Omahub
← All plugins
C

Focus Modes

by Casper Bottelet

iOS-style Focus modes for your desktop. One toggle applies a whole context — notifications off, distracting sites blocked, noisy apps quarantined, theme switch, keep-awake — and gives every bit of it back when the mode ends.

Security review

Review recommended · 10 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
77fe5b8
Scanned
4 days ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -o root -g root -m 755 helpers/focus-modes-hosts /usr/local/bin/focus-modes-hosts
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -o root -g root -m 755 ... /usr/local/bin/focus-modes-hosts)"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 644 49-focus-modes.rules.example /etc/polkit-1/rules.d/49-focus-modes.rules
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm /etc/polkit-1/rules.d/49-focus-modes.rules
  • medium sudo Panel.qml:302

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install the helper to " + Model.systemHelperPath())
  • Docs sudo README.md:54

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -o root -g root -m 755 \
  • Docs sudo README.md:81

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -m 644 helpers/49-focus-modes.rules.example /etc/polkit-1/rules.d/49-focus-modes.rules
  • Docs sudo README.md:128

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo focus-modes-hosts --clear` — or delete the block between
  • Docs sudo README.md:132

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm /usr/local/bin/focus-modes-hosts`
  • Docs sudo README.md:134

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm /etc/polkit-1/rules.d/49-focus-modes.rules`

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
77fe5b8
Reviewed
3 days ago

The plugin is well-engineered with a clear security model: it confines privileged operations to a single audited helper invoked via pkexec, validates all inputs, and documents its behavior thoroughly. The deterministic scan flagged sudo usage, but these are documented one-time setup steps and the helper itself enforces root ownership and validation, mitigating the risk. No obfuscation, hidden persistence, or credential theft was found.

  • The plugin requires a one-time manual sudo install of a helper to /usr/local/bin, which is a privilege escalation point; however, the helper is audited, fail-closed, and only modifies a marker block in /etc/hosts.
  • The optional polkit rule allows password-less execution of the helper, which could be abused by a local process to modify the hosts file without prompting; this is clearly documented as a trade-off.
  • User-defined hooks run arbitrary shell commands, but they are user-configured and bounded by a timeout, which is acceptable for a productivity plugin.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Bottelet/omarchy-focus-modes --enable
Productivity #bar #quickshell #system

Focus Modes

One toggle, whole context. Work mode blocks the noise; Off mode gives it back. Like Focus on your phone — but for your actual computer.

A mode is a named profile (Deep Focus, Work, Meeting, your own) that applies a set of actions atomically when it starts and reverts exactly what it applied when it ends — by click, by timer, or after a crash:

  • 🔕 Silence notifications — the shell's own do-not-disturb
  • 🌐 Block distracting sites system-wide (/etc/hosts, no browser extension)
  • 📦 Quarantine distracting apps — Discord & friends slide to a hidden workspace and come back to the exact workspace they were on; apps opened mid-mode get caught too
  • 🎨 Switch theme — visual context for "I'm working now"
  • ☕ Keep the screen awake (Meeting mode's best friend)
  • 🔇 Mute audio
  • ⚙️ Run your own hooks on enter/exit — Slack status, smart lights, anything

A timer (25/50/90 min or custom) shows a countdown in the bar; when it expires everything is restored and you get a notification with the session length. A small "this week" view totals your focus time per mode.

Fully local. No network access, no accounts, no telemetry — your focus habits never leave the machine.

Focus Modes

Install

omarchy plugin add https://github.com/Bottelet/omarchy-focus-modes --enable

The bar chip shows an outline icon when off, and the mode's icon + name + remaining time while a mode runs. Click it for the mode cards; keyboard-first (←→ select, ↵ start, 1/2/3 = 25/50/90 min timer, e edit, n new mode, Esc close).

Site blocking and authorization (one-time setup)

Blocking sites edits /etc/hosts, which needs root. The plugin does that through a tiny audited helper which must be installed once to a root-owned path — pkexec is never pointed at anything inside the (user-writable) plugin directory, because a script you can rewrite is a script any process running as you can rewrite between the prompt and the execution:

# review it first — ~150 lines of bash
less ~/.config/omarchy/plugins/bottelet.focus-modes/helpers/focus-modes-hosts

sudo install -o root -g root -m 755 \
  ~/.config/omarchy/plugins/bottelet.focus-modes/helpers/focus-modes-hosts \
  /usr/local/bin/focus-modes-hosts

The plugin only ever invokes /usr/local/bin/focus-modes-hosts, and the helper itself refuses to do privileged work from any path that is not root-owned and non-user-writable, so a copy that never went through sudo install is inert. Without the setup, modes still work; site blocking reports "needs one-time setup" and is skipped. Each block/unblock shows a polkit authorization prompt; cancel it and the mode still applies its other actions.

Plugin updates never touch the installed helper. If a future release changes helpers/focus-modes-hosts, re-run the sudo install line (the README changelog will say so).

localhost, *.local, *.localhost and this machine's own hostname can never be blocked — local development keeps working no matter what is on the block list. Already-open tabs keep their existing connections; new lookups die. See SECURITY.md for the full threat model.

Optional: password-less toggling. If the per-toggle prompt annoys you, install the provided polkit rule (edit the username first). It authorizes only the root-owned installed helper, never the plugin checkout:

sudo install -m 644 helpers/49-focus-modes.rules.example /etc/polkit-1/rules.d/49-focus-modes.rules
sudoedit /etc/polkit-1/rules.d/49-focus-modes.rules   # set your username

Keybinding

Bind a mode to a key in your Hyprland bindings:

o.bind("SUPER + SHIFT + F", "Deep Focus",
       "omarchy-shell bottelet.focus-modes activate deep-focus")

CLI surface: activate <mode-id>, off, status, toggle.

Editing modes

Click ✎ on a card (or press e). Everything is per-mode: the action toggles, the site list, app classes (with a "pick from open windows" row), theme, default timer, hooks. Modes live in ~/.local/state/omarchy-focus-modes/modes.json if you prefer editing JSON.

Settings

  • Show mode name — chip shows icon only when off
  • Scroll cycles modes — wheel on the chip switches modes (default off)
  • Notify when a timer ends (default on)

Good companions, known overlaps

Curtain / Share Cloak own screen-share hiding — a Meeting mode composes around them, it doesn't replace them. If you run single-purpose toggles like Caffeine or Snooze, they keep working; last writer wins on the shared resource (idle inhibit, hosts file) and this plugin only ever touches its own hosts marker block.

Remove

omarchy plugin remove bottelet.focus-modes

Removal checklist — everything the plugin ever touched:

  1. End the active mode first (click Off) so DND, theme, mute, windows and the hosts block are reverted by the engine itself.
  2. If you removed the plugin mid-mode, clean the hosts block manually: sudo focus-modes-hosts --clear — or delete the block between # >>> bottelet.focus-modes >>> and # <<< bottelet.focus-modes <<< in /etc/hosts by hand. Verify with grep focus-modes /etc/hosts (should print nothing).
  3. Remove the installed helper: sudo rm /usr/local/bin/focus-modes-hosts
  4. If you installed the optional polkit rule: sudo rm /etc/polkit-1/rules.d/49-focus-modes.rules
  5. State (modes, session log): rm -rf ~/.local/state/omarchy-focus-modes

Dependencies

Everything is on a stock Omarchy install: bash, pkexec (polkit), hyprctl, wpctl (PipeWire), systemd-inhibit, notify-send, resolvectl (optional, DNS cache flush).

License

MIT — see LICENSE.