Omahub
← All plugins
B

Cast indicator

by Basem Aljedai

Cast your screen to an Apple TV or a Chromecast from the bar: mirror or extend, with a live indicator

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
4c9a149
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4c9a149
Reviewed
1 month ago

This is a straightforward QML bar widget that only invokes the external `castr` binary with literal, non-shell arguments: status and listing commands are read-only, and start/stop run only after an explicit user click. The deterministic scan found nothing, and the sampled source contains no obfuscation, persistence, credential theft, or destructive install behavior. The main residual risk is inherent to the feature itself: receivers come from unauthenticated mDNS advertisements, so a malicious LAN device could appear in the list and receive the user's screen if clicked.

  • The widget deliberately runs `castr start` and `castr stop` on user click; because `castr` runs unsandboxed inside the shell, users must also trust the externally installed `castr` binary and its backends.
  • Receiver discovery relies on unauthenticated mDNS; a malicious receiver can advertise itself as a TV and receive a cast if the user clicks it. This is the plugin's intended function, not hidden malicious behavior.
  • The sampled `Widget.qml` was truncated before the remaining `Process` definitions; the visible code is clean and uses process argument arrays, but a final human check of the rest of the file is prudent.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/mrCode/castr-indicator --enable
System #Hyprland #bar #media

Cast indicator

A bar widget for Omarchy that casts your screen to an Apple TV or a Chromecast — mirror it, or extend onto an Apple TV as a second desktop — and shows what is casting.

The cast panel

Click the icon for a panel listing the receivers on your network. Pick a mode once, click a receiver, and it casts. Televisions sort above laptops, because a colleague's MacBook answering AirPlay is noise. Right-click the icon to stop.

Extend is AirPlay only. A Chromecast row says "Mirror only" when Extend is selected, and mirrors — rather than letting a click start a cast that cannot work.

Requires castr

The widget is a front end for castr, which does the actual work. Install it first:

yay -S castr

Without it the widget says so and tells you this command, rather than sitting there looking idle.

castr then needs whichever backend you cast with — doubletake-git for an Apple TV, GStreamer for a Chromecast — and neither is involved in the other's cast. castr's Installing section has both, and castr names the missing one rather than failing obscurely.

If you run a firewall, it has to let the receiver reach your machine — neither protocol is one-way:

port why
UDP 5353 mDNS, so receivers are discovered at all
TCP + UDP 60000-60010 the range an Apple TV connects into to fetch the stream
TCP 8010 where a Chromecast fetches the stream from

A Chromecast also needs GStreamer, which castr's package lists as optional dependencies — the Chromecast capture is castr's own code rather than doubletake's.

Without those, discovery finds nothing or a cast starts and then stalls. castr's README carries the exact ufw commands: Installing.

Install

omarchy plugin add https://github.com/mrCode/castr-indicator.git --enable --yes

Remove

omarchy plugin remove castr.indicator

That takes the widget out of the bar and deletes its checkout. It leaves castr itself alone; uninstall that separately with your package manager if you want it gone too. The widget stores nothing of its own — everything it shows comes from asking castr — so there is no leftover state to clean up.

What it shows

  • Idle — a dim icon; the panel lists what it can cast to
  • Connecting — a screen-share prompt may be waiting for you; answer it
  • Streaming — the receiver and mode, with a stop button
  • Failed — what went wrong, in the receiver's own words where there are any

The icon stays visible whether or not you are casting. A control you cannot see is a control you cannot find, and this one is how you stop.

Mirror and extend

Mirror sends the screen you pick at the share prompt. Your panel keeps its own resolution and refresh rate — castr does not touch it.

Extend gives you a second desktop. When the share prompt appears, pick the output named castr, not your own screen; the portal remembers that choice. If you pick wrong, castr reset-share extend asks again without making you re-pair with the television.

How it talks to castr

Three commands, all of them read-only until you click something:

command when
castr bar polled every 2s; never starts a daemon
castr list --json only while the panel is open
castr status --json only while the panel is open

Polling castr bar cannot start or keep alive a background daemon, so an idle machine stays idle.

Licence

MIT. Plugins run unsandboxed inside omarchy-shell; the source here is one QML file, and it is worth the two minutes to read before you enable it.