Omahub
← All plugins
E

AJAZZ Keyboard

by ESH

Lighting controls for the AJAZZ AK820 MAX keyboard.

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
e893889
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:35

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -Dm644 "$PLUGIN_DIR/udev/70-ajazz-ak820.rules" \
  • Docs sudo README.md:37

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm control --reload-rules
  • Docs sudo README.md:86

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f /etc/udev/rules.d/70-ajazz-ak820.rules
  • Docs sudo README.md:87

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm control --reload-rules

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e893889
Reviewed
1 month ago

The plugin is a transparent QML/Python HID controller for a specific keyboard model. The deterministic scan flagged sudo commands in the README, but those are manual udev-rule installation and removal steps, not code executed by the plugin. No obfuscation, network activity, hidden persistence, or destructive behavior was found in the sampled executable files.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ESHAYAT102/ajazz-keyboard-omarchy-plugin --enable
Hardware #bar #system

AJAZZ Keyboard for Omarchy

A native Omarchy Quattro top-bar controller for the AJAZZ AK820 MAX keyboard. Choose a lighting effect, full RGB color, brightness, speed, direction, and rainbow mode without running the Windows driver.

Requirements

  • Omarchy Quattro on Linux
  • Python 3; the backend uses only the standard library
  • udev and Linux hidraw support
  • AJAZZ AK820 MAX connected in wired USB mode
  • USB identity 0C45:8009 with HID collection FF13:0001

No Python packages, external services, remote builds, or second Quickshell process are required.

Bluetooth device 0C45:FEFE exposes only standard keyboard, mouse, media, and lock-LED reports, so it cannot carry these RGB commands. The unverified 05AC:024F 2.4 GHz receiver is intentionally read-only as well.

Install

Install the plugin through Omarchy's transactional Git installer:

omarchy plugin add https://github.com/ESHAYAT102/ajazz-keyboard-omarchy-plugin.git --enable

The RGB interface is root-owned by default. Install the included udev rule to grant the active desktop session access only to USB interface 3:

PLUGIN_DIR="$HOME/.config/omarchy/plugins/esh.ajazz-keyboard"
sudo install -Dm644 "$PLUGIN_DIR/udev/70-ajazz-ak820.rules" \
  /etc/udev/rules.d/70-ajazz-ak820.rules
sudo udevadm control --reload-rules

Reconnect the keyboard in wired mode after installing the rule. The panel detects the supported interface automatically.

Usage

  • Left-click the keyboard icon to open or close the panel.
  • Press Escape to close the panel.
  • Select an effect from the dropdown.
  • Pick a color visually or enter #RRGGBB in the hex field.
  • Adjust brightness, speed, direction, and rainbow mode in the panel.
  • Scroll over the bar icon to adjust brightness.
  • Right-click the bar icon to toggle lighting power.

The plugin can also be opened and closed through the standard shell lifecycle:

omarchy-shell shell summon esh.ajazz-keyboard '{}'
omarchy-shell shell hide esh.ajazz-keyboard

Backend diagnostics

The bundled helper can inspect the connection without writing to hardware:

PLUGIN_DIR="$HOME/.config/omarchy/plugins/esh.ajazz-keyboard"
"$PLUGIN_DIR/bin/ajazz-keyboard" status
"$PLUGIN_DIR/bin/ajazz-keyboard" diagnose
"$PLUGIN_DIR/bin/ajazz-keyboard" apply --effect static --color '#ff3158' --dry-run

The helper refuses writes unless both the wired VID/PID and vendor collection match. It never opens the standard keyboard input interfaces.

Remove

Remove the plugin through Omarchy:

omarchy plugin remove esh.ajazz-keyboard

The privileged udev rule and optional saved lighting state are separate from the Git checkout. Remove them explicitly if they are no longer wanted:

sudo rm -f /etc/udev/rules.d/70-ajazz-ak820.rules
sudo udevadm control --reload-rules
rm -rf "${XDG_STATE_HOME:-$HOME/.local/state}/omarchy/plugins/esh.ajazz-keyboard"

Reconnect the keyboard once after removing the rule.

Development

Validate the repository root and QML entry points before publishing:

omarchy plugin validate .
/usr/lib/qt6/bin/qmllint -I "$OMARCHY_PATH/shell" \
  BarWidget.qml Panel.qml Service.qml ColorPicker.qml
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest discover -s tests -v

The protocol tests cover report size, command order, control markers, RGB and parameter offsets, state persistence, and the captured AA 55 trailer.

Protocol

The implementation follows the vendor driver's 35 ms pacing and captured feature-report transaction:

  1. 04 18 start, then feature readback
  2. 04 13 mode preamble with byte 8 set to 01, then readback
  3. 64-byte effect payload
  4. 04 02 save, then readback
  5. 04 F0 finish, then readback

At the Linux hidraw boundary every feature transfer is prefixed with report ID zero, producing a 65-byte ioctl buffer for the unnumbered 64-byte report.

License

MIT. See LICENSE.