• Sources: One Happy Fellow, HN 49447682
  • Summary: The post argues Omarchy ships shell scripts written with model assistance that handle untrusted input without escaping it. It cites command injection through a video title and arbitrary command execution reached from notification content. The critique identifies no version boundary, so the affected Omarchy releases are not stated.
  • Why it matters: The named issue classes are ordinary command injection in code paths handling untrusted strings, which is a concrete review question for any project generating shell glue with a model.

send feedback on this story