Omahub
← All plugins
E

Hearth

by Elliot Moreau

Mix Blanket's ambient loops from the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
8e4e953
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
8e4e953
Reviewed
1 month ago

Hearth is a self-contained ambient sound mixer that launches mpv via argument arrays, communicates only over a local Unix socket with a small Python helper, and carefully sanitizes state-derived paths and sound IDs. No network activity, credential access, hidden persistence, destructive commands, or obfuscated code were found; the deterministic scan's 'none' result is consistent with this review.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/cempack/hearth --enable
Widgets #bar #quickshell #media

Hearth

Tend a mix of ambient sound from the Omarchy bar. The voices and grouping come from Blanket: rain, storm, cafe, fireplace, noise, and the rest, mixed from a theme-aware popout that keeps playing after it closes.

The bar mark is the same nerd-font flame as the rest of the shell. Idle tiles are just glyphs; lit ones bloom in that sound's color with a volume ring. While anything is playing, the panel washes with drifting ambient color — rain cools the room, fire warms it, mixed voices blend — then settles dimly when you pause.

Requirements

  • Omarchy 4 with the Quickshell shell
  • mpv on PATH (playback). The panel still opens without it and shows an install hint.
  • python3 on PATH (used only to send volume commands to mpv over a unix socket)
  • mkdir, head, test, and timeout from coreutils

No network calls. No secrets. Bundled loops are the recordings shipped with Blanket 0.8.0; authors and licenses are in sounds/ATTRIBUTION.md.

Install

omarchy plugin add https://github.com/cempack/hearth.git --enable

For a local checkout:

omarchy plugin validate "$PWD"
PLUGIN_ID="$(jq -r .id manifest.json)"
PLUGIN_DIR="$HOME/.config/omarchy/plugins/$PLUGIN_ID"
mkdir -p "$PLUGIN_DIR"
rsync -a --delete --exclude .git --exclude tests "$PWD/" "$PLUGIN_DIR/"
omarchy-shell shell rescanPlugins
omarchy plugin enable "$PLUGIN_ID" --section right

Omarchy rejects a plugin folder that is a symlink, and also rejects symlinks inside the plugin. Copy or rsync the files.

To move the widget later:

omarchy bar move io.github.cempack.hearth --section right

If a QML layout change does not appear after saving under the user plugin directory, restart the shell:

omarchy restart shell

Usage

Click the hearth in the bar to open or close the panel. Middle-click play/pauses the whole mix without opening the panel.

  • Click a tile to light or extinguish that sound (this also starts the mix)
  • Drag up/down or scroll on a tile to change its volume
  • Preset chips apply Storm night, Deep work, Cafe, Sleep, Shore, Forest, Hearth, or Commute
  • The master slider at the top scales every voice, the same way Blanket multiplies each sound by the global volume

The mix is saved at ~/.local/state/omarchy/hearth/mix.json and resumes after a shell restart.

Keyboard

With the panel open:

  • Arrows / h j k l — move the tile cursor
  • Space or Enter — toggle the highlighted sound
  • p — play or pause the mix
  • Escape — close
  • Tab — switch to an adjacent bar panel

IPC (after the widget is enabled):

omarchy-shell io.github.cempack.hearth toggle
omarchy-shell io.github.cempack.hearth togglePlay
omarchy-shell io.github.cempack.hearth play
omarchy-shell io.github.cempack.hearth pause
omarchy-shell io.github.cempack.hearth open
omarchy-shell io.github.cempack.hearth close

Security

  • mpv is started with an argument array. User-supplied names never go through bash -c or bar.run.
  • Only the fourteen bundled files under sounds/ are played. Paths are constrained to [a-z0-9-]+.ogg inside the plugin directory.
  • Volume IPC is python3 hearth-ipc.py <socket> <payload> with a constant helper script; the socket path is built from a safe sound id under XDG_RUNTIME_DIR.
  • State JSON stores only play/pause, volumes, and the last preset name. Reads of mix.json run only after test -f confirms a regular file, are capped with timeout plus head -c, and are rejected if larger than 8KiB; the parser copies only the fourteen catalog voices. A FIFO or hung read cannot block the shell: the child is deadline-killed and the reload gate does not restart around it.

Tests

./tests/run

Remove

omarchy plugin disable io.github.cempack.hearth
omarchy plugin remove io.github.cempack.hearth --yes

Then delete ~/.local/state/omarchy/hearth if you want the saved mix gone too.

License

Hearth's QML and JavaScript are MIT. The audio loops retain their original licenses (CC0, CC BY, CC BY-SA, or public domain) as documented by Blanket in SOUNDS_LICENSING.md.