Omahub
← All plugins
C

Framework Microphone Privacy

by chalkers

Framework hardware microphone privacy and capture indicator

Security review

Potentially dangerous behavior detected · 10 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
4c5674c
Scanned
1 month ago
  • high persistence uninstall.sh:5

    Registers scheduled or boot-time system tasks.

    systemctl disable --now framework-privacy-cache.service || true
  • high persistence setup.sh:21

    Registers scheduled or boot-time system tasks.

    systemctl enable --now framework-privacy-cache.service
  • Bundles a systemd unit file.

    [Unit]
  • medium sudo uninstall.sh:5

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl disable --now framework-privacy-cache.service || true
  • medium sudo uninstall.sh:6

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f \
  • medium sudo uninstall.sh:9

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl daemon-reload
  • medium sudo setup.sh:14

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -Dm755 \
  • medium sudo setup.sh:17

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -Dm644 \
  • medium sudo setup.sh:20

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl daemon-reload
  • medium sudo setup.sh:21

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl enable --now framework-privacy-cache.service

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4c5674c
Reviewed
1 month ago

The plugin is a transparent bar widget that reads Framework hardware microphone state via a hardened systemd service and PipeWire. The deterministic scan flagged sudo and systemd persistence, but these are necessary and clearly documented for accessing the root-only Framework EC device. No obfuscation, credential theft, or destructive behavior was found.

  • Installs and enables a persistent systemd service with root privileges; users should review setup.sh and the service unit before running, as the README advises.
  • setup.sh runs `omarchy pkg add framework-system`, which installs an external package; the package source should be trusted.
  • The service runs framework_tool every second and writes to /run, which is a minor but reasonable resource use.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/chalkers/omarchy-framework-microphone --enable
Hardware #bar #quickshell #system

Framework Microphone Privacy for Omarchy

An Omarchy bar plugin for the physical microphone privacy switch on Framework laptops.

The icon reports both hardware privacy and active PipeWire capture:

  • Blue microphone: The physical switch is on. The microphone is ready and idle.
  • Green microphone: An application is actively capturing audio.
  • Red crossed microphone: The physical switch is off. The red slider is visible.
  • Amber warning: The hardware state is unavailable or stale.

Move the pointer over the icon to see the hardware state and active applications. Click the icon to refresh the state.

Requirements

  • Omarchy 4
  • A Framework laptop supported by framework_tool --privacy
  • PipeWire

The Framework EC device is root-only. A small, hardened system service calls the official framework_tool command and writes a read-only state cache under /run. The shell plugin reads that cache without root access.

Install

Add the plugin:

omarchy plugin add https://github.com/chalkers/omarchy-framework-microphone.git

Install and start the hardware cache service:

~/.config/omarchy/plugins/chalkers.framework-microphone/setup.sh

Enable the bar widget:

omarchy plugin enable chalkers.framework-microphone

The widget starts in the center section. Move it when necessary:

omarchy bar move chalkers.framework-microphone --section right

The setup script installs the official Arch framework-system package. It also uses sudo to install and enable framework-privacy-cache.service. Review setup.sh and the files under system/ before you run the script.

Remove

Remove the root cache service first:

~/.config/omarchy/plugins/chalkers.framework-microphone/uninstall.sh

Then remove the plugin:

omarchy plugin remove chalkers.framework-microphone

Validate

omarchy plugin validate .
./status.py --self-test
./system/framework-privacy-cache --self-test
systemctl status framework-privacy-cache.service --no-pager
python -m json.tool /run/framework-privacy-waybar/state.json

How it works

  1. framework-privacy-cache.service runs /usr/bin/framework_tool --privacy once per second.
  2. The service writes the microphone state and timestamp to /run/framework-privacy-waybar/state.json.
  3. status.py reads the cache and checks PipeWire for active audio capture streams.
  4. BarWidget.qml refreshes the icon and tooltip every two seconds.

The service uses systemd hardening options. It can only write to its runtime cache directory.

License

MIT