Omahub
← All plugins
H

Keyboard Indicator

by HANCORE

Unified Omarchy keyboard center for CapsLock/Ctrl remapping, independent CapsLock/Left Ctrl/Right Ctrl Voxtype dictation, Fcitx5 input methods, and keyboard layouts.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
9e432bb
Scanned
4 weeks ago
  • medium sudo ctrl_swap.py:126

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo is required to install the keyboard remap")
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo is required to install the keyboard remap")
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo fallback for systems where a Polkit prompt is unavailable.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
9e432bb
Reviewed
4 weeks ago

The plugin is a legitimate keyboard remapping widget: it uses keyd with a pinned upstream commit, builds it as the unprivileged user, and performs privileged writes through a narrowly scoped pkexec/sudo helper. The deterministic scan's medium findings are triggered by the literal string 'sudo' in an error message and a changelog sentence, not by a dangerous command. No obfuscation, credential theft, or destructive behavior was found, but the privileged root helper, automatic reapply on shell start, and supply-chain fetch justify a human review before publishing.

  • PRIVILEGED_HELPER is executed as root via pkexec or a passwordless `sudo -n` fallback and can write/remove files under /etc/keyd plus fixed /usr/local paths; the allowlist should be audited for path traversal and unintended overwrites.
  • The plugin automatically runs `ensure` on shell startup and may re-apply saved keyd state, triggering a Polkit/systemd change without a fresh user gesture in that session.
  • If keyd is absent, the plugin fetches and builds a pinned upstream commit as the user and installs the resulting binaries as root; supply-chain integrity depends on the pinned commit and the build artifact handling.
  • The root helper accepts any `/etc/keyd/*.conf` as a write/removal target, so the profile-selection feature can modify user keyd profiles; this is documented but should be confirmed as intended.
  • A duplicate root-level ctrl_swap.py exists alongside scripts/ctrl_swap.py; packaging should verify only the intended script is used by the QML entry points.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/iamcheyan/omarchy-keyboard-indicator --enable
Desktop #Hyprland #bar #quickshell

Keyboard Indicator

0.4.4

  • Fixed keyboard-panel option text overlapping the right-side toggles at narrow widths and larger font sizes.
  • Adapted the settings panel text, dropdowns, and controls to Omarchy popup theme tokens so light and dark themes keep readable contrast.

Keyboard Indicator is an Omarchy experience-enhancement plugin for keyboard remapping, independent per-key Voxtype dictation, Fcitx5 input methods, and XKB keyboard layouts.

Marketplace

Keyboard Indicator has been approved and verified in the Omarchy plugin marketplace: open the published marketplace page.

Features

  • Native Omarchy top-bar widget and settings panel.
  • Independent toggles for the CapsLock/Left Ctrl swap and separate CapsLock, Left Ctrl, and Right Ctrl Voxtype dictation.
  • Applies to graphical applications, terminals, tmux, SSH sessions, and Hyprland global shortcuts because keyd remaps the input before they receive it.
  • Uses keyd and a small system configuration managed through an explicit pkexec authentication prompt.
  • If keyd is missing, the plugin fetches one pinned upstream commit, verifies it, and builds it as the user. The privileged step receives only the resulting binaries and installs them; it never executes the downloaded Makefile.
  • Remembers the enabled state; keyd continues to run as a system service after shell or Hyprland restarts.
  • Keeps the UI and state management in the user session; privileged work is limited to installing/removing the keyd config.

Installation

omarchy plugin add https://github.com/iamcheyan/omarchy-keyboard-indicator.git --enable

Open the Keyboard Indicator keyboard icon in the top bar. The panel follows Omarchy's native theme and uses the shell's KeyboardPanel, ToggleSwitch, and themed selector patterns.

The plugin automatically reapplies the selected state when the Omarchy shell starts. Disable or remove the plugin to restore the normal mapping and stop the plugin's runtime integration.

Interface

The default panel puts the active input method and keyboard layout first, followed by the optional keyboard remap and three independent dictation switches.

Keyboard Indicator default panel

Default panel with the current input method and keyboard layout.

Both selectors use compact dropdown menus so the available input schemes and layouts stay out of the way until needed.

Keyboard Indicator expanded selector

Expanded input-method selector.

How it works

keyd stays installed whenever the Ctrl swap or any dictation switch is on. The generated configuration depends on the four independent controls. Each enabled voice key emits the plugin-owned F24 signal. A standalone press toggles Voxtype on release; holding either Ctrl key with another key keeps normal Ctrl shortcuts working.

Swap only:

[ids]
*

[main]
capslock = layer(control)
leftcontrol = capslock

Dictation only (CapsLock is consumed, so it no longer toggles case):

[ids]
*

[main]
capslock = f24
leftcontrol = overload(control, f24)

Swap and dictation together (standalone press = Voxtype, combination = Ctrl):

[ids]
*

[main]
capslock = overload(control, f24)
leftcontrol = overload(control, f24)

The file is installed as /etc/keyd/hancore-ctrl-swap.conf after the user approves the pkexec prompt. The file carries a schema marker, and a config missing the marker is treated as drift and rebuilt. When the swap and all three dictation switches are off, the file is removed instead of leaving an identity mapping: keyd applies one wildcard config per device, so our file could otherwise override the user's own /etc/keyd/default.conf and discard unrelated mappings. keyd is restarted so the user's configuration can take over again. The swap intent is stored at:

~/.local/state/hancore.keyboard-center/enabled

The panel also lists the installed /etc/keyd/*.conf profiles with their device IDs. Selecting a profile applies the plugin mapping to that profile while preserving its existing mappings; the selection is stored in the same state directory. This is useful when a keyboard has an explicit keyd profile that would otherwise win over the plugin's wildcard profile.

Optional per-key dictation

The panel provides separate switches for CapsLock, Left Ctrl, and Right Ctrl. Each enabled key uses the plugin-owned F24 toggle trigger when pressed alone:

voxtype record toggle

keyd remaps enabled voice keys to the plugin-owned F24 signal. F24 toggles Voxtype on release. F9 remains the user's original Voxtype toggle. Left and Right Ctrl use overload(control, f24) so Ctrl shortcuts remain available. Disabling one switch removes only that key's voice mapping. These options require the voxtype command.

Boundary and compatibility notes

  • Only Left Ctrl and CapsLock are swapped. Right Ctrl is never part of the swap, but it can independently be assigned to Voxtype.
  • This plugin requires one-time administrator authentication when keyd is first installed, and authentication again when the system config is changed.
  • It does not install a permissive Polkit rule; authentication is handled by the normal desktop Polkit agent.

Uninstallation

Disable or remove the plugin through Omarchy's plugin manager. Disabling all switches restores the original keyboard mapping by removing /etc/keyd/hancore-ctrl-swap.conf, handing the device back to the user's own keyd configuration. Removing the plugin files alone does not revert the system configuration — turn all switches off first. It does not remove unrelated Hyprland or keyboard configuration.

Validation

omarchy plugin validate .
qmllint -I /usr/share/omarchy/shell bar/widget.qml CtrlSwapPanel.qml
python3 -m py_compile scripts/ctrl_swap.py
python3 -m unittest discover -s tests
# live state walk; asks for polkit authentication once per transition
python3 tests/e2e_four_states.py

License

MIT. See LICENSE.