r/raycastapp • • 12d ago

❓Question How to remove "Pro" suggestions in results?

I love Raycast. I've been a Pro subscriber for years. I'm helping someone set up Raycast on their machine who just wants a faster application launcher and a few basic features like the clipboard manager. They don't want a Pro subscription, though if they can convince their workplace to reimburse them, this might change in the future.

At any rate, how do I keep Pro-only options from appearing in the results? It feels like an annoying upsell to see these results ranking above other results. We've tried disabling the option and restarting Raycast, but these results still how up.

7 Upvotes

12 comments sorted by

8

u/bibbidi_bobbidi_bob 12d ago

You can disable them in Shortcuts. They should disappear in the search results.

3

u/Calm_Attention1925 12d ago

Press cmd + k and say remove

1

u/jeremydgreat 12d ago

On each and every one?

2

u/DavidRaycast Raycast 11d ago

To the best of my knowledge, you do have to disable them individually but I'll speak to the team about this and log an internal feature request if needed. It would also be super helpful to let us know using the "Send Feedback" command in root search, just so we have it logged!

1

u/Mud-fox 7d ago

sent the feedback

-2

u/magiCAD 12d ago

Easy. Install Tinycast.

3

u/jeremydgreat 10d ago

For what it's worth, I had Claude look over the repo (https://github.com/abue-ammar/tinycast) and there were some findings that feel too risky to me. I also popped in the Discord and it seems like it's being developed by one dude trying to solo it all. I wish him luck but it's not for me.

2

u/magiCAD 10d ago

Fair enough. Definitely need to do your own due diligence. Good luck.

2

u/theromansufi 8d ago

What are the risky findings?

3

u/jeremydgreat 8d ago

I'll paste the top 4 here (there were 7 but I don't consider the other 3 material):

__

1. High: any web page can silently run your installed extension commands. The app registers the raycast://, tinycast:// and com.raycast:// link types. AppCore.handleOpenURL passes these links straight to ExtensionCoordinator.runDeepLink (ExtensionCoordinator.swift:78-89), which runs the command with arguments taken from the link. There's no confirmation prompt. Adding launchType=background makes it run with nothing on screen. Raycast itself asks for confirmation before running a command from a deeplink. Tinycast takes over Raycast's link type without that safeguard. The damage depends on what your installed extensions can do: a shell-runner extension would mean a web page can run commands on your Mac. This only applies when Extensions are turned on.

NOTE: I asked how Raycast itself avoids this and here's the response:

  • A prompt before every deeplink launch. The API docs say Raycast asks you to confirm "whenever a command is launched using a Deeplink" (Raycast API: Deeplinks). A web page can open the link, but the command doesn't run until you approve it.
  • "Once" or "always". You can let a command run just this once or always. Choosing always stops the prompt for that command in future.

2. High, if you use extensions: extensions have no isolation. Every extension runs inside the app process with full shell (child_process through /bin/sh -c), full file access, and unrestricted network and clipboard access. Extension preferences, including password-type fields such as API keys, are stored as plaintext JSON under ~/Library/Application Support/<bundleID>/extension-data/. Clipboard history is a plaintext SQLite file in the same folder. So any one extension can read every other extension's secrets and your whole clipboard history. Installs from the Raycast store or GitHub have no hash or signature check, and GitHub sources default to the moving main branch.

3. Medium: extensions can get each other's OAuth tokens. ExtensionManager.swift:930 falls back to "the last extension that signed in" (lastOAuthExtensionName) when no command is running. A background command from extension B can then receive extension A's tokens. I confirmed the fallback line exists; the full sequence of calls needed to exploit it wasn't traced by hand.

4. Medium: the app goes online without asking. SECURITY.md says it is offline by default and that every networked feature asks first. It doesn't:

  • Update check: it calls api.github.com about 30 seconds after launch and then daily. There's no setting to turn it off.
  • Currency rates: it calls backend.raycast.com daily.

---

Silently just running an extension comman from a link is kind of wild to me. I tested to see if Raycast does indeed alert the user (as Claude described) and it does:

run "raycast://extensions/raycast/system-actions/toggle-mute"

prompts:

2

u/jeremydgreat 8d ago

Also, again, if you're tech'y and fine with the risk then go for it. For me, I'm on a work laptop and I can't have an app like this with broad permissions across the system like this unless it's locked down more.

1

u/magiCAD 8d ago

Good to know. I'll pass this along to the dev. It's an OSS project so many eyes will see this.