Omahub
← All plugins
F

RyzenAdj

by Foresight

Focused AMD Ryzen telemetry, CPU-supported numeric tuning, quick presets, and profile management in the Omarchy bar.

Security review

Potentially dangerous behavior detected · 9 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
6ed4484
Scanned
1 month ago
  • high destructive_filesystem systemd/uninstall-service.sh:30

    Destructive operation on the root filesystem or a block device.

    rm -rf /usr/lib/ryzenadj
  • high destructive_filesystem systemd/uninstall-service.sh:31

    Destructive operation on the root filesystem or a block device.

    rm -rf /etc/ryzenadj
  • Registers scheduled or boot-time system tasks.

    systemctl disable --now ryzenadj-apply.service 2>/dev/null || true
  • Bundles a systemd unit file.

    [Unit]
  • Registers scheduled or boot-time system tasks.

    systemctl disable ryzenadj-apply.service, /usr/bin/systemctl start ryzenadj-apply.service, /usr/bin/systemctl stop ryzenadj-apply.service, /usr/bin/systemctl restart ryzenadj-apply.service
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec ./systemd/uninstall-service.sh)" >&2
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec ./systemd/install-service.sh)" >&2
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo tee (needed to get past root restrictions)"""
  • Docs external_hosts README.md:56

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/rishadtharayil/omarchy-plugin-ryzenadj.git ~/.config/omarchy/plugins/foresight.ryzenadj

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6ed4484
Reviewed
1 month ago

This is a legitimate, well-documented RyzenAdj frontend with readable code and no signs of obfuscation, credential theft, or hidden network behavior. The high deterministic findings are mostly expected for a hardware-tuning plugin: the rm -rf targets are plugin-owned directories during explicit uninstall, and the systemd/sudoers entries are documented boot-persistence features. The main residual risk is the privileged footprint (passwordless sudo for ryzenadj and a root systemd service), which warrants human review before publishing.

  • install-service.sh installs a passwordless sudoers rule for ryzenadj and a root systemd service; this is disclosed in the README but is still a significant privilege expansion.
  • ryzenadj.sudoers defaults to ALL users; install-service.sh narrows it to the invoking user only when run via sudo/pkexec, but running it as root leaves the rule open to all local users.
  • uninstall-service.sh removes /usr/lib/ryzenadj and /etc/ryzenadj with rm -rf; these are plugin-owned paths, but the command could delete data from other ryzenadj-based tools, and only settings.json is backed up.
  • The root-run apply_saved.py service applies values from /etc/ryzenadj/settings.json at boot; the code is benign, but the sudoers tee rule makes that file writable by the user, so a compromised user session could influence root-applied hardware settings.
  • The deterministic flags for the README git clone and sudo usage are documentation/expected behavior rather than malicious activity.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rishadtharayil/omarchy-plugin-ryzenadj --enable
Hardware #bar #quickshell #power-management

RyzenAdj Omarchy Shell Plugin

An Omarchy status bar widget and popout tuning panel for AMD Ryzen mobile and desktop processors powered by ryzenadj.

Exposes focused hardware telemetry, CPU-supported power/clock/thermal/current tuning inputs, quick power presets, custom profile management, and boot persistence controls directly from the Omarchy status bar.


Features

  • Live Telemetry & Status Bar:
    • Live STAPM power readout directly on the bar button (󰍛 7.2 W).
    • Hero dashboard with only the four live metrics: STAPM power, core temperature, CPU clock, and iGPU clock.
    • Dynamically measured bar slot width so text never clips or overlaps neighboring icons.
  • ⚡ Quick Presets:
    • 1-click Power Saving and Max Performance presets.
    • Right-click the status bar icon to toggle between presets instantly.
  • ⚙️ Hardware Tuning:
    • Category tabs for Power, Clocks, Current, Thermal, Undervolt, and Timing.
    • Dynamic discovery of parameters supported by the detected CPU; unsupported controls are hidden.
    • Direct numeric entry with displayed units such as W, A, MHz, and °C, converted automatically to the native ryzenadj command values.
    • Per-parameter Reset controls remove a value from the applied startup configuration.
  • 🔖 Custom Profiles:
    • Save current tuning parameters to named profiles.
    • 1-click apply and delete.
    • Automatic profile switching on AC connection and Battery discharge.
  • 🛠️ Boot Persistence & Preferences:
    • Toggle startup persistence systemd service directly from the GUI.
    • Background Persistence Guard to counteract firmware power limit resets.
    • Configurable polling intervals (1s, 2s, 3s, 5s, 10s) and bar display toggles.

Tuning workflow

At startup, the backend probes ryzenadj and exposes only the parameters supported by the detected CPU. The tuning view contains numeric fields rather than sliders or live target badges.

  • Enter values in the displayed unit: W for power, A for current, MHz for clocks, and °C for temperatures.
  • Press Apply to Hardware to validate the values, convert them to RyzenAdj's native command units, apply them, and save them for persistence.
  • Press Reset beside a parameter to remove it from the next apply and from the saved startup configuration.
  • Built-in presets and custom profiles are separate from tuning drafts; applying a preset clears the pending custom draft.

Installation

Add via Omarchy Plugin Manager

omarchy plugin add https://github.com/rishadtharayil/omarchy-plugin-ryzenadj.git --enable

Manual Installation

Clone into your user plugins directory:

git clone https://github.com/rishadtharayil/omarchy-plugin-ryzenadj.git ~/.config/omarchy/plugins/foresight.ryzenadj
omarchy plugin enable foresight.ryzenadj right

For an existing checkout, copy or update the plugin directory and restart the Omarchy shell so the QML changes are loaded:

omarchy plugin enable foresight.ryzenadj right
omarchy-restart-shell

Privileges & Service Setup

The plugin uses sudo -n for non-interactive hardware register writes and systemd lifecycle operations.

1. Requirements

  • ryzenadj:
    omarchy pkg aur add ryzenadj
    

2. Sudoers & Persistence Service Setup

Run the included installation script to install the strict sudoers policy, backend runner, and systemd service:

sudo ~/.config/omarchy/plugins/foresight.ryzenadj/systemd/install-service.sh

This installs:

  • Strict Sudoers Policy (/etc/sudoers.d/ryzenadj):
    • Grants non-interactive access to /usr/bin/ryzenadj.
    • Permits exact systemctl lifecycle commands (enable --now, disable --now, is-enabled, start, stop, restart for ryzenadj-apply.service).
    • Permits exact file sync for /etc/ryzenadj/settings.json.
    • Permits exact AMDGPU sysfs clock overrides for supported cards.
  • Backend Service Unit (/etc/systemd/system/ryzenadj-apply.service):
    • Runs /usr/lib/ryzenadj/apply_saved.py on boot to apply saved power and curve-optimizer limits.

Removal & Uninstallation

To cleanly remove the plugin:

# 1. Disable and remove the shell plugin
omarchy plugin remove foresight.ryzenadj --yes

# 2. (Optional) Uninstall systemd persistence service and sudoers rules
sudo ~/.config/omarchy/plugins/foresight.ryzenadj/systemd/uninstall-service.sh

IPC Commands

Control the widget from scripts, Hyprland keybindings, or terminal:

# Toggle open / close panel
omarchy-shell foresight.ryzenadj toggle

# Apply presets
omarchy-shell foresight.ryzenadj applyPreset power-saving
omarchy-shell foresight.ryzenadj applyPreset max-performance

# Apply named profile
omarchy-shell foresight.ryzenadj applyProfile <profile_name>

# Configure polling interval (in milliseconds)
omarchy-shell foresight.ryzenadj setPollingInterval 5000

# Toggle live power wattage on the bar
omarchy-shell foresight.ryzenadj toggleLivePower

# Toggle active profile tag on the bar
omarchy-shell foresight.ryzenadj toggleActiveProfile

# Query live telemetry JSON
omarchy-shell foresight.ryzenadj status

Validation & Testing

omarchy plugin validate ~/.config/omarchy/plugins/foresight.ryzenadj
node --test ~/.config/omarchy/plugins/foresight.ryzenadj/tests/model.test.js
python3 -m unittest discover -s ~/.config/omarchy/plugins/foresight.ryzenadj/tests -p '*test.py'

License

MIT License. Copyright (c) 2026.