Omahub
← All plugins
H

Vital Signs

by Harel Malka

A customizable Omarchy system-monitor widget for RAM, CPU, load, network, battery, temperatures, fans, and process controls.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
ea8c0a1
Scanned
4 weeks ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:51

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/harel/omarchy-vital-signs.git

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
ea8c0a1
Reviewed
4 weeks ago

The plugin is a system monitor that reads local /proc and /sys data and includes a user-confirmed process kill and a separately confirmed pkexec-based kernel OOM trigger. The OOM trigger is intentionally destructive but clearly documented and gated behind explicit user confirmation, so it is not hidden malicious behavior. The deterministic scan's external-host finding is documentation-only (a git clone in the README) and not part of the executable code.

  • The kernel OOM trigger writes 'f' to /proc/sysrq-trigger via pkexec, which can kill processes and cause data loss or session instability; it is destructive but requires explicit user confirmation and is documented.
  • The process termination feature sends SIGTERM to user-owned processes after confirmation; it is limited to the current user and revalidates PID/name/ownership/start time, but still allows killing user processes from the panel.
  • The collector script reads many /proc and /sys files and runs as the user; it does not appear to exfiltrate data or perform hidden network activity.
  • The deterministic scan flagged the README's git clone URL, but that is documentation for local development and not executed by the plugin.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/harel/omarchy-vital-signs --enable
System #bar #quickshell #system

Vital Signs

An Omarchy 4 shell plugin that displays selectable live system metrics in the bar. Click the status line to choose metrics; use the settings page to control the refresh rate, bar alignment, empty-value visibility, and metric icons. The Advanced page lists top CPU and RAM processes owned by the current user, with confirmed termination actions, plus a separately confirmed privileged kernel OOM trigger.

Vital Signs bar

Vital Signs overlay

Requirements

  • Omarchy 4 with omarchy-shell
  • A Linux system exposing metrics through /proc and /sys
  • Standard Omarchy command-line tools: Bash, awk, GNU ps, getconf, and pkexec

Installation

Install and enable the plugin directly from GitHub:

omarchy plugin add https://github.com/harel/omarchy-vital-signs.git --enable

The command asks for confirmation because Omarchy plugins run inside the long-lived shell process. After installation, Vital Signs appears in the bar's right section by default.

To update an existing installation:

omarchy plugin update harel.vital-signs

To remove it:

omarchy plugin remove harel.vital-signs

Local development

Clone the repository anywhere, then symlink it into Omarchy's user plugin directory:

git clone https://github.com/harel/omarchy-vital-signs.git
cd omarchy-vital-signs
mkdir -p "$HOME/.config/omarchy/plugins"
ln -s "$PWD" "$HOME/.config/omarchy/plugins/harel.vital-signs"
omarchy-shell shell rescanPlugins
omarchy plugin enable harel.vital-signs

After changing QML or scripts behind the development symlink, restart the shell to ensure the linked source is reloaded:

omarchy restart shell

Use omarchy-shell shell rescanPlugins when adding a new plugin or entry point.

Process monitoring

Process collection runs only while the Advanced page is open. The settings page offers two CPU calculation modes:

  • Live delta (default) calculates CPU usage from kernel tick differences between samples. RAM appears after the first sample; CPU appears after the second, with a measuring message shown in the meantime.
  • ps average uses GNU ps lifetime-average CPU values and appears after the first sample.

By default, CPU follows the familiar top/ps per-core convention: 100% means one logical CPU is fully occupied, so a multithreaded process can exceed 100%. Disable Use per-core CPU percentage to normalize each process against the machine's total logical CPU capacity instead.

The collector excludes itself and its sampling children from the results.

Notes

  • Network speed is the combined receive rate for all non-loopback interfaces.
  • Battery percentage is read from the first battery exposed in Linux sysfs.
  • Temperature and fan availability depend on what the kernel exposes through /sys/class/hwmon; unsupported hardware is shown as “Not reported”.
  • All metrics are read locally without root privileges.
  • The process list is restricted to the current user's processes. Termination sends SIGTERM without privilege escalation after an in-panel confirmation and revalidates the PID, process name, ownership, and kernel start time to protect against PID reuse.
  • The kernel OOM trigger is an intentionally destructive emergency control. It requires a separate in-panel confirmation followed by pkexec authorization, then writes f to /proc/sysrq-trigger. The kernel chooses a memory-consuming process to kill; this can cause data loss or destabilize the session.