Omahub
← All plugins
B

Keyboard RGB

by Bruno G. Soares

Control MSI SteelSeries per-key keyboard lighting from the Omarchy bar.

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
e02a9ee
Scanned
1 month ago
  • medium sudo uninstall.sh:12

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm /etc/udev/rules.d/99-msi-steelseries-rgb.rules"
  • medium sudo setup.sh:33

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -Dm644 '$RULE_PATH' /etc/udev/rules.d/99-msi-steelseries-rgb.rules"
  • medium sudo setup.sh:34

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm control --reload-rules"
  • medium sudo setup.sh:35

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo udevadm trigger --subsystem-match=hidraw"

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e02a9ee
Reviewed
1 month ago

The plugin is a straightforward keyboard RGB controller that installs user-space files and a udev rule to grant the user access to a specific keyboard device. The sudo commands flagged by the deterministic scan are only printed as instructions, not executed by the scripts, so they pose no actual elevation risk. No obfuscation, credential theft, or destructive behavior was found.

  • The setup.sh and uninstall.sh print sudo commands for the user to run manually; these are not executed by the scripts themselves, so the deterministic scan's medium findings are overstated.
  • The udev rule grants the user ownership of the hidraw device, which is necessary for the plugin to function and is clearly documented.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/bruno-g-soares/omarchy-keyboard-rgb --enable
Hardware #bar #quickshell

Omarchy Keyboard RGB

An Omarchy Quattro bar plugin for the SteelSeries per-key RGB keyboard in the MSI Stealth GS66 12U. It provides solid colors, brightness, power control, saved profiles, startup restore, and optional Omarchy theme synchronization.

Keyboard RGB panel

Compatibility

The currently verified hardware is:

  • MSI Stealth GS66 12U
  • SteelSeries KLC USB ID 1038:113a
  • US keyboard layout

The controller deliberately refuses to target any other USB ID. Other MSI models may use a similar keyboard, but they are unsupported until tested.

Requirements

  • Omarchy Quattro with the plugin system enabled
  • Python 3
  • Arch Linux hidapi package (omarchy-pkg-add hidapi)

Install

Add and enable the plugin:

omarchy plugin add https://github.com/bruno-g-soares/omarchy-keyboard-rgb.git --enable
cd ~/.config/omarchy/plugins/io.github.bruno-g-soares.omarchy-keyboard-rgb
./setup.sh

setup.sh installs the bundled controller under ~/.local, registers uniquely named theme/startup hooks, and generates a device rule restricted to your user. It does not request elevated privileges. Run the three commands it prints to install and activate that rule; those are the only privileged installation steps.

The runtime plugin never invokes sudo or pkexec.

Use

  • Left-click the bar icon to open the panel.
  • Right-click it to toggle the keyboard lighting.
  • Choose a fully saturated color or enter a six-digit hex color.
  • Use the slider to adjust software brightness.
  • Enable Theme Sync to follow keyboard.rgb from the active Omarchy theme, falling back to the theme's accent value.

The controller is also available from the command line:

omarchy-keyboard-rgb set '#8d8d8d'
omarchy-keyboard-rgb brightness 70
omarchy-keyboard-rgb off
omarchy-keyboard-rgb auto-theme enable
omarchy-keyboard-rgb auto-theme disable
omarchy-keyboard-rgb profiles save work
omarchy-keyboard-rgb profiles apply work
omarchy-keyboard-rgb status --json

Safety

This release sends only the steady-color (0x0e) and apply (0x09) packets validated on the 1038:113a controller. It does not expose the older bundled hardware-effect presets or generate undocumented effect packets.

The power key's RGB element is included. Its separate blue/amber GPU-status LED is firmware-controlled and is never addressed by this plugin.

Brightness is implemented by scaling RGB intensity because this keyboard does not expose a host-side brightness command. The keyboard's firmware brightness hotkey remains independent.

Theme and startup behavior

Theme Sync is off by default. When enabled, the theme-set hook reapplies the active theme color. The post-boot hook restores the saved enabled state, color, and brightness after login.

State is stored under ${XDG_STATE_HOME:-~/.local/state}/omarchy-keyboard-rgb. Saved profiles are stored under ${XDG_CONFIG_HOME:-~/.config}/omarchy-keyboard-rgb.

Remove

From the installed plugin directory, run:

./uninstall.sh

The script removes user-space plugin files, controller files, and hooks while retaining state and saved profiles. It prints the optional privileged command for removing the system device rule.

Development

bash tests/test-controller.sh
bash tests/test-protocol.py
bash tests/test-release.sh
omarchy plugin validate .
/usr/lib/qt6/bin/qmllint -I /usr/share/omarchy/shell BarWidget.qml Panel.qml

License and attribution

The plugin is MIT licensed. It vendors the MIT-licensed msi-perkeyrgb backend by Askannz; its original license is retained at vendor/msi-perkeyrgb.LICENSE.