Omahub
← All plugins
B

Privacy Devices

by bolens

Unified, configurable privacy indicators for microphones, audio playback, cameras, screen sharing, screenshots, screen recording, and location access.

Security review

Potentially dangerous behavior detected · 6 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
08222db
Scanned
3 weeks ago
  • high decode_and_execute …/bash/common.sh:403

    Interpreter evaluated with an execution builtin.

    python3 -c 'import sys; raise SystemExit(sys.version_info.major != 3)' >/dev/null 2>&1; then
  • high decode_and_execute …/bash/common.sh:406

    Interpreter evaluated with an execution builtin.

    python -c 'import sys; raise SystemExit(sys.version_info.major != 3)' >/dev/null 2>&1; then
  • high destructive_filesystem .devcontainer/Dockerfile:44

    Destructive operation on the root filesystem or a block device.

    rm -rf /var/lib/apt/lists/*
  • high persistence privacy-control:70

    Registers scheduled or boot-time system tasks.

    systemctl mask --runtime --now geoclue.service
  • medium package_manager .devcontainer/Dockerfile:11

    System package manager operation.

    apt-get install -y --no-install-recommends \
  • Docs external_hosts CONTRIBUTING.md:19

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/bolens/omarchy-privacy-devices.git

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
08222db
Reviewed
3 weeks ago

The plugin is a privacy-monitoring widget that inspects PipeWire/ALSA/V4L2 state and runs small helper scripts to read or change device state; the deterministic scan's high findings are mostly benign development-container and spec-kit tooling, and the persistence finding is a runtime systemd mask of geoclue that only takes effect when the user explicitly enables the location control. No obfuscated code, credential theft, or destructive install-time behavior was found.

  • The privacy-control helper can run systemctl mask/unmask and pactl/wpctl commands; these are user-visible privacy controls, but a bug or malicious update could change device state without confirmation.
  • The plugin ships executable helper scripts (privacy-control, privacy-deps, privacy-history, privacy-audio-devices) that are not fully shown in this sample; a human should spot-check them for command injection or unexpected side effects.
  • The devcontainer Dockerfile and .specify scripts are not part of the installed plugin runtime, but they are included in the repository and were flagged by the scan; they are development tooling only.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/bolens/omarchy-privacy-devices --enable
Widgets #bar #quickshell #security

Privacy Devices

A configurable Omarchy Shell widget that combines privacy activity indicators and controls for microphones, audio output, cameras, location, screen sharing, screenshots, and screen recording.

Website and user guide · Community marketplace listing · Documentation · Get support · Report an issue

Contributors: contributing guide · architecture · security policy

Privacy Devices activity panel showing live device state and controls

The widget occupies only its privacy-device indicators in the center bar:

Privacy Devices indicators in their exact bar footprint

Activity notifications use the detected application icon when available:

Privacy Devices notification with an application icon

<details> <summary>Settings pages</summary>
General Appearance
<img src="docs/general.png?v=a0646e3054d5" alt="General settings page" width="360"> <img src="docs/appearance.png?v=d86e1399ca51" alt="Appearance settings page" width="360">
Alerts Monitoring
<img src="docs/alerts.png?v=34d2df58f038" alt="Alerts settings page" width="360"> <img src="docs/monitoring.png?v=a284799b7797" alt="Monitoring settings page" width="360">
Private data Observer health
<img src="docs/monitoring-private.png?v=188db0bdc8b4" alt="Private history and settings transfer controls" width="360"> <img src="docs/monitoring-health.png?v=2c755b25e931" alt="Monitoring status and observer health" width="360">
Individual device settings Activity history
<img src="docs/device.png?v=99a96937055a" alt="Individual privacy-device settings page" width="360"> <img src="docs/history.png?v=1ef5c5219702" alt="Completed privacy activity history view" width="360">
History disabled
<img src="docs/history-disabled.png?v=74b0876b9c4e" alt="Activity history disabled state" width="360">
</details>

Highlights

  • Per-application activity, session context, controls, and health for seven privacy-device classes.
  • Reactive PipeWire monitoring plus optional same-user direct-device coverage.
  • Verified mute, recording, camera, location, and screen-sharing controls, plus named privacy modes and a confirmed privacy lockdown with observed-state undo.
  • Per-endpoint microphone and audio-output management on their device settings pages, with exact hardware names and verified mute/unmute results.
  • Global and per-device appearance, ordering, visibility, backend, and status settings.
  • Keyboard-focusable controls and activity cards with named state descriptions for assistive technologies.
  • App- and device-aware visibility and notification policies, friendly hardware labels, session-only device-change feedback, and live inspection-target copy.
  • Private diagnostics and searchable optional bounded history with trend bars, device/evidence filters, stable sorting, and today/seven-day summaries.
  • Click-through activity notifications, optional rate-limited observer-health alerts, and a guided redacted self-test with remediation guidance.
  • Allowlisted IPC quick actions for activity, history, diagnostics, lockdown, undo, and rescanning, suitable for thin launcher adapters.
  • Deep-linked IPC routes for the main activity view, a validated device detail, a settings page, or a validated settings section.
  • Keyboard navigation throughout the popup and settings, with activity actions and shortcut help pinned around independently scrollable content. Global settings navigation and reset actions remain pinned as settings fields move, while independently anchored chrome keeps settings content from rendering behind those controls. Width remains stable between pages while height fits loaded content between a useful minimum viewport and the configured cap.
  • Persistent observers and bounded background work, with no network telemetry.

See the user guide for supported controls, requirements, configuration, privacy behavior, troubleshooting, and lifecycle commands.

Notification actions and launchers use the installed privacy-action helper. It accepts only open-activity [kind], open-history [kind], open-diagnostics, lockdown, undo-lockdown, and rescan; no observed metadata is interpreted as a command.

To add searchable Privacy Devices rows to the Omarchy menu, run the optional, idempotent adapter from the installed plugin:

~/.config/omarchy/plugins/io.github.bolens.privacy-devices/privacy-menu-entry install

Use status to inspect it or remove to delete only the entries owned by this plugin. The lockdown row opens the existing confirmation step; it never changes device state directly.

Quick install

omarchy plugin add https://github.com/bolens/omarchy-privacy-devices.git --enable

Add or move the widget through Setup → Bar, or run:

omarchy bar move io.github.bolens.privacy-devices --section center

Development

See CONTRIBUTING.md, the validation matrix, and ARCHITECTURE.md. Maintainers can refresh interface images with the restoring screenshot workflow.

License

MIT

License scope and attribution

See third-party notices for the project license scope, retained upstream notices, and dependency or asset exceptions.