Omahub
← All plugins
B

Voxtype Stats

by Bind Ashutosh Parasnath

Local voxtype talk-time panel with destinations and a 14-day chart.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
b09e377
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:17

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec. The plugin never writes Hyprland, `shell.json`, or `~/.config/voxtype/config.toml`. You point voxtype at the two collector scripts yourself.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
b09e377
Reviewed
1 month ago

The plugin is a local bar widget that reads a JSON snapshot and displays voxtype talk-time stats. The collector scripts are benign: they write only to user state directories, use hyprctl only to read the focused window class (not titles), and never use sudo or network. The deterministic scan flagged a sudo mention in the README, but that is documentation only and not part of the executable code.

  • The README contains a line mentioning 'sudo or pkexec' but it explicitly states the plugin never uses them; this is documentation only.
  • The collector uses hyprctl to read the active window class for destination classification, which is a minor privacy consideration but does not capture titles or content.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Ashutoshbind15/omarchy-voxtype-stats --enable
Productivity #bar #quickshell

Voxtype Stats for Omarchy

Local voxtype talk-time on the Omarchy bar: today's words, pace, where takes landed, and a 14-day chart. Counts only. No transcripts, window titles, or network.

It is a bar-widget with a nested panel. It does not replace the Dictation indicator.

Voxtype Stats across three Omarchy themes

The panel follows the active theme. Same layout, same counts, three palettes.

Requirements

  • Omarchy 4 (Quattro) — Quickshell bar
  • voxtype (AI Dictation tool on Omarchy)
  • python3 and hyprctl (stock on Omarchy)

No sudo or pkexec. The plugin never writes Hyprland, shell.json, or ~/.config/voxtype/config.toml. You point voxtype at the two collector scripts yourself.

Install

omarchy plugin add https://github.com/Ashutoshbind15/omarchy-voxtype-stats.git --enable

The pill starts in the center section. Move it if you want:

omarchy bar move io.github.ashutoshbind15.omarchy-voxtype-stats --section right

Counts stay at zero until voxtype runs the collector on each take. Add these two keys to ~/.config/voxtype/config.toml. Voxtype keeps one command per key, so this is a replace unless you already have hooks — then compose them (next section).

PLUGIN="$HOME/.config/omarchy/plugins/io.github.ashutoshbind15.omarchy-voxtype-stats"
printf 'pre_recording_command = "%s/collector/session-start"\n' "$PLUGIN"
printf 'command = "%s/collector/log"\n' "$PLUGIN"

Paste the printed lines into the right sections:

[output]
pre_recording_command = "/home/you/.config/omarchy/plugins/io.github.ashutoshbind15.omarchy-voxtype-stats/collector/session-start"

[output.post_process]
command = "/home/you/.config/omarchy/plugins/io.github.ashutoshbind15.omarchy-voxtype-stats/collector/log"
timeout_ms = 2000

Then systemctl --user try-restart voxtype.service.

After adding or renaming QML files, run omarchy restart shell once so Qt picks up the new directory listing.

To confirm the post-process hook without dictating:

echo hello world | ~/.config/omarchy/plugins/io.github.ashutoshbind15.omarchy-voxtype-stats/collector/log

That should print hello world and bump the snapshot.

If you already have voxtype hooks

voxtype setup compositor sets pre_recording_command (Hyprland submap) and post_output_command (reset). This plugin does not use post_output_command. Keep that one.

For a key you already filled, keep your command and add the collector. session-start and log both exit 0 on failure so they should not break recording.

[output]
pre_recording_command = "hyprctl dispatch submap voxtype_recording; /home/you/.config/omarchy/plugins/io.github.ashutoshbind15.omarchy-voxtype-stats/collector/session-start"

[output.post_process]
# log echoes stdin unchanged, so an LLM (or sed) can run first
command = "ollama run llama3.2:1b 'Clean up:' | /home/you/.config/omarchy/plugins/io.github.ashutoshbind15.omarchy-voxtype-stats/collector/log"
timeout_ms = 45000

Raise timeout_ms if the first command is slow. Drop the extra command if you only want counts.

Usage

  • Left-click the pill to open or close the panel.
  • Escape closes it.
  • Click a destination row or a day bar to inspect that slice.
  • Shell routes:
omarchy-shell shell summon io.github.ashutoshbind15.omarchy-voxtype-stats '{}'
omarchy-shell shell hide io.github.ashutoshbind15.omarchy-voxtype-stats

The bar shows the talk-time icon. The panel shows today's words, WPM, six destination buckets (Browser, Editor, Terminal, Chat, Agent, Other), and the last 14 days. Daily rows are kept for 42 days.

Destinations come from the Hyprland class at recording start. Super+agent windows (org.omarchy.agent) land in Agent. A CLI agent inside a normal terminal stays Terminal.

Privacy

  • Snapshot: ~/.local/state/io.github.ashutoshbind15.omarchy-voxtype-stats/session.json — counts, seconds, destination ids, day keys. The bar and collector refuse a file over 64 KiB and cap the day and destination arrays they walk.
  • Scratch: $XDG_RUNTIME_DIR/io.github.ashutoshbind15.omarchy-voxtype-stats/take-start — epoch + class.
  • The collector never writes the transcript, clipboard, or window titles. Stdin is counted in a 0600 temp file under $XDG_RUNTIME_DIR (first 256 KiB; the rest is still echoed) and deleted before the snapshot is updated. An EXIT/INT/TERM/HUP trap removes that file if voxtype's timeout_ms or a signal interrupts the hook.

Remove

Take the two keys out of ~/.config/voxtype/config.toml (or put your old commands back), then:

omarchy plugin remove io.github.ashutoshbind15.omarchy-voxtype-stats

Optionally:

rm -rf ~/.local/state/io.github.ashutoshbind15.omarchy-voxtype-stats

Tests

./test/talk-stats-test.sh

Node checks StatsModel.js. Python and the collector check WPM hold, date rollover, the 42-day cap, destination tokens, stdin passthrough, stdin/snapshot size caps, temp-file cleanup on timeout, and the python-failure path.

License

MIT — see LICENSE.