Omahub
← All plugins
D

Aura

by Donovan Burbano

ASUS Aura keyboard lighting: firmware effects, theme sync, and an audio-reactive music mode.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
8470829
Scanned
2 weeks ago
  • Dynamic code execution via eval().

    eval(fs.readFileSync(path.join(__dirname, '..', 'Aura.js'), 'utf8')
  • medium sudo AuraDevice.qml:7

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo needed -- asusd's polkit policy

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
8470829
Reviewed
2 weeks ago

The plugin controls ASUS Aura keyboard lighting over D-Bus via busctl and adds an audio-reactive mode that samples the default audio output; the code is straightforward and all commands are built as argv arrays with no shell interpolation. The deterministic scan's medium findings are false positives: the eval() is confined to a unit-test harness that loads the plugin's own Aura.js, and the sudo match is a comment explaining that sudo is not needed. No destructive, persistent, or credential-harvesting behavior was found.

  • The eval() in tests/aura_test.js only reads and evaluates the local Aura.js for unit testing; it is never executed by the plugin runtime.
  • The sudo match in AuraDevice.qml is a comment ('No sudo needed'), not a command; the plugin does not invoke sudo.
  • The plugin legitimately runs unsandboxed and talks to the system asusd service over D-Bus, which is expected for a hardware-control plugin but worth noting.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/DonovanSB/omarchy-aura --enable
Hardware #bar #quickshell #media
<p align="center"> <img src="assets/icon.svg" alt="" width="112" height="112"> </p> <h1 align="center">Aura</h1> <p align="center"> ASUS Aura keyboard lighting for the Omarchy shell. </p>

The firmware effects your device supports, an Omarchy theme colour source, and an audio-reactive music mode.

Adds a keyboard pill to the bar. Clicking it opens the control panel.

<p align="center"> <img src="preview.png" alt="The Aura panel: brightness, mode, peak and quiet colours, and smoothing" width="380"> </p>

Requirements

  • Omarchy 4 (Quattro)
  • asusctl installed and asusd running
  • An ASUS device exposing Aura over D-Bus

The plugin adds no system packages.

Install

omarchy plugin add https://github.com/DonovanSB/omarchy-aura.git --enable --yes

Without --yes the command is interactive and lets you review the code before enabling, which is worth doing: shell plugins run unsandboxed.

To place the pill somewhere specific:

omarchy bar move donovan.aura --section right

Remove

omarchy plugin remove donovan.aura

To keep it installed but off the bar, use omarchy plugin disable donovan.aura.

Using it

Control What it does
Brightness Off / Low / Med / High
Mode The firmware effects this device reports, plus Music
Colour Swatches, any hex, or the theme chip
Quiet colour Where music fades to between peaks

The panel also opens from omarchy-shell shell toggle donovan.aura '{}', so it can be bound to a key in ~/.config/hypr/bindings.lua or added to omarchy-menu.jsonc.

On the pill itself: right-click switches the lights off and back on at the level they were, and middle-click steps through the brightness levels.

Only the effects your firmware actually implements are listed. A different ASUS board will show a different set.

Theme colour

The first chip in the colour row follows the Omarchy theme. Themes may ship a keyboard.rgb; those that don't fall back to their accent colour. It is a colour source, not a mode, so it composes with every effect — including music, where the theme colour becomes the peak.

Picking any other swatch turns it off and restores your manual colour.

Music mode

There is no music effect in the firmware, so this one is software: it samples the default audio output (not a microphone) and drives the lighting between your quiet and peak colours.

One knob, Smoothing — how slowly the light falls back after a peak. Raise it if it flickers, lower it if it feels sluggish. Everything else auto-levels.

Turning brightness off stops it, and nothing is written to the keyboard while the lights are off.

Scope

Built and tested on a ROG Strix G513RC (Omarchy 4.0.0, asusctl 6.3.8, Quickshell 0.3.0). The code adapts to whatever the device reports, so other Aura hardware should work, but none has been tested. Reports welcome.

Development

Aura.js holds the pure logic and has no dependencies:

node tests/aura_test.js
omarchy plugin validate .

Saving any file under ~/.config/omarchy/plugins/ hot-reloads the plugin.

License

MIT