Omarchy Plugin Audit

Static + AI audit for Omarchy plugins. Static is deterministic (regex, no hallucinations); AI is contextual (refines severity, e.g., Qt.resolvedUrl("mx-ctl") → executable). Overview shows both — AI refines, static is fallback.

Plugin Last commit Scanned Static risk AI risk Score
M4Marvin-omarchy-plugin-opencode-go 3594b52 8/25/2026, 11:54:18 AM medium low 13 View →
NachoRodriguezM-omarchy-google-calendar-clock 14cf448 8/25/2026, 12:18:22 PM high low 19 View →
gastonmira-omarchy-mx-master 6d9184a 8/25/2026, 11:42:49 AM low low 4 View →
jankeesvw-omarchy-downloads 3a48310 8/25/2026, 11:43:25 AM medium safe 8 View →
niraletter-vitals 1dcdbf7 8/25/2026, 11:55:14 AM low low 2 View →
Static risk is deterministic; AI risk is contextual and may be higher (e.g., mx-ctl executable) or lower (expected imports). When AI exists, the plugin page shows both and uses AI for the hero badge, but keeps static visible for comparison.

How to trust?

Trust static for reproducibility, AI for context. If AI says high and static says low (like mx-ctl resolved then executed), review the AI Reasoning and Related Code on the plugin page — it should cite the exact line where ctl is used in statusProc.command. If no AI yet, the “View report” page will prompt to re-run with --with-llm.

Tracked Plugins (state.json)

jankeesvw-omarchy-downloads 3a48310 (medium, score 8) https://github.com/jankeesvw/omarchy-downloads
gastonmira-omarchy-mx-master 6d9184a (low, score 4) https://github.com/gastonmira/omarchy-mx-master
M4Marvin-omarchy-plugin-opencode-go 3594b52 (medium, score 13) https://github.com/M4Marvin/omarchy-plugin-opencode-go
niraletter-vitals 1dcdbf7 (low, score 2) https://github.com/niraletter/vitals
NachoRodriguezM-omarchy-google-calendar-clock 14cf448 (high, score 19) https://github.com/NachoRodriguezM/omarchy-google-calendar-clock