f38633da851a8f456aaf","slug":"abc97256971695cb95bf"},{"package":"@glafeara/omarchy-wireguard","repository":"glafeara/omarchy-wireguard","repositoryId":1317471978,"path":"","commit":"acffeb96cb40c207b0cc6698215c04cfb1b56231","tree":"56ffa52573be464dae630fa11c296fce532127b7","manifestSha256":"04dd9211b3980d79931f5c0f3de5ae82883001d1522275e6c8c56bbba0e5a297","id":"glafeara.wireguard","name":"Omawire","description":"Tunnel status, transactional switching, import, rename, QR export, live traffic and drop notifications in the Omarchy bar. Unofficial third-party widget for WireGuard tunnels; not affiliated with the WireGuard project.","author":"glafeara","license":"MIT","version":"2.5.1","kinds":["bar-widget"],"publisher":"","publishedAt":"2026-09-09T14:45:31.415821+00:00","repositoryCreatedAt":"2026-07-30T16:28:58Z","stars":13,"forks":3,"warnings":[],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"glafeara.wireguard","name":"Omawire","version":"2.5.1","author":"glafeara","license":"MIT","description":"Tunnel status, transactional switching, import, rename, QR export, live traffic and drop notifications in the Omarchy bar. Unofficial third-party widget for WireGuard tunnels; not affiliated with the WireGuard project.","kinds":["bar-widget"],"entryPoints":{"barWidget":"Panel.qml"},"barWidget":{"displayName":"Omawire","description":"Toggle, switch and rename NetworkManager WireGuard tunnels, import .conf files, show QR codes, watch traffic, get a toast when a tunnel drops. No sudo required.","category":"Network","allowMultiple":false,"defaultSection":"right","defaults":{"refreshIntervalSec":10,"pingHost":"1.1.1.1"},"schema":[{"key":"refreshIntervalSec","type":"integer","label":"Refresh interval (seconds)","min":2,"max":3600,"step":1,"defaultValue":10},{"key":"pingHost","type":"string","label":"Ping host (empty disables the latency probe)","defaultValue":"1.1.1.1"}]}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[{"file":"Panel.qml","line":269,"evidence":"Quickshell.execDetached([\"bash\", \"-c\", \"printf %s \" + Util.shellQuote(text) + \" | wl-copy\"])"},{"file":"Service.qml","line":7,"evidence":"// deactivates them through backend.sh (nmcli over D-Bus, authorized by"},{"file":"Service.qml","line":8,"evidence":"// polkit \u2014 no sudo, no root shell, config hooks never run)."},{"file":"Service.qml","line":16,"evidence":"readonly property string backendPath: String(Qt.resolvedUrl(\"backend.sh\")).replace(/^file:\\/\\//, \"\")"},{"file":"Service.qml","line":93,"evidence":"// Connection facts from `backend.sh details` \u2014 ip, ip6, endpoint, allowed,"},{"file":"Service.qml","line":209,"evidence":"trafficProcess.command = [\"bash\", \"-c\", trafficScript, \"wireguard\"].concat(activeDevices)"},{"file":"Service.qml","line":216,"evidence":"detailsProcess.command = [\"bash\", backendPath, \"details\", primaryUuid, primaryDevice]"},{"file":"Service.qml","line":241,"evidence":"pingProcess.command = [\"bash\", \"-c\", pingScript, \"wireguard\","},{"file":"Service.qml","line":542,"evidence":"saveProcess.command = [\"bash\", \"-c\","},{"file":"Service.qml","line":670,"evidence":"editProcess.command = [\"bash\", backendPath, \"edit\", _editUuid, _editName]"},{"file":"Service.qml","line":698,"evidence":"exportProcess.command = [\"bash\", backendPath, \"export-file\", profile.uuid, dest]"},{"file":"Service.qml","line":723,"evidence":"qrProcess.command = [\"bash\", backendPath, \"qr-png\", profile.uuid]"}],"process":[{"file":"Service.qml","line":508,"evidence":"// Queued, not fired directly: the process may be busy, and a lost"},{"file":"Service.qml","line":707,"evidence":"// closeQr retracts a render but lets it finish, so the process can be"},{"file":"Service.qml","line":731,"evidence":"// process handler deletes an unwanted result instead of keeping it."},{"file":"Service.qml","line":732,"evidence":"// The process itself is left to finish: killing qrencode mid-write would"},{"file":"Service.qml","line":742,"evidence":"// Each path gets its own detached remover. A shared Process can have its"},{"file":"Service.qml","line":777,"evidence":"// Deferred through a timer because the editor process that produced the"},{"file":"Service.qml","line":869,"evidence":"// is world-readable through /proc/<pid>/cmdline for as long as the process"},{"file":"Service.qml","line":894,"evidence":"\"  exec zenity --file-selection --title='Import WireGuard config' \\\\\\n\" +"},{"file":"Service.qml","line":897,"evidence":"\"  exec kdialog --getopenfilename \\\"$HOME\\\" '*.conf|WireGuard config'\\n\" +"},{"file":"Service.qml","line":899,"evidence":"\"  exec yad --file --title='Import WireGuard config'\\n\" +"},{"file":"Service.qml","line":1050,"evidence":"Process {"},{"file":"Service.qml","line":1080,"evidence":"Process {"}],"filesystemRead":[{"file":"Service.qml","line":908,"evidence":"\"  printf '%s %s %s\\\\n' \\\"$d\\\" \\\"$(cat \\\"$s/rx_bytes\\\")\\\" \\\"$(cat \\\"$s/tx_bytes\\\")\\\"\\n\" +"},{"file":"Service.qml","line":990,"evidence":"FileView {"},{"file":"backend.sh","line":183,"evidence":"t=\"$(cat \"$f\" 2>/dev/null)\" || t=0"},{"file":"backend.sh","line":270,"evidence":"live=\"$(cat \"/sys/class/net/$ifname/mtu\" 2>/dev/null)\" && [ -n \"$live\" ] && mtu=\"$live\""},{"file":"backend.sh","line":586,"evidence":"uuid=\"$(cat /proc/sys/kernel/random/uuid 2>/dev/null)\" ||"},{"file":"backend.sh","line":929,"evidence":"seed=\"$(cat)\""},{"file":"backend.sh","line":947,"evidence":"cat -- \"$tmp\""},{"file":"tests/fake/mktemp","line":8,"evidence":"[ -f \"$count_file\" ] && count=\"$(cat \"$count_file\")\""},{"file":"tests/fake/nmcli","line":22,"evidence":"cat \"$FAKE_DIR/list\" 2>/dev/null"},{"file":"tests/fake/nmcli","line":31,"evidence":"cat \"$FAKE_DIR/partial-export.$u\""},{"file":"tests/fake/nmcli","line":35,"evidence":"cat \"$FAKE_DIR/export.$u\""},{"file":"tests/fake/nmcli","line":48,"evidence":"cat \"$FAKE_DIR/names\" 2>/dev/null"}],"filesystemWrite":[{"file":"Service.qml","line":543,"evidence":"\"mkdir -p \\\"$1\\\" && printf '%s' \\\"$2\\\" > \\\"$1/wireguard-last\\\"\","},{"file":"Service.qml","line":748,"evidence":"if (knownPath !== \"\") Quickshell.execDetached([\"rm\", \"-f\", \"--\", knownPath])"},{"file":"Service.qml","line":752,"evidence":"// current PNG is known to this instance, so remove only that path; do not"},{"file":"backend.sh","line":51,"evidence":"#   cleanup-runtime             remove QR/editor files owned by a dead shell"},{"file":"backend.sh","line":594,"evidence":"printf '%s\\n' \"Could not remove incomplete replacement $uuid; state is unknown \u2014 check connections manually\" >&2"},{"file":"backend.sh","line":845,"evidence":"# and Service destruction remove it; a hard crash is reaped on the next"},{"file":"backend.sh","line":860,"evidence":"trap 'rm -f \"$tmp\"; exit 1' HUP INT TERM"},{"file":"backend.sh","line":861,"evidence":"trap 'rm -f \"$tmp\"' EXIT"},{"file":"backend.sh","line":884,"evidence":"trap 'rm -f -- \"$png\"; exit 1' HUP INT TERM"},{"file":"backend.sh","line":885,"evidence":"trap 'rm -f -- \"$png\"' EXIT"},{"file":"backend.sh","line":892,"evidence":"# Remove only known-safe stale secret-bearing runtime files. New-format names"},{"file":"backend.sh","line":909,"evidence":"rm -f -- \"$png\""}],"environment":[{"file":"Service.qml","line":14,"evidence":"readonly property string stateDir: Quickshell.env(\"HOME\") + \"/.local/state/omarchy\""},{"file":"Service.qml","line":897,"evidence":"\"  exec kdialog --getopenfilename \\\"$HOME\\\" '*.conf|WireGuard config'\\n\" +"},{"file":"Service.qml","line":906,"evidence":"\"  s=\\\"/sys/class/net/$d/statistics\\\"\\n\" +"},{"file":"Service.qml","line":907,"evidence":"\"  [ -r \\\"$s/rx_bytes\\\" ] && [ -r \\\"$s/tx_bytes\\\" ] || continue\\n\" +"},{"file":"Service.qml","line":908,"evidence":"\"  printf '%s %s %s\\\\n' \\\"$d\\\" \\\"$(cat \\\"$s/rx_bytes\\\")\\\" \\\"$(cat \\\"$s/tx_bytes\\\")\\\"\\n\" +"},{"file":"Service.qml","line":921,"evidence":"\"out=\\\"$(ping -n -q -c 1 -W 2 -I \\\"$dev\\\" -- \\\"$host\\\" 2>/dev/null)\\\" || rc=$?\\n\" +"},{"file":"Service.qml","line":922,"evidence":"\"if [ \\\"$rc\\\" != 0 ] && [ \\\"$rc\\\" != 1 ] && [ -n \\\"$src\\\" ]; then\\n\" +"},{"file":"Service.qml","line":924,"evidence":"\"  out=\\\"$(ping -n -q -c 1 -W 2 -I \\\"$src\\\" -- \\\"$host\\\" 2>/dev/null)\\\" || rc=$?\\n\" +"},{"file":"Service.qml","line":926,"evidence":"\"[ \\\"$rc\\\" = 0 ] || exit \\\"$rc\\\"\\n\" +"},{"file":"Service.qml","line":927,"evidence":"\"printf '%s\\\\n' \\\"$out\\\" | awk -F/ '/^rtt|^round-trip/ {print $5; exit}'\\n\""},{"file":"Service.qml","line":973,"evidence":"\"for pair in \\\"$@\\\"; do bash \\\"$be\\\" mark-active \\\"${pair%%:*}\\\" \\\"${pair#*:}\\\" || rc=1; done\\n\" +"},{"file":"Service.qml","line":974,"evidence":"\"exit $rc\\n\""}],"downloads":[],"downloadExecution":[{"file":"backend.sh","line":8,"evidence":"# here ever eval()s config content, so a config file is data, not code."}],"obfuscation":[],"credentials":[{"file":"backend.sh","line":6,"evidence":"# has network-control and settings.modify.system without a password on"},{"file":"backend.sh","line":243,"evidence":"# nmcli runs *without* -s, so no secret is ever read, let alone printed \u2014"},{"file":"backend.sh","line":275,"evidence":"local chunk token count=0 endpoint=\"\" allowed=\"\""},{"file":"backend.sh","line":283,"evidence":"for token in $chunk; do"},{"file":"backend.sh","line":284,"evidence":"case \"${token%%=*}\" in"},{"file":"backend.sh","line":285,"evidence":"endpoint) endpoint=\"${token#*=}\" ;;"},{"file":"backend.sh","line":286,"evidence":"allowed-ips) allowed=\"${token#*=}\"; allowed=\"${allowed//;/, }\" ;;"},{"file":"backend.sh","line":813,"evidence":"local chunk token first"},{"file":"backend.sh","line":820,"evidence":"for token in $chunk; do"},{"file":"backend.sh","line":822,"evidence":"echo \"PublicKey = $token\""},{"file":"backend.sh","line":826,"evidence":"key=\"${token%%=*}\""},{"file":"backend.sh","line":827,"evidence":"value=\"${token#*=}\""}]},"counts":{"network":0,"shell":98,"process":30,"filesystemRead":23,"filesystemWrite":32,"environment":664,"downloads":0,"downloadExecution":1,"obfuscation":0,"credentials":18},"qml":[{"file":"NamePrompt.qml","warnings":216,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Panel.qml","warnings":1284,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"QrWindow.qml","warnings":289,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"RenameWindow.qml","warnings":92,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Service.qml","warnings":306,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800945","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"1969858b14dbbe7b244906b67182723d039d6a39df3a6a0e63a8c2082356ff69","slug":"9f84abf0851a448255b2"},{"package":"@ericvrp/omarchy-bar-autohide","repository":"ericvrp/omarchy-bar-autohide","repositoryId":1312622234,"path":"","commit":"514d6fc353f5b88b7c159edc7d3cab74d60506ce","tree":"ea7256eece8d8f06cd129a1cca3b6d693bb85d64","manifestSha256":"920b19cb7ab8c7cab721753ee1d954e07d3cf557e274379021e23ef3aad419b7","id":"ericvrp.bar-autohide","name":"Bar Autohide","description":"Event-driven auto-hide for the Omarchy bar","author":"Eric van Riet Paap","license":"MIT","version":"1.3.0","kinds":["service"],"publisher":"","publishedAt":"2026-09-09T14:45:27.451018+00:00","repositoryCreatedAt":"2026-07-26T08:19:15Z","stars":2,"forks":2,"warnings":["Service.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"ericvrp.bar-autohide","name":"Bar Autohide","version":"1.3.0","author":"Eric van Riet Paap","description":"Event-driven auto-hide for the Omarchy bar","license":"MIT","kinds":["service"],"entryPoints":{"service":"Service.qml"}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[{"file":"Service.qml","line":15,"evidence":"property var shell: null"},{"file":"Service.qml","line":93,"evidence":"command: [\"bash\", \"-c\", \"[[ -f \" + Util.shellQuote(root.barOffFile)"},{"file":"scripts/dev-install.sh","line":1,"evidence":"#!/bin/bash"},{"file":"scripts/dev-uninstall.sh","line":1,"evidence":"#!/bin/bash"}],"process":[{"file":"Service.qml","line":89,"evidence":"Process {"}],"filesystemRead":[],"filesystemWrite":[{"file":"Service.qml","line":85,"evidence":"Util.execDetached(\"rm -f \" + Util.shellQuote(barOffFile))"},{"file":"Service.qml","line":103,"evidence":"Util.execDetached(\"mkdir -p \" + Util.shellQuote(root.toggleDir)"},{"file":"Service.qml","line":188,"evidence":"Util.execDetached(\"mkdir -p \" + Util.shellQuote(toggleDir)"},{"file":"Service.qml","line":191,"evidence":"Util.execDetached(\"rm -f \" + Util.shellQuote(barOffFile))"},{"file":"scripts/dev-install.sh","line":24,"evidence":"mkdir -p \"$plugin_dir\" \"$(dirname -- \"$shell_config\")\""},{"file":"scripts/dev-install.sh","line":30,"evidence":"rm -f \"$plugin_dir/cursor_poll.py\""},{"file":"scripts/dev-install.sh","line":31,"evidence":"rm -rf \"$legacy_plugin_dir\""},{"file":"scripts/dev-install.sh","line":78,"evidence":"os.unlink(temporary)"},{"file":"scripts/dev-uninstall.sh","line":58,"evidence":"os.unlink(temporary)"},{"file":"scripts/dev-uninstall.sh","line":66,"evidence":"rm -rf \"$plugin_dir\""},{"file":"scripts/dev-uninstall.sh","line":67,"evidence":"rm -rf \"$legacy_plugin_dir\""}],"environment":[{"file":"Service.qml","line":13,"evidence":"property string toggleDir: Quickshell.env(\"HOME\") + \"/.local/state/omarchy/toggles\""},{"file":"scripts/dev-install.sh","line":16,"evidence":"repo_dir=$(cd -- \"$(dirname -- \"${BASH_SOURCE[0]}\")/..\" && pwd)"},{"file":"scripts/dev-install.sh","line":17,"evidence":"config_home=${XDG_CONFIG_HOME:-$HOME/.config}"},{"file":"scripts/dev-install.sh","line":19,"evidence":"plugin_dir=\"$config_home/omarchy/plugins/$plugin_id\""},{"file":"scripts/dev-install.sh","line":20,"evidence":"legacy_plugin_dir=\"$config_home/omarchy/plugins/autohide\""},{"file":"scripts/dev-install.sh","line":21,"evidence":"shell_config=\"$config_home/omarchy/shell.json\""},{"file":"scripts/dev-install.sh","line":22,"evidence":"defaults=\"${OMARCHY_PATH:-/usr/share/omarchy}/config/omarchy/shell.json\""},{"file":"scripts/dev-install.sh","line":24,"evidence":"mkdir -p \"$plugin_dir\" \"$(dirname -- \"$shell_config\")\""},{"file":"scripts/dev-install.sh","line":26,"evidence":"if [[ $repo_dir != \"$plugin_dir\" ]]; then"},{"file":"scripts/dev-install.sh","line":27,"evidence":"install -m 0644 \"$repo_dir/manifest.json\" \"$plugin_dir/manifest.json\""},{"file":"scripts/dev-install.sh","line":28,"evidence":"install -m 0644 \"$repo_dir/Service.qml\" \"$plugin_dir/Service.qml\""},{"file":"scripts/dev-install.sh","line":30,"evidence":"rm -f \"$plugin_dir/cursor_poll.py\""}],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[]},"counts":{"network":0,"shell":4,"process":1,"filesystemRead":0,"filesystemWrite":11,"environment":29,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":0},"qml":[{"file":"Service.qml","warnings":134,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800492","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"99ed90cfbd9c21edc5f20033d811615eb39b7e9430bc01c10fae8fb12023a57c","slug":"55416616d4f656724286"},{"package":"@jjdizz1l/dizziee.system-stats","repository":"JJDizz1L/dizziee.system-stats","repositoryId":1315368415,"path":"","commit":"5500990ce9da1d732e58876886c52181d68923cf","tree":"894755dfe74e00024a7f0225d306531bf7d7eafb","manifestSha256":"595ec91e6e3316d5b8b592511eb342ae41d508e0a041206d7b8e785257d966bb","id":"dizziee.system-stats","name":"System Stats","description":"CPU, GPU, Memory, and Storage monitor with per-compartment toggles.","author":"Dizziee","license":"MIT","version":"1.0.2","kinds":["bar-widget"],"publisher":"","publishedAt":"2026-09-09T14:45:24.678605+00:00","repositoryCreatedAt":"2026-07-28T19:36:08Z","stars":3,"forks":2,"warnings":["Panel.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"dizziee.system-stats","name":"System Stats","version":"1.0.2","author":"Dizziee","license":"MIT","description":"CPU, GPU, Memory, and Storage monitor with per-compartment toggles.","kinds":["bar-widget"],"entryPoints":{"barWidget":"Panel.qml"},"barWidget":{"displayName":"System Stats","description":"Hardware monitoring for CPU, GPU, memory, and storage.","category":"System","allowMultiple":false,"defaults":{"compartments":{"cpu":{"enabled":true,"showInBar":false,"barDisplay":"usage","pollIntervalSec":30},"gpu":{"enabled":false,"showInBar":false,"barDisplay":"usage","pollIntervalSec":30},"memory":{"enabled":true,"showInBar":false,"pollIntervalSec":30},"storage":{"enabled":true,"showInBar":false,"pollIntervalSec":30}}},"schema":[{"key":"compartments","type":"object","label":"Compartments","description":"Per-compartment settings","options":[{"key":"cpu","label":"CPU","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":true},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"barDisplay","type":"enum","label":"Bar display","options":["usage","temp","both"],"defaultValue":"usage"},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]},{"key":"gpu","label":"GPU","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":false},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"barDisplay","type":"enum","label":"Bar display","options":["usage","temp","both"],"defaultValue":"usage"},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]},{"key":"memory","label":"Memory","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":true},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]},{"key":"storage","label":"Storage","type":"object","options":[{"key":"enabled","type":"boolean","label":"Enabled","defaultValue":true},{"key":"showInBar","type":"boolean","label":"Show in bar","defaultValue":false},{"key":"pollIntervalSec","type":"integer","label":"Poll interval (seconds)","min":5,"max":3600,"step":5,"defaultValue":30}]}]}]}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[],"process":[{"file":"Panel.qml","line":314,"evidence":"Process {"},{"file":"Panel.qml","line":323,"evidence":"Process {"},{"file":"Panel.qml","line":332,"evidence":"Process {"},{"file":"scripts/system_stats_scanner.py","line":11,"evidence":"import subprocess"},{"file":"scripts/system_stats_scanner.py","line":117,"evidence":"result = subprocess.run("},{"file":"scripts/system_stats_scanner.py","line":226,"evidence":"result = subprocess.run([\"lspci\"], capture_output=True, text=True, timeout=3)"},{"file":"scripts/system_stats_scanner.py","line":244,"evidence":"result = subprocess.run("}],"filesystemRead":[{"file":"Panel.qml","line":302,"evidence":"FileView {"},{"file":"Panel.qml","line":308,"evidence":"FileView {"}],"filesystemWrite":[],"environment":[],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[]},"counts":{"network":0,"shell":0,"process":7,"filesystemRead":2,"filesystemWrite":0,"environment":0,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":0},"qml":[{"file":"Panel.qml","warnings":1446,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800261","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"2881ab946fc305aa0ac1cd9d50a8425990d041b17fc05703e052b8355f11345b","slug":"9c8e33969b0ab09191aa"},{"package":"@jjdizz1l/dizziee.power-profiles","repository":"JJDizz1L/dizziee.power-profiles","repositoryId":1315368371,"path":"","commit":"e790fd60a019903a1f2314d97fede36cd04d0a03","tree":"bd045d24011dd303e6b89464b575bd0ead616cc9","manifestSha256":"34f9de19c42bf962a8a1a966897482ed478a4c0438db35895e3635dfbf000a86","id":"dizziee.power-profiles","name":"Power Profiles","description":"Power profile switcher for desktop systems.","author":"Dizziee","license":"MIT","version":"1.0.0","kinds":["bar-widget"],"publisher":"","publishedAt":"2026-09-09T14:45:22.293671+00:00","repositoryCreatedAt":"2026-07-28T19:36:06Z","stars":0,"forks":0,"warnings":["Panel.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"dizziee.power-profiles","name":"Power Profiles","version":"1.0.0","author":"Dizziee","license":"MIT","description":"Power profile switcher for desktop systems.","kinds":["bar-widget"],"entryPoints":{"barWidget":"Panel.qml"},"barWidget":{"displayName":"Power Profiles","description":"Switch between power-saver, balanced, and performance profiles.","category":"System","allowMultiple":false}},"scan":{"validation":"passed","capabilities":{"network":[],"shell":[],"process":[{"file":"Panel.qml","line":66,"evidence":"Process {"},{"file":"Panel.qml","line":75,"evidence":"Process {"}],"filesystemRead":[],"filesystemWrite":[],"environment":[],"downloads":[],"downloadExecution":[],"obfuscation":[],"credentials":[]},"counts":{"network":0,"shell":0,"process":2,"filesystemRead":0,"filesystemWrite":0,"environment":0,"downloads":0,"downloadExecution":0,"obfuscation":0,"credentials":0},"qml":[{"file":"Panel.qml","warnings":215,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603800031","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"6b03579ff13660f45ab27a6a2536a4f229326905cb02a8cbb2fe362d40e79817","slug":"1cea4c7c7c380f801dfc"},{"package":"@nuu-maan/omarchy-widgets","repository":"Nuu-maan/omarchy-widgets","repositoryId":1359152458,"path":"","commit":"9265e49ed7bd52b87a86840044dda6462cb6002d","tree":"1da32d2e4d5f834839e8462dc550bad31734f431","manifestSha256":"6a85364322bf3b6c557249edb7959c48d56a5c2b2f2e14ce6b50f6c77d08292e","id":"anishfn.widgets","name":"Widgets","description":"Desktop widgets that sit on your wallpaper and take their colors from your Omarchy theme. Choose which ones are on screen from the bar.","author":"anishfn","license":"MIT","version":"0.2.0","kinds":["panel","bar-widget","service"],"publisher":"Nuu-maan","publishedAt":"2026-09-09T14:45:07.233925+00:00","repositoryCreatedAt":"2026-09-06T13:09:38Z","stars":0,"forks":0,"warnings":["Service.qml: process execution, privilege escalation, or network access; inspect source"],"status":"unverified","issue":"https://github.com/Nuu-maan/omarchy-plugins/issues/0","releaseState":[],"manifest":{"schemaVersion":1,"id":"anishfn.widgets","name":"Widgets","version":"0.2.0","author":"anishfn","license":"MIT","description":"Desktop widgets that sit on your wallpaper and take their colors from your Omarchy theme. Choose which ones are on screen from the bar.","repository":"https://github.com/anishfn/omarchy-widgets","keywords":["widgets","desktop","clock","wallpaper","quickshell"],"kinds":["panel","bar-widget","service"],"keepLoaded":true,"entryPoints":{"panel":"Surface.qml","barWidget":"BarWidget.qml","service":"Service.qml"},"barWidget":{"displayName":"Widgets","description":"Choose which desktop widgets are on screen.","category":"Desktop","allowMultiple":false,"defaultSection":"right","defaults":{"showCount":false},"schema":[{"key":"showCount","type":"boolean","label":"Show how many widgets are on","defaultValue":false}]}},"scan":{"validation":"passed","capabilities":{"network":[{"file":"Model.js","line":1774,"evidence":"if (isSafeRepo(candidates[i])) return \"https://github.com/\" + candidates[i]"},{"file":"Service.qml","line":387,"evidence":"\"https://wttr.in/\" + query + \"?format=j1\"]"},{"file":"Service.qml","line":470,"evidence":"\"https://github.com/users/\" + login + \"/contributions\"]"},{"file":"Service.qml","line":562,"evidence":"\"https://api.github.com/repos/\" + name]"},{"file":"Service.qml","line":604,"evidence":"\"https://api.github.com/search/issues?per_page=1&q=repo:\""},{"file":"install","line":31,"evidence":"#   curl -fsSL https://raw.githubusercontent.com/anishfn/omarchy-widgets/main/install | bash -s -- --yes"},{"file":"install","line":39,"evidence":"URL=\"https://github.com/anishfn/omarchy-widgets.git\""},{"file":"install","line":48,"evidence":"\"palccod.omate|https://github.com/Palccod/Omate.git|the Omate card|the desktop pet's switch, its skins, and its dials\""},{"file":"manifest.json","line":9,"evidence":"\"repository\": \"https://github.com/anishfn/omarchy-widgets\","},{"file":"tests/model.test.js","line":1523,"evidence":"\"https://github.com/Nuu-maan/Filly-Discord-Token-Filler\")"},{"file":"tests/model.test.js","line":1526,"evidence":"assert.equal(Model.repoUrl(null, \"cli/cli\"), \"https://github.com/cli/cli\")"},{"file":"tests/model.test.js","line":1547,"evidence":"\"https://github.com/cli/cli\")"}],"shell":[{"file":"Editor.qml","line":24,"evidence":"property var shell: null"},{"file":"Editor.qml","line":364,"evidence":"shell: root.shell"},{"file":"Editor.qml","line":845,"evidence":"shell: root.shell"},{"file":"Service.qml","line":16,"evidence":"property var shell: null"},{"file":"Service.qml","line":236,"evidence":"// and it is cheap: one short-lived bash for every zone in the config,"},{"file":"Service.qml","line":261,"evidence":"zoneProc.command = [\"/usr/bin/timeout\", \"-k\", \"2\", \"5\", \"/usr/bin/bash\", \"-c\", service.zoneScript, \"--\"].concat(zones)"},{"file":"Surface.qml","line":25,"evidence":"property var shell: null"},{"file":"Surface.qml","line":171,"evidence":"shell: root.shell"},{"file":"Surface.qml","line":188,"evidence":"item.shell = root.shell"},{"file":"WidgetInstance.qml","line":20,"evidence":"property var shell: null"},{"file":"WidgetInstance.qml","line":53,"evidence":"if (\"shell\" in item) item.shell = root.shell"},{"file":"dev/preview","line":1,"evidence":"#!/bin/bash"}],"process":[{"file":"Model.js","line":1980,"evidence":"while ((match = pattern.exec(html)) !== null) {"},{"file":"Model.js","line":2225,"evidence":"// should not have to wait for a subprocess to answer."},{"file":"Model.js","line":2403,"evidence":"var m = /^([+-])(\\d{2})(\\d{2})(\\d{2})?$/.exec(String(value || \"\").replace(/^\\s+|\\s+$/g, \"\"))"},{"file":"Model.js","line":2417,"evidence":"var m = /^(\\d{4})(\\d{2})(\\d{2})(?:T(\\d{2})(\\d{2})(\\d{2})(Z)?)?$/.exec(s)"},{"file":"Model.js","line":2456,"evidence":"var weeks = /^P(\\d+)W$/.exec(s)"},{"file":"Model.js","line":2458,"evidence":"var m = /^P(?:(\\d+)D)?(?:T(?:(\\d+)H)?(?:(\\d+)M)?(?:(\\d+)S)?)?$/.exec(s)"},{"file":"Model.js","line":2514,"evidence":"var m = /^([+-]?\\d{1,2})?(SU|MO|TU|WE|TH|FR|SA)$/.exec(days[d])"},{"file":"Model.js","line":2691,"evidence":"// zoneinfo lookup the shell would have to run a subprocess for."},{"file":"Model.js","line":2857,"evidence":"// from the network being turned into objects inside the process that draws"},{"file":"Model.js","line":3167,"evidence":"var todoTxt = /^x\\s+(?:\\d{4}-\\d{2}-\\d{2}\\s+)?(.*)$/.exec(rest)"},{"file":"Model.js","line":3172,"evidence":"var box = /^\\[([ xX\\u00d7~-])\\]\\s*(.*)$/.exec(rest)"},{"file":"Model.js","line":3180,"evidence":"var bang = /^!+\\s*(.*)$/.exec(rest)"}],"filesystemRead":[{"file":"Service.qml","line":217,"evidence":"FileView {"},{"file":"Service.qml","line":224,"evidence":"// Absent on first run. FileView reports that as a failure rather than as"},{"file":"Service.qml","line":356,"evidence":"FileView {"},{"file":"Service.qml","line":825,"evidence":"delegate: FileView {"},{"file":"dev/preview","line":45,"evidence":"cat > \"$ROOT/shell.qml\" <<EOF"},{"file":"install","line":242,"evidence":"cat <<'NEXT'"}],"filesystemWrite":[{"file":"Inspector.qml","line":9,"evidence":"// then Duplicate and Remove, then whatever its schema asked for, all reading"},{"file":"Inspector.qml","line":97,"evidence":"// Duplicate and Remove sit up here with the name rather than under the"},{"file":"Inspector.qml","line":99,"evidence":"// be told, and a Remove at the bottom of a list of fields is a Remove"},{"file":"Inspector.qml","line":180,"evidence":"text: \"Remove\""},{"file":"Service.qml","line":208,"evidence":"configFile.setText(text)"},{"file":"Service.qml","line":804,"evidence":"view.setText(next)"},{"file":"Service.qml","line":1100,"evidence":"function remove(id: string): string {"},{"file":"dev/preview","line":40,"evidence":"rm -rf \"$ROOT\""},{"file":"dev/preview","line":41,"evidence":"mkdir -p \"$ROOT\""},{"file":"dev/preview","line":85,"evidence":"trap 'rm -rf \"$ROOT\"' EXIT"},{"file":"tests/model.test.js","line":410,"evidence":"for (const bad of [\"../../etc/passwd\", \"Asia/Kolkata; rm -rf ~\", \"$(id)\", \"/etc/localtime\"]) {"},{"file":"tests/model.test.js","line":2104,"evidence":"for (const bad of [\"\", \"/etc/passwd\", \"../../etc/passwd\", \"Asia/../..\", \"Asia/Kolkata; rm -rf ~\","}],"environment":[{"file":"Service.qml","line":18,"evidence":"property string omarchyPath: Quickshell.env(\"OMARCHY_PATH\")"},{"file":"Service.qml","line":20,"evidence":"readonly property string home: Quickshell.env(\"HOME\")"},{"file":"Service.qml","line":246,"evidence":"'  if [ -f \"/usr/share/zoneinfo/$z\" ]; then\\n' +"},{"file":"Service.qml","line":247,"evidence":"'    printf \\'%s\\\\t%s\\\\n\\' \"$z\" \"$(TZ=\":/usr/share/zoneinfo/$z\" date +%z)\"\\n' +"},{"file":"Service.qml","line":249,"evidence":"'    printf \\'%s\\\\t\\\\n\\' \"$z\"\\n' +"},{"file":"dev/preview","line":29,"evidence":"ROOT=${XDG_RUNTIME_DIR:-/tmp}/omarchy-widgets-preview"},{"file":"dev/preview","line":32,"evidence":"[ -d \"$SHELL_DIR/Commons\" ] || { echo \"Omarchy shell not found at $SHELL_DIR\" >&2; exit 1; }"},{"file":"dev/preview","line":40,"evidence":"rm -rf \"$ROOT\""},{"file":"dev/preview","line":41,"evidence":"mkdir -p \"$ROOT\""},{"file":"dev/preview","line":42,"evidence":"ln -s \"$SHELL_DIR/Commons\" \"$ROOT/Commons\""},{"file":"dev/preview","line":43,"evidence":"ln -s \"$SHELL_DIR/Ui\" \"$ROOT/Ui\""},{"file":"dev/preview","line":45,"evidence":"cat > \"$ROOT/shell.qml\" <<EOF"}],"downloads":[{"file":"Model.js","line":2313,"evidence":"// curl, so it is matched against a pattern rather than escaped -- an"},{"file":"Service.qml","line":383,"evidence":"// and the whole thing is passed as one argv entry to curl."},{"file":"Service.qml","line":386,"evidence":"\"/usr/bin/curl\", \"-fsS\", \"--max-time\", \"15\","},{"file":"Service.qml","line":469,"evidence":"\"/usr/bin/curl\", \"-fsS\", \"--max-time\", \"20\","},{"file":"Service.qml","line":560,"evidence":"\"/usr/bin/curl\", \"-fsSL\", \"--max-time\", \"15\","},{"file":"Service.qml","line":602,"evidence":"\"/usr/bin/curl\", \"-fsSL\", \"--max-time\", \"20\","},{"file":"Service.qml","line":697,"evidence":"// about to be handed to curl as a URL."},{"file":"Service.qml","line":703,"evidence":"\"/usr/bin/curl\", \"-fsSL\", \"--max-time\", \"30\","},{"file":"install","line":21,"evidence":"#     Missing curl is not an install failure; it is four cards that never"},{"file":"install","line":31,"evidence":"#   curl -fsSL https://raw.githubusercontent.com/anishfn/omarchy-widgets/main/install | bash -s -- --yes"},{"file":"install","line":124,"evidence":"\"/usr/bin/curl|weather, the contribution graph, repo pulse and the calendar fetch with it\" \\"},{"file":"tests/model.test.js","line":1982,"evidence":"test(\"a report also parses from the raw string curl hands back\", () => {"}],"downloadExecution":[{"file":"install","line":31,"evidence":"#   curl -fsSL https://raw.githubusercontent.com/anishfn/omarchy-widgets/main/install | bash -s -- --yes"}],"obfuscation":[],"credentials":[{"file":"Model.js","line":249,"evidence":"description: \"What is next, from your Google Calendar's secret iCal address.\","},{"file":"Model.js","line":256,"evidence":"// decoration holding an OAuth token. One GET to Google's own host, no"},{"file":"Model.js","line":265,"evidence":"label: \"Secret iCal address\","},{"file":"Model.js","line":830,"evidence":"// non-empty text setting\" -- would put a calendar's secret address in the"},{"file":"Model.js","line":1934,"evidence":"// /users/<login>/contributions and needs no token. That is the whole source:"},{"file":"Model.js","line":2240,"evidence":"function parseOffsetToken(token) {"},{"file":"Model.js","line":2241,"evidence":"var m = String(token || \"\").match(/^([+-])(\\d{2})(\\d{2})$/)"},{"file":"Model.js","line":2291,"evidence":"// Google Calendar publishes every calendar as an iCalendar file at a secret"},{"file":"Model.js","line":2292,"evidence":"// address: Settings -> Integrate calendar -> \"Secret address in iCal format\"."},{"file":"Model.js","line":2294,"evidence":"// refresh token for a wallpaper decoration to hold, and no third party in the"},{"file":"Model.js","line":2312,"evidence":"// The secret address, to Google's own shape. This becomes a URL handed to"},{"file":"Service.qml","line":422,"evidence":"// /users/<login>/contributions and needs no token. So this goes to"}]},"counts":{"network":26,"shell":19,"process":35,"filesystemRead":6,"filesystemWrite":12,"environment":162,"downloads":12,"downloadExecution":1,"obfuscation":0,"credentials":19},"qml":[{"file":"BarWidget.qml","warnings":412,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Editor.qml","warnings":1019,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Field.qml","warnings":70,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Inspector.qml","warnings":425,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"PickerField.qml","warnings":391,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Service.qml","warnings":376,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"SettingField.qml","warnings":304,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"Surface.qml","warnings":123,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetCard.qml","warnings":43,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetInstance.qml","warnings":45,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetRow.qml","warnings":170,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"WidgetsMark.qml","warnings":72,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Calendar.qml","warnings":477,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Clock.qml","warnings":187,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Github.qml","warnings":287,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Music.qml","warnings":760,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/MusicButton.qml","warnings":96,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Omate.qml","warnings":935,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Photo.qml","warnings":272,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/RepoPulse.qml","warnings":278,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/TickRing.qml","warnings":55,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Todos.qml","warnings":557,"note":"Static parser only; Omarchy imports may be unavailable."},{"file":"widgets/Weather.qml","warnings":276,"note":"Static parser only; Omarchy imports may be unavailable."}],"method":"Static pattern analysis and qmllint parsing. Up to 12 evidence samples per capability; all matching lines counted. Absence of a match does not establish absence of a capability."},"receipt":"https://github.com/Nuu-maan/omarchy-plugins/issues/11#issuecomment-5603799330","reviews":[],"reports":[],"verification":null,"submissionStatus":"PENDING REVIEW","capabilityChanges":[],"trustEvents":[],"scanDigest":"0852aed72f53a0c18fa794dac551550e487048120329d5ea2d3473b498cdf428","slug":"355109434baeed25d3a0"}]}