Omahub
← All plugins
E

Power Timings

by Eduard G. Castelló

Adjust screensaver, lock, and auto-suspend idle timeouts from the bar, plus quick lock/suspend actions.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
9b89cc2
Scanned
3 weeks ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:26

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/eddygarcas/omarchy-power-timings.git \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
9b89cc2
Reviewed
3 weeks ago

The deterministic scan's only finding is a git clone URL in the README install instructions, which is documentation and not part of the plugin's executable code. The plugin itself is a straightforward power-timings widget: it edits idle.* keys in shell.json via a carefully written atomic Python helper and runs systemctl suspend / omarchy-system-lock only for its stated purpose. No obfuscation, network access, persistence, or destructive behavior was found; the only minor issue is that the atomic writer creates shell.json with mode 0644 rather than preserving the original file's mode.

  • power_timings_ctl.py creates the replacement shell.json with mode 0644; if the original file had a stricter mode (e.g. 0600), the write would widen local read access.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/eddygarcas/omarchy-power-timings --enable
System #bar #power-management #system

Power Timings

An Omarchy shell plugin that adds a bar widget for controlling how long the system waits before the screensaver, the lock screen, and suspend kick in — plus quick "Lock now" / "Suspend now" actions.

Power Timings panel

Why

Omarchy's built-in idle service already reads idle.screensaver and idle.lock from ~/.config/omarchy/shell.json, but there's no UI to change them and no auto-suspend timeout at all. This plugin adds both: a popup with a slider for each of the three timeouts, and a background timer that suspends the machine after the configured idle period.

Install

omarchy plugin add https://github.com/eddygarcas/omarchy-power-timings.git --enable

Or manually:

git clone https://github.com/eddygarcas/omarchy-power-timings.git \
  ~/.config/omarchy/plugins/eduard.power-timings
omarchy-shell shell rescanPlugins
omarchy plugin enable eduard.power-timings

What it does

Click the bar icon to open the panel:

  • Manage power timings — a switch at the top. Turn it off to disable everything below and let the system's own idle defaults apply (screensaver and lock keep working as Omarchy ships them; auto-suspend is disabled).
  • Screensaver after / Lock after — sliders, marked at each preset stop, that write straight into idle.screensaver / idle.lock in ~/.config/omarchy/shell.json, the same keys the built-in idle service already reads.
  • Suspend after — a new idle.suspend timeout, also a marked slider ("Never" at the low end). A background service (Service.qml) watches for that much idle time and runs systemctl suspend. It respects the existing "Stay awake" indicator, so turning that on also pauses auto-suspend.
  • The three sliders always keep screensaver < lock < suspend ("Never" is exempt): dragging one past a neighbor pushes that neighbor forward to its own next preset instead of landing on an invalid order.
  • Lock now / Suspend now — run omarchy-system-lock / systemctl suspend directly, regardless of the switch above.

Session locking before any suspend (manual or automatic) is already handled by Omarchy's own omarchy-sleep-lock service, so this plugin never needs to lock the screen itself before suspending.

Known limitations

Changing idle.screensaver / idle.lock while the shell is already running doesn't reliably re-arm a countdown that's already in flight — in testing, a new short timeout sat for 90+ seconds with no effect until the shell was restarted, at which point it fired right on schedule. This is a property of Omarchy's built-in idle-notify plumbing that these sliders write into, not something this plugin controls. If releasing a slider doesn't seem to take effect immediately, run omarchy restart shell (or just wait through one natural idle → active cycle) to make it stick.

Remove

omarchy plugin remove eduard.power-timings

This deletes ~/.config/omarchy/plugins/eduard.power-timings/, removes the widget from your bar layout, and stops the background auto-suspend timer. It does not revert idle.screensaver / idle.lock / idle.suspend in shell.json — whatever values were last set stay in effect (the built-in idle service keeps reading idle.screensaver / idle.lock either way). Delete those keys by hand, or run omarchy refresh shell, if you want them back to Omarchy's defaults too.

Permissions & dependencies

  • Requires Python 3 on PATH — standard on any Omarchy install. No other runtime dependencies, and no network access at all.
  • Reads idle.* in ~/.config/omarchy/shell.json live through a Quickshell FileView (same file the built-in idle service already owns). Writes go through power_timings_ctl.py instead, never a direct path-based write: the script opens ~/.config/omarchy via an ancestor-nofollow, owner-checked directory descriptor (refuses if any component from $HOME down is a symlink, or if the directory isn't owned by you — but never chmods it, since it's shared with the rest of Omarchy and every other plugin), re-validates shell.json's identity immediately before committing (aborts rather than overwrite if it changed, appeared, or disappeared since it was read), and commits via a same-directory, exclusively-created temp file that's fsync'd and atomically renamed over the real name — safe even if shell.json currently is (or becomes) a symlink, since rename(2) replaces the destination without ever following it.
  • Reads ~/.local/state/omarchy/indicators/stay-awake (the same file the built-in "Stay awake" bar indicator manages) to pause auto-suspend.
  • Runs two commands, both already used by Omarchy's own system menu: omarchy-system-lock (Lock now) and systemctl suspend (Suspend now, and automatically once the configured suspend timeout elapses).
  • Like every Quickshell plugin, this code runs unsandboxed inside the shared omarchy-shell process — review Panel.qml / Service.qml / power_timings_ctl.py before installing.

Files

File Purpose
manifest.json Plugin manifest (service + bar-widget)
Panel.qml Bar icon + popup UI
Service.qml Background auto-suspend timer
Model.js Preset lists and duration formatting
power_timings_ctl.py Symlink-safe, atomic shell.json idle-block writer

License

MIT — see LICENSE.